Sign in

sankarshan

@sankarshan.bsky.social
139 followers 837 following 168 posts

about.me/sankarshan.mukhopadhyay

PostsRepliesMedia
sankarshan @sankarshan.bsky.social · 31/08/2026
My governing principle for Wikimedia’s API strategy would therefore be: Modernize the interface aggressively; centralize authority cautiously. The goal isn’t merely cleaner APIs. It’s open knowledge infrastructure that remains open to inspection, experimentation and challenge.
000
sankarshan @sankarshan.bsky.social · 31/08/2026
I’d change the success metrics too. Don’t measure only adoption, efficiency, reliability or Enterprise conversion. Measure independent tools created, tools surviving migrations, time-to-first volunteer contribution and how much capability remains available without privileged relationships.
100
sankarshan @sankarshan.bsky.social · 31/08/2026
If gateways enforce access tiers, attribution, audiences or rate limits, make those policies inspectable. A developer should be able to discover not only THAT access was refused, but WHY. And consequential classifications need correction and appeal paths.
100
sankarshan @sankarshan.bsky.social · 31/08/2026
I’d also be very cautious about “internal” APIs. Different operational guarantees for WMF applications? Reasonable. Capabilities unavailable to community developers simply because they’re “internal”? Much harder to justify. Restrictions should follow explicit risks, not org charts.
110
sankarshan @sankarshan.bsky.social · 31/08/2026
One distinction is essential to emphasise: Protecting finite infrastructure is not the same thing as restricting access to knowledge. Rate limits may be necessary. Abuse controls certainly are. But resource protection and knowledge entitlement should not quietly become the same policy.
100
sankarshan @sankarshan.bsky.social · 31/08/2026
So the question isn’t only: “How should Wikimedia APIs work?” It is also: Who decides who may do what with Wikimedia knowledge, according to which rules, using what evidence, and with what route to challenge a decision? That belongs in an API strategy too.
100
sankarshan @sankarshan.bsky.social · 31/08/2026
The interesting part is the proposed gateway. Routing + authentication + rate limits + identification + monitoring + API audiences turns a gateway into more than infrastructure. It becomes a policy enforcement point and enforcement points exercise authority.
100
sankarshan @sankarshan.bsky.social · 31/08/2026
OpenAPI, REST, common schemas, SDKs and better documentation are good ideas. Machine-readable documentation isn’t inherently anti-human either. Ideally humans, software and AI all encounter different representations of the same well-defined contract.
100
sankarshan @sankarshan.bsky.social · 31/08/2026
I’ve been reading Wikimedia’s new API Strategy. I agree with much of the diagnosis: fragmented APIs, inconsistent interfaces and difficult discovery need fixing. My concern is elsewhere - API modernization can also quietly become governance centralization.
100
sankarshan @sankarshan.bsky.social · 19/08/2026
That is the inverse of “The Edge Knows First.” The edge may know before the institution does. But if resolution still depends on a trusted central interpreter, distributed knowledge has not yet become distributed governance. thetrustgraph.substack.com/p/the-edge-k...
thetrustgraph.substack.com
The Edge Knows First
What Accountable Execution Governance Cannot Fix
000
sankarshan @sankarshan.bsky.social · 19/08/2026
Jake Orlowitz’s account of Jimmy Wales exposes a hidden layer of Wikipedia governance: authority can sit not only in institutions, but in the person trusted to absorb conflict and translate between centre and edge. medium.com/regarding-wi...
medium.com
The Art of Being Jimmy Wales
One talk page, July to August 2026
100
sankarshan @sankarshan.bsky.social · 14/08/2026
What happens when proof of personhood becomes infrastructure? At what point does proving that you are a person become proving that you are sufficiently embedded in recognised institutions?
000
sankarshan @sankarshan.bsky.social · 10/08/2026
The missing piece isn’t better agent authentication. It’s a mandate: a bounded, revocable, machine-verifiable record of what an agent is authorised to do, and how that authority is withdrawn. open.substack.com/pub/thetrust...
open.substack.com
The Mandate Layer DPI Is Missing
Why identity, consent, and payment rails become insufficient when software acts under delegated authority
000
sankarshan @sankarshan.bsky.social · 10/08/2026
Digital Public Infrastructure was built to answer one question: who is acting? Agentic systems raise a harder one: under whose authority does the action happen? Identity and consent assume the person authenticating is the person deciding, in the same moment. Agents break that.
100
Reposted by sankarshan
Zack Whittaker @zackwhittaker.com · 04/08/2026
By me at this.weekinsecurity.com: A major online ads company that claims to serve 1.5 billion ads a day was hacked and began serving malware designed to steal a person's crypto. This is the latest perfect example why you should use an ad-blocker.
this.weekinsecurity.com
Online advertising giant Adform was hacked, proving once again why ad blockers are necessary
The hacked digital advertiser was caught serving malicious ads that allowed hackers to steal a victim's cryptocurrency.
8264154
sankarshan @sankarshan.bsky.social · 27/07/2026
The design principle is fairly simple: check the constraints, the delegation and the instruction first. Use behavioural inference only for what remains genuinely undecided. A model may know your habits well. That does not mean it has been authorised to bind you.
000
sankarshan @sankarshan.bsky.social · 27/07/2026
The problem becomes clearest when you change your mind or respond to something new. Your instruction may contain the only fresh information in the system. The model only has your past to work with, so it naturally leans toward continuity.
100
sankarshan @sankarshan.bsky.social · 27/07/2026
A behavioural model can make a good guess about what you usually want. It should not be able to overrule what you have actually instructed. Prediction is useful. It is not authority. thetrustgraph.substack.com/p/agents-tha...
thetrustgraph.substack.com
Agents That Outvote Their Principals
How behavioural inference quietly displaces expressed intent as the authoritative signal in delegated systems
100
sankarshan @sankarshan.bsky.social · 22/07/2026
Accountable institutions can still make bad decisions. Not because authority failed, but because the knowledge the decision needed never reached the people making it. The edge knows first. open.substack.com/pub/thetrust...
open.substack.com
The Edge Knows First
What Accountable Execution Governance Cannot Fix
000
sankarshan @sankarshan.bsky.social · 16/07/2026
Every identity system rewards linkage, not purpose limitation. Compliance with the rule and erosion of the rule turn out to be compatible. open.substack.com/pub/thetrust...
open.substack.com
The State Learned to Recognise Us. The System Learned to Watch Us.
What the history of identity documentation reveals about the incentive structure now built into biometric and digital identity infrastructure
010
sankarshan @sankarshan.bsky.social · 15/07/2026
Agent registries should do more than identify software. ARPA treats them as authority-control planes for delegated action, covering scope, limits, revocation, evidence and redress. Draft spec + reference implementation: github.com/sankarshanmu...
github.com
GitHub - sankarshanmukhopadhyay/agent-registry-protocol: A standards-oriented protocol for agent registries as distributed authority-control planes for delegated action. Defines interoperable models f...
A standards-oriented protocol for agent registries as distributed authority-control planes for delegated action. Defines interoperable models for agent identity, accountability, delegation, assuran...
000
sankarshan @sankarshan.bsky.social · 13/07/2026
Full essay: open.substack.com/pub/thetrust...
open.substack.com
Governing Delegation, Not Decisions
Retrospective Review Cannot Govern Systems That Never Stop Acting
000
sankarshan @sankarshan.bsky.social · 13/07/2026
Financial markets already made this shift: from reviewing individual trades to governing the scope algorithmic trading systems could operate under. Agentic governance needs the same move, and it’s coming whether or not the architecture is ready for it.
100
sankarshan @sankarshan.bsky.social · 13/07/2026
Good architecture can still fail on incentives. If broad, vague delegation stays cheaper to issue than narrow, well-specified delegation, the system will keep producing exactly the behavior it was built to prevent. That contradiction is the actual finding.
100
sankarshan @sankarshan.bsky.social · 13/07/2026
Revocation is the property that matters most, and the one current architecture handles worst. A revocation that applies only to new sessions while old ones run to completion isn’t a revocation. It’s a notice of intent.
100
sankarshan @sankarshan.bsky.social · 13/07/2026
A mandate isn’t one thing. It’s five: scope, duration, constraint, revocability, and a traceable principal chain. Leave any of them implicit and you’ve built an authorization nobody can actually check at the moment it matters.
100
sankarshan @sankarshan.bsky.social · 13/07/2026
Mandates for agents get written like mandates for human executives: broad objectives, implicit trust in judgment to fill gaps. Humans have a completion mechanism for that. Models don’t. They generalize from what’s explicit, not from what you meant.
110
sankarshan @sankarshan.bsky.social · 13/07/2026
Oversight frameworks review decisions after the fact. Delegation frameworks authorize the conditions under which decisions get taken. Confusing the two is the actual failure: retrospective review answering a question that no longer has a stable object to attach to.
100
sankarshan @sankarshan.bsky.social · 13/07/2026
A model under a standing mandate acts, then acts again, across parallel threads, on inputs nobody reviewed in real time. There’s no single moment to audit. There’s a policy applied continuously to a stream the principal never chose and never saw.
100
sankarshan @sankarshan.bsky.social · 13/07/2026
“Governing Delegation, Not Decisions” argues AI governance keeps answering the wrong question. It asks: was this decision legitimate? That question assumes a decision that holds still long enough to review. Agentic systems don’t produce anything that holds still.
100
sankarshan @sankarshan.bsky.social · 11/07/2026
I’d argue we need a richer model of accountable actors. Humans, organizations, software agents, and even composite systems can all be identifiable principals. What’s missing is verifiable authority, delegation rights, provenance, and liability that survive across chains of delegation.
000
sankarshan @sankarshan.bsky.social · 11/07/2026
This is why the conversation has to move beyond digital identity. The real design challenge is building systems where authority is observable, legitimacy is computable, and accountability survives delegation. open.substack.com/pub/thetrust...
open.substack.com
Delegation Without a Fixed Referent: What Multi-Hop Agent Chains Break That Single-Hop Delegation Doesn't
Attenuation, Lineage, and the Limits of Single-Hop Delegation Standards
020
sankarshan @sankarshan.bsky.social · 11/07/2026
Today’s identity infrastructure largely authenticates participants. Tomorrow’s trust infrastructure must also represent delegation, policy, scope, constraints, provenance, and continuous authority. Only this design pattern ensures that governance becomes infrastructure.
100
sankarshan @sankarshan.bsky.social · 11/07/2026
As agents invoke other agents, call tools, and cross organizational boundaries, authority becomes a chain, not a point. That chain needs to be explicit, bounded, verifiable, and revocable. Otherwise accountability disappears into orchestration.
100
sankarshan @sankarshan.bsky.social · 11/07/2026
Authentication answers who. Delegation answers whether they were entitled to act. Those are fundamentally different questions. Identity without authority is not sufficient for agentic systems.
100
sankarshan @sankarshan.bsky.social · 11/07/2026
Everyone is talking about AI agents and almost everyone is talking about identity. I think the bigger challenge is governance. Not “Who is the agent?” But “Who allowed this agent to act, under what authority, and who remains accountable?”
321
sankarshan @sankarshan.bsky.social · 08/07/2026
In substack.com/@thetrustgra... and substack.com/@thetrustgra... I look at the challenges in agentic systems which have to deal with the issue of delegation. Especially, multi agent and multi hop flows which surface some interesting capability gaps.
substack.com
Acting on Behalf: When the Agent Enters the Market Before the Principal Does
Delegated Authority Is Outrunning the Evidence That Would Make It Accountable
010
sankarshan @sankarshan.bsky.social · 07/07/2026
diff.wikimedia.org/2026/06/11/w... - this is not just a UX problem. It is a participation infrastructure problem. Wikipedia cannot rely indefinitely on civic goodwill while making the first step into contribution feel hidden, ambiguous, and hostile.
020
sankarshan @sankarshan.bsky.social · 18/05/2026
open.substack.com/pub/thetrust... Delegated intelligence is a shift in authority. When agents act, route, decide and delegate, the governance question changes from “what did the model output?” to “who authorised this chain of action, under what constraints, and with what redress?”
open.substack.com
Delegated Intelligence: The Next Compute Paradigm
The Shift: From Predictive Models to Autonomous Agents
000
sankarshan @sankarshan.bsky.social · 05/05/2026
open.substack.com/pub/thetrust...
open.substack.com
The Authority Gap
Why Agentic Systems Need Delegation Architecture, Not Digital Identities
000
sankarshan @sankarshan.bsky.social · 04/05/2026
If DPI 2.0 touches jobs, credit, benefits, health, education, agriculture and AI guidance, it becomes part of the control plane. Scale will not be enough. Legitimacy will require inspectable decisions, accountable intermediaries, and real redress.
000
sankarshan @sankarshan.bsky.social · 04/05/2026
The gap is governance. The roadmap invokes trust, privacy, consent, interoperability and safe AI, but the hard question is operational: who controls data flows, certifies actors, audits AI systems, resolves disputes, and revokes authority?
100
sankarshan @sankarshan.bsky.social · 04/05/2026
The strongest move is the shift from national platform thinking to district-led demand aggregation. DPI will not scale through rails alone. It needs local operating capacity, credible demand, contextual adoption, and state-level execution.
100
sankarshan @sankarshan.bsky.social · 04/05/2026
DPI@2047 is not really a technology roadmap. It is a state-capacity argument. The core claim is that digital public infrastructure can move India from foundational inclusion toward livelihood-led productivity, market access, and human capability.
100
sankarshan @sankarshan.bsky.social · 04/05/2026
open.substack.com/pub/thetrust... Machines making commitments is the real threshold. Once an agent can bind a payment, filing, contract, workflow, or institutional promise, the question is no longer “is it capable?” It is “was it legitimately authorised to create an obligation?”
open.substack.com
When Machines Make Commitments
Autonomy becomes consequential when it binds the future. Commitments are not a feature of agentic systems — they are the threshold at which delegation becomes institutional force.
000
sankarshan @sankarshan.bsky.social · 21/04/2026
The frontier for open knowledge systems: how to build governance that remains real after the control plane shifts. thetrustgraph.substack.com/p/the-control-plane-has-already-shifted thetrustgraph.substack.com/p/the-commons-after-the-control-plane thetrustgraph.substack.com/p/who-holds-the-license
thetrustgraph.substack.com
The Control Plane Has Already Shifted
Wikimedia's Governance Crisis and What Comes After
000
sankarshan @sankarshan.bsky.social · 21/04/2026
A governed training license may be necessary. But who gets to issue it? Institutions may hold infrastructure, but that does not automatically give them legitimate control over community-produced knowledge. Stewardship cannot become a quiet claim of sovereignty.
100
sankarshan @sankarshan.bsky.social · 21/04/2026
That is why consultation is not enough. A system is not legitimate because people were heard. It is legitimate only when authority is explicit, bounded, reviewable, and paired with mechanisms for correction, enforcement, and redress.
100
sankarshan @sankarshan.bsky.social · 21/04/2026
Commons governance worked when resources were bounded, attributable, and socially visible. AI breaks that condition. The consequential act now happens below the level where communities can meaningfully see, contest, or shape it.
100
sankarshan @sankarshan.bsky.social · 21/04/2026
The deeper rupture is this: AI consumes the commons at a level the commons can no longer properly observe or govern. When use becomes illegible, old governance mechanisms do not merely weaken. They lose the substrate that made them operative in the first place.
100