







This piece argues that DASL introduces security risk when applied to delegations, and that by not using DASL, capability trees avoid that risk.
Authority as Possession: Permissioned Spaces Deserve Better Than ACLs
Why Capability Trees are the right governance primitive for permissioned spaces.
The Substrate Requirements for Capability Trees
The bar other data sovereignty substrates must meet, to be compatible with Capability Trees.
Capability Trees: A Protocol-Level Extension of Object Capabilities, Draft 2
This draft addresses questions and feedback from the ATProto community, in particular from Zicklag (@zicklag.dev) and Brooklyn Zelenka (@expede.wtf). Draft 1 remains available for transparency.
Capability Trees: A Protocol-Level Extension of Object Capabilities, Draft 4
This draft incorporates feedback from Brooklyn Zelenka (@expede.wtf) and Daniel Holmgren (@dholms.at), and developments in the ATProto Private Data Working Group. Previous drafts remain available for transparency.
Capability Trees: A Protocol-Level Extension of Object Capabilities, Draft 3
This draft incorporates feedback from Brooklyn Zelenka (@expede.wtf), Daniel Holmgren (@dholms.at), and Zicklag (@zicklag.dev), and addresses questions raised in the ATProto Private Data Working Group. Draft 2 remains available for transparency.
Composing capability security and conflict-free replicated data types — Spritely Institute
In August, I attended the DWeb Seminar where a small group of builders gathered to discuss the state-of-the-art and open problems in the distributed web space. Some in the group are primarily concerned with distributed data and focus on sync algorithms and local-first use cases. I am mainly concerned with distributed behavior and focus on the object capability security model. Both areas of study are steeped in their own lore and research papers, which makes it difficult for the two camps to communicate effectively with each other.
A Tale of Two Theories (of Coordination)
Leveraging and Deleveraging Toward Thick Sovereignty

WAVE: A Decentralized Authorization Framework with Transitive Delegation | USENIX
Michael P Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro, John Kolb, Hyung-Sin Kim, David E. Culler, and Raluca Ada Popa, University of California, Berkeley
Sovereignty and Landscape | Simon Wardley | 15 comments
X : What is digital sovereignty? Me : I was asked that question by some friends within Government at the beginning of this month. I know some have been working on the idea, which is very encouraging, but I gave my tuppence worth of a definition. "Digital sovereignty is a country's ability to make its own decisions about the technology it uses, the data it creates, and how digital systems work in service of its people rather than being forced to accept choices made by other entities. This requires continuous situational awareness of the economic and technological landscape to anticipate changes, maintain strategic advantage, and shape international digital norms. Digital sovereignty is achieved through strategic control over critical digital assets and relationships, extending from public sector systems to the broader digital ecosystem affecting citizens and economic interests." The key is choice. You are sovereign if you retain the ability to make your own decisions rather than being forced to accept the decisions of others. This doesn't mean you need to own the entire tech stack, or all the data but you do need to maintain control over critical assets and relationships. This can be achieved by many means not just by conflict with others but through co-operation and collaboration (i.e. all the forms of competition matter). You also can consciously compromise, accepting some loss of sovereignty in one space to gain sovereignty in another. Anyway, I quite like the Mike Bracken description https://lnkd.in/eFjzcAdr "Digital sovereignty is the agency and capacity of any organisation to make intelligent, informed choices to shape its digital future by design". I used to do a lot of work on sovereignty many years ago, so if you want to know more about my view and how to achieve this, well I have a series of hopefully useful but somewhat introductory posts. Sovereignty and Landscape https://lnkd.in/eku2X_Ea Societal versus Market benefit https://lnkd.in/eXxkCv-K Whose interests are you serving? https://lnkd.in/eAgHS5wc | 15 comments on LinkedIn
Object-capability model
The object-capability model is a computer security model. A capability describes a transferable right to perform one (or more) operations on a given object. It can be obtained by the following combination:
Protocols and Power
If "context" is king, we need to ensure it remains fluid and accessible by third-party developers

Protocol: How Control Exists after Decentralization by …
How Control Exists after Decentralization by Galloway, …

DASL — Data-Addressed Structures & Links
A small set of simple, standard primitives to work on content-addressed data.
