







This draft addresses questions and feedback from the ATProto community, in particular from Zicklag (@zicklag.dev) and Brooklyn Zelenka (@expede.wtf). Draft 1 remains available for transparency.
Capability Trees: A Protocol-Level Extension of Object Capabilities, Draft 3
This draft incorporates feedback from Brooklyn Zelenka (@expede.wtf), Daniel Holmgren (@dholms.at), and Zicklag (@zicklag.dev), and addresses questions raised in the ATProto Private Data Working Group. Draft 2 remains available for transparency.
Capability Trees: A Protocol-Level Extension of Object Capabilities, Draft 4
This draft incorporates feedback from Brooklyn Zelenka (@expede.wtf) and Daniel Holmgren (@dholms.at), and developments in the ATProto Private Data Working Group. Previous drafts remain available for transparency.
The Substrate Requirements for Capability Trees
The bar other data sovereignty substrates must meet, to be compatible with Capability Trees.
Object-capability model
The object-capability model is a computer security model. A capability describes a transferable right to perform one (or more) operations on a given object. It can be obtained by the following combination:
What is a Capability?
I have several folks asking me what I mean when I say capability in the context of what we are building with Naftiko. I have been writing about API capabilit...

Composing capability security and conflict-free replicated data types — Spritely Institute
In August, I attended the DWeb Seminar where a small group of builders gathered to discuss the state-of-the-art and open problems in the distributed web space. Some in the group are primarily concerned with distributed data and focus on sync algorithms and local-first use cases. I am mainly concerned with distributed behavior and focus on the object capability security model. Both areas of study are steeped in their own lore and research papers, which makes it difficult for the two camps to communicate effectively with each other.
Capability Chains vs UCAN · by holobrine.bsky.social
Five ways in which ATProto capability chains offer improvements over UCAN
ATProto Architecture
Visual summary of the AT Protocol architecture: PDS, AppView, identity, records, lexicons.

Capability Trees: Sovereignty Is the Point
This piece argues that DASL introduces security risk when applied to delegations, and that by not using DASL, capability trees avoid that risk.
Capabilities
There are three kinds of capabilities in Peergos: Mirror, Read and Write.
Epoch Capabilities Index
The Epoch Capabilities Index combines many benchmarks into a single capability scale for comparing models over time.
Authority as Possession: Permissioned Spaces Deserve Better Than ACLs
Why Capability Trees are the right governance primitive for permissioned spaces.
Protocol Reader - Summer of Protocols
The Protocol Reader The Protocol Reader is an 358-page book (currently only available as an epub) comprising 26 foundational essays by 31 authors from the Summer of Protocols program, carefully edited and sequenced to introduce you to the fascinating new discipline of Protocol Studies. It can serve as

Well, atproto *is* an open protocol so... I'm looking into an excension of the schema to allow accounts that are declaring that they're automated to optionally declare details about that automation, including an operator, a purpose, even an interaction model. Aids in both discovery and moderation!
Compose | Taproot
Compose | Taproot

ATScience Ecosystem Map

Bluesky Protocol Services

Explore

AnyPub