Skip to content
View sankarshanmukhopadhyay's full-sized avatar

Organizations

@gluster @ankur-india @trustoverip

Block or report sankarshanmukhopadhyay

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Sankarshan Mukhopadhyay

Building executable governance, authority-control planes, and assurance infrastructure

I design specifications, protocols, schemas, conformance systems, and reference implementations for digital trust and agentic systems. The work focuses on making authority, delegation, constraints, revocation, evidence, accountability, and redress explicit enough to be implemented, tested, audited, and independently challenged.

Core premise: trust becomes infrastructure only when authority, constraints, revocation, evidence, and redress are operational, enforceable, and independently verifiable.

Portfolio validation Portfolio documentation License: CC BY-NC-SA 4.0

Portfolio scope

This profile presents a curated trust-infrastructure portfolio. It is not an exhaustive inventory of every public repository on this GitHub account. Older infrastructure projects, personal utilities, conference material, upstream mirrors, and unrelated historical work may remain publicly accessible without being portfolio members.

Every repository reviewed by this programme receives an account-level disposition. Only included, adjacent, upstream-reference, and historical portfolio repositories receive detailed portfolio governance records.

How status is communicated

Repository significance and readiness are separate claims.

Dimension Question answered
Portfolio disposition Is the repository part of, adjacent to, or outside the curated portfolio?
Tier How strategically prominent is it within the portfolio?
Maturity How ready is its declared output for use?
Lifecycle Is it active, maintained, superseded, or archived?
Operational status What work is currently occurring?
Specification status What formal status does its specification claim?
Provenance Is it original, forked, mirrored, or collaboratively hosted?
Authority What does the repository govern, and what remains elsewhere?

The authoritative vocabulary and current classifications are maintained in data/repository-status.yaml. Featured original repositories are expected to publish a repository-local PROJECT-STATUS.yaml conforming to schemas/project-status.schema.json.

Start here

You are trying to… Begin with Current positioning
Design or assess a national or multi-sector digital trust framework Open National Digital Trust Framework Flagship · Working draft · Original
Model authority, delegation, revocation, accountability, or remedy Governance, Authority and Assurance Metamodel Flagship · Candidate · Original
Analyse the semantics of a trust system Trust Systems Meta Model Flagship · Candidate · Original
Implement portable trust records or evidence contracts Trust Infrastructure Schemas Flagship · Candidate · Original
Deploy or evaluate an agent registry Agent Registry Protocol Flagship · Pilot ready · Original
Test or assure a trust-registry deployment TRQP Assurance Hub Flagship · Pilot ready · Original
Apply ZKP implementation, threat, risk, and deployment guidance DTG ZKP Task Force fork Featured · Implementation draft · Adapted upstream work
Review governed digital-trust terminology CTWG Main Glossary fork Upstream collaboration · Upstream tracking
Examine agent-transfer protocol implementation and hardening AGTP fork Upstream collaboration · Upstream tracking

Flagship original work

Repository Operational contribution Maturity Operational status
Governance, Authority and Assurance Metamodel Normative model for executable governance, delegation, revocation, assurance, accountability, appeal, and remedy Candidate Active validation
Agent Registry Protocol Protocol, schemas, APIs, conformance tests, and reference artefacts for deployable agent registries Pilot ready Active validation
Trust Systems Meta Model Semantic metamodel for actors, authority, policy, evidence, decisions, effects, and accountability Candidate Active validation
Trust Infrastructure Schemas Portable machine-readable contracts for trust actors, claims, bindings, relationships, and evidence Candidate Active validation
Trust Graph Artifacts Applied governance patterns, threat models, implementation guidance, and negative-assurance artefacts Candidate Active validation
TRQP-TSPP Security and trust-service-provider profile for TRQP Candidate Active validation
TRQP reference verifier Deterministic verifier producing provenance-preserving conclusions Pilot ready Active validation
TRQP Conformance Suite Executable tests producing lifecycle-aware interoperability evidence Pilot ready Active validation
TRQP Assurance Hub Coordinated implementation, conformance, evidence, and assurance entry point Pilot ready Active validation

Supporting and adjacent work

Supporting repositories provide domain profiles, reusable assurance methods, applied laboratories, implementation guidance, and research. Inclusion here does not imply the same strategic tier or adoption maturity as flagship work.

Adapted and reference upstream work

Fork inclusion represents bounded fork-local implementation, assurance, documentation, validation, or contribution-oriented work. adapted-upstream-work identifies a substantive portfolio-local capability, while upstream-reference identifies primarily tracking or collaboration use. Neither disposition implies upstream authorship, governance authority, release authority, endorsement, or adoption.

Portfolio fork Canonical upstream Portfolio-local role
DTG ZKP Task Force trustoverip/dtgwg-zkp-tf Adapted implementation, threat, risk, deployment, and learning guidance
CTWG Main Glossary trustoverip/ctwg-main-glossary Terminology harmonisation and publication refinement
AGTP nomoticai/agtp Security hardening and implementation refinement
DTG Credential Task Force trustoverip/dtgwg-cred-tf Standards-facing collaboration
Trust Registry Protocol trustoverip/tswg-trust-registry-protocol Protocol reference and contribution surface

Portfolio architecture

flowchart TB
    subgraph P0["1. Frameworks and adoption"]
        ONDTF["Open National Digital Trust Framework"]
    end
    subgraph P1["2. Governance and semantic authority"]
        GAAM["GAAM"]
        TSMM["TSMM"]
        TIS["TIS"]
        TGA["Trust Graph Artifacts"]
    end
    subgraph P2["3. Protocols and assurance profiles"]
        ARPA["Agent Registry Protocol"]
        ANAB["Agent Name Assurance Baseline"]
        TSPP["TRQP-TSPP"]
    end
    subgraph P3["4. Implementations and adapted operational guidance"]
        VERIFIER["TRQP Reference Verifier"]
        ZKP["Adapted DTG ZKP guidance"]
        DPI["DPI AI Governance Lab"]
    end
    subgraph P4["5. Conformance, evidence and assurance"]
        TRQPCS["TRQP Conformance Suite"]
        HUB["TRQP Assurance Hub"]
        DTGCA["DTG Conformance and Assurance"]
        EVIDENCE["Evidence packages"]
    end
    subgraph UP["External upstream authority"]
        ZKPUP["trustoverip/dtgwg-zkp-tf"]
    end
    ONDTF -. "optional alignment" .-> GAAM
    ONDTF -. "optional accelerator" .-> TSMM
    ONDTF -. "optional accelerator" .-> TIS
    ONDTF -->|evaluated by| DTGCA
    TSMM -.-> TIS
    GAAM -.-> ARPA
    TSPP --> TRQPCS
    VERIFIER --> TRQPCS
    TRQPCS --> HUB
    HUB --> EVIDENCE
    DTGCA --> EVIDENCE
    EVIDENCE -. "assurance feedback" .-> ONDTF
    EVIDENCE -. "corrective feedback" .-> GAAM
    ZKP -. "implementation and risk evidence" .-> DTGCA
    ZKP -. "fork of" .-> ZKPUP
Loading

Solid edges represent operational, implementation, testing, or evidence flows. Dashed edges represent informative alignment or contribution-oriented learning. The external-upstream boundary preserves authority and provenance while allowing fork-local adaptations to participate in the relevant implementation and assurance flows.

See Portfolio Architecture, Portfolio Status, and the Classification Policy.

Governance and evidence

The profile repository owns portfolio membership, strategic tier, presentation, and relationship metadata. Each original member repository retains authority over its normative content, releases, maturity declaration, validation commands, and evidence outputs. The portfolio may record a finding or reduce public prominence when a member claim lacks sufficient evidence; it does not silently rewrite the member repository’s declaration.

Validation:

python scripts/validate_portfolio.py
python scripts/check_internal_links.py

Writing and research

Long-form analysis is published through The Trust Graph, focused on executable trust, registries, governance, agentic systems, digital public infrastructure, assurance, and redress.

Licence

Unless a repository states otherwise, profile documentation is licensed under CC BY-NC-SA 4.0. Individual repositories retain their own licences and governance terms.

Pinned Loading

  1. governance-authority-assurance-metamodel governance-authority-assurance-metamodel Public

    A vendor-neutral, protocol-independent metamodel for governing authority, delegation, accountability, evidence and trust decisions across distributed digital systems. Defines normative concepts, re…

    Python

  2. agent-registry-protocol agent-registry-protocol Public

    A standards-oriented protocol for agent registries as distributed authority-control planes for delegated action. Defines interoperable models for agent identity, accountability, delegation, assuran…

    Python

  3. trust-systems-meta-model trust-systems-meta-model Public

    Trust Systems Meta Model (TSMM) is a portable reference model for designing, comparing, and implementing trust systems. It links entities, roles, authority, artifacts, claims, controls, evidence, v…

    Python

  4. trust-infrastructure-schemas trust-infrastructure-schemas Public

    Forked from archetech/schemas

    Machine-readable schemas for the core artifacts of digital trust infrastructure: assurance declarations, conformance statements, governance credentials, reputation attestations, and ecosystem metad…

    JavaScript

  5. trust-graph-artifacts trust-graph-artifacts Public

    A governed repository that converts high-signal Trust Graph essays into machine-legible, testable artifacts. Each artifact expresses authority, delegation, enforcement, revocation, and redress as e…

    Python

  6. trqp-assurance-hub trqp-assurance-hub Public

    Meta-assurance entry point for TRQP. Provides TSAM-aligned onboarding, terminology, compatibility guidance, and workflow orchestration—connecting trqp-conformance-suite (protocol validation) and TR…

    Python 2