Skip to content

Trust and standing

Kunuleco keeps apart two questions that most services blur. One is who you are, which your identity answers. The other is what you may do in a given place, which grants and standing answer. Being present somewhere answers neither.

Grants, not lists

Access to a capsule comes from a grant, a record signed by the person who made it. The node checks that signature before it honours the grant. You give someone specific capabilities (read, write, and so on) on a capsule you own, and take them back later.

grant notes mira#7K2QX9 read,write
revoke notes mira#7K2QX9
list grants notes

grant and revoke act on your own capsule of that name. Only a capsule's owner can share it or revoke access to it, and a capsule someone shared with you cannot be shared on. Because the grant names the thing it opens, taking it back is clean. And because presence is not permission, someone can stand in your Hall without being able to open anything in it.

The node user and the owner

Every node has its own account, the node user, created the first time the node starts. It is the root that other rights come from, and nobody can sign in as it. The first person to create an account on a node becomes its owner. The node user gives that person four grants once, create_user and node_admin and the right to pass each of them on.

Owner and Steward are different things. The owner runs the node, and node_admin is what makes someone an owner, so a person who can create accounts is not thereby an owner. A Steward runs a Hall.

The owner's four grants from the node user do not expire. Every create_user, node_admin and delegate: grant that a person gives expires 90 days after it is given, and nothing renews it unless the person who gave it does.

Command What it does
delegations List the grants you gave that are still live, with their expiry
renew <name> Renew every expiring grant you gave that person
renew all List what would be renewed, and sign nothing
yes Renew exactly the list renew all showed, within ten minutes
undelegate <id> Revoke a grant, and what was passed on from it

When you sign in, the node tells you which of your grants lapse within 30 days.

Standing

Standing is your trust level inside one Hall. It rises from visitor to steward, and each tier adds to the one below it.

Tier Can
Visitor Read the public zone. Not a member
Newcomer Read and write in the public zone. The first member tier
Familiar Use the common zone
Trusted Moderate the common zone, and vouch in a members-only Hall
Steward Use the private zone, govern the Hall, and set other people's standing

standing shows yours in the Hall you are in. standing <user> <tier> is the Steward's command for setting someone's tier, and in this build it grants nothing (see Known issues). So a member reaches Newcomer through accept or an open Hall, and no one can yet be raised to Familiar, Trusted or Steward.

Getting into a Hall

A Hall's threshold decides how much ceremony entry takes. A Steward changes it with set hall threshold <open|knock|invite_only|members_only>.

Threshold What happens on first entry
open You walk in as a Newcomer
knock Your knock waits for a Steward. This is the default for a new Hall
invite_only Reserved. For now your request waits for a Steward, as with knock
members_only Your knock waits, and two vouches from Trusted members admit you without a Steward

A Steward reviews the queue with knocks and answers with accept <user> or reject <user>. In a members-only Hall a Trusted member or the Hall's owner can vouch <user>. When two vouches from people who are still Trusted are in, the person is admitted as a Newcomer. See Your first Hall.

Petnames

A petname is your own private alias for someone (petname mira#7K2QX9 mira). It is bound to their full handle, and to their identifier when your peer registry has one, not to a display name. An alias you have set cannot be quietly pointed at someone else. To reassign it, you clear it first with petname <name> --clear. Your petnames and contacts live in your private peer registry and survive restarts.

Blocking

block <name> blocks the person by the AID their connection proved, wherever that person appears on your node, and drops any session you have open with them. If your node has never verified who a name belongs to, or the name belongs to more than one identity, block says so and blocks nothing. unblock <name> lifts it, and someone who was a contact comes back as a contact. blocked lists who you have blocked.

A block is a decision your node makes about what it accepts. It does not reach into anyone else's node or erase what they already have.

Membership is intentional

Sponsorship. Once a node has an account, creating another one needs a sponsor who holds create_user. The owner holds it, and other people hold it only if the owner passes it on. Nodes grow on purpose rather than by drift.

Meeting in person. meet shows a kunul1… seed and a QR code. The other person runs join with it, and their node dials yours over the local network and checks that the identity your node proves matches the AID inside the seed. If it does not match, the connection is dropped and nothing is recorded, so what you scanned is who you get.