Creation as First Access Agreement
Creating an Identity is two things at once: factual lineage and a default jurisdiction package. Parent-Child is not ownership of the Child Stem. It is the first Access Agreement the framework makes explicit.
Ownership as Relative Jurisdictionsupplied the working language: Access and Jurisdiction as degrees of freedom, sovereignty as the highest relative claim over theIdentity Stem. What remained under-specified was the moment a new Identity begins.
Without an explicit creation-time model, nested Spaces, agents, ideas, and spin-offs drift into one of two failures: silent account-root power, or no residual control at all. This essay locks the operational answer.
Lineage and Jurisdiction Package
Creating an Identity records factual origin: who brought this form into existence (creator_identity_id). Lineage is audit history. Grandparent relations are reconstructible from the chain; they do not confer silent elevation.
At the same moment the runtime issues a default jurisdiction package to the creator (or to a designated initial admin Identity when creation is delegated): a transferable set of grants for policy, visibility, Surface, and further grants on the new form.
Parent-Child is therefore not a second geometry layer and not classical ownership of the Child Stem. It is creator lineage plus transferable default grants, with a narrow residual emergency lever for the original creator line.
Roles in Effect, Not Permanent Titles
Indicative scopes (names may evolve; semantics locked):
policy_admin: change Surface access policy, consent defaults, criticality rules for this Identity.
visibility_control: set discovery and addressability caps (known vs reachable) relative to Spaces and peers.
surface_admin: manage non-critical Surface tooling under existing critical-approval rules.
grant_admin: issue and revoke ordinary grants on this Identity (not the residual).
These grants start with the creator and are transferable under audit. After transfer, the previous holder loses that operational power unless a new grant is issued. Lineage does not change.
Ordinary Parent Power Is Revocable
The Child Identity may revoke ordinary grants held over it, including those that originated as the creation-time default set, subject to audit. This preserves agency: a mature agent or idea Identity is not permanently subordinate in policy merely because it was spawned.
Sovereignty over the Stem stays with the Identity that holds it. Jurisdiction over policy, visibility, and Surface is relative and grant-scoped. The framework refuses both permanent Parent capture and silent account-root power.
Narrow, Audited, Not Full Admin
The original creator line retains a residual emergency capability that is not fully extinguished by ordinary Child revocation.
- Emergency Surface freeze or quarantine of the Child Identity
- Force a visibility or membrane-cap re-evaluation
- Trigger audit-visible emergency policy caps
- Silent Stem, Vision, or Mature writes
- Unrestricted policy rewrite without audit
- Automatic Grandparent elevation up the lineage chain
The residual is always audited (actor, reason, timestamp). It is a last lever, not a standing override of the Child's Stem sovereignty. Grandparent residual is not automatic.
Registration Is Not Reachability
Registration or discovery in a parent Space (including a managed main Space) does not imply addressability.
- →Known: membrane-allowed existence, host descriptor, or minimal Public Card stub.
- →Addressable: Surface endpoints and grants that allow others to call the Identity.
visibility_control and Space membrane policy decide the difference. This is the operational answer for Identities that become known in a higher Space without becoming public by default. See Boundaryand Multicellularityfor the membrane reading.
Two Lenses, One Contract
Under the biology lens,Genenames the heritable founding configuration: what can be passed so a new Identity begins related and still becomes other. Passing Gene does not keep Ownership over the new form.
Under the framework reading of Ownership, creation is the first Access Agreement: an explicit, auditable trade of degrees of freedom at birth. The OS contract operationalizes Jurisdiction at creation time without promoting Ownership to a new Core Concept or claiming legal title.
Open Core:identity-creation-jurisdiction.md.
What This Model Refuses
- →Parent as absolute owner of the Child Stem
- →Automatic Grandparent override of intermediate Parents
- →Silent account-root power over all Identities under an account
- →Treating "registered in main Space" as public Surface access
- →Residual red button as unrestricted admin
- →Replacing Space membrane policy with lineage alone
What Changes in Practice
- 01Name the founding gift.When you start a child Identity, idea-identity, or spin-off, what exactly is being passed, and what must stay yours?
- 02Separate known from addressable.Discovery in a Space is not Surface reachability. Visibility caps are membrane work.
- 03Keep residual narrow.Any last emergency lever for the creator line is audited and scoped. It is not silent Stem writes.
- 04Honor lineage without identity collapse.The new form may carry your Gene and still owe you no obligation to remain a copy.
Working Definition, Operational Continuity
This essay crystallizes the creation-time reading of Ownership. It does not introduce a new Core Concept. It does not settle legal title. It supplies the public language that matches the Open Core contract already locked in IE OS.
Further formal steps remain: Access and Jurisdiction probes, continued tracking of the ownership gap, and eventual Core Concept promotion only when the measurement layer is stable enough.
Where the work continues
- →Ownership as Relative Jurisdiction: the parent working definition
- →Gene: heritable founding configuration and operational continuity
- →Boundary: membrane condition and known vs addressable
- →OS: Identity creation unit and Open Core contract
- →Access and Jurisdiction probes (OS issue track)
- →Critical Gaps: ownership entry remains open until Core Concept promotion