Public Release - 2026-07-20

An agentic phone is not authorized to act because it can act.

Artifact: voice_identity_action_gate_v1. This note turns an agentic-phone action chain into a reviewable authorization record: a familiar voice, face, or chat history can support an identity claim, but cannot silently unlock a transfer, credential release, or external commitment.

claim_id claimed_identity independent_channel urgency_signal requested_action verification_phrase action_lock evidence_timestamp boundary_update review_status
Agentic Phone Authorization Gate v1 public evidence visual.

Artifact

Execution capability is not authorization.

An agentic phone can move from a spoken request to a chain of external actions. The review object asks who authorized the final step, what independent channel verified the identity, and which action remains locked when the evidence is weak.

A familiar channel still needs a second channel.

Gate

A familiar channel still needs a second channel.

Voice, face, or chat history can imitate familiarity and urgency. A sensitive action needs an independent verification phrase and a visible action lock that does not depend on the same agentic interaction.

If urgency bypasses verification, the device has exceeded its authority.

Review

If urgency bypasses verification, the device has exceeded its authority.

A useful challenge should identify a missing field, an unsupported causal link, a stale evidence timestamp, or a condition under which the proposed control fails. The protocol does not certify a device or claim universal reliability.

1

claim_id

The identity, transfer, access, or external action claim under review.

2

claimed_identity

The person or role that the call, face, message, or device says it represents.

3

independent_channel

The second route used to verify the request outside the original interaction.

4

urgency_signal

The pressure cue that tries to compress the time available for judgment.

5

requested_action

The transfer, credential release, approval, or commitment being requested.

6

verification_phrase

The callback step, shared phrase, or non-voice proof that can block impersonation.

7

action_lock

The state that prevents an external action until verification is complete.

8

evidence_timestamp

The source date, incident date, or operating window that anchors the claim.

9

boundary_update

The scope change required when the device channel is too weak to authorize action.

10

review_status

The recorded state: supported, narrowed, pending, or retired.