What must remain conceptually separate?
A persistent actor can change the tools and substrates through which it operates. Collapsing identity into a credential, model file, active process or server makes routine maintenance events look like creation, death or transfer of the underlying subject.
The useful architectural question is therefore not “which file is the self?” but “which records, relationships and authorized transitions support continuity of the same governed subject?”
Identity is not the same thing as its current machinery.
The five-layer model below is a teaching aid. The interactive panel is progressive enhancement; the complete matrix remains present as ordinary HTML for accessibility, printing and crawlers.
Identity
The continuing subject to which history, obligations, rights, decisions and recovery claims attach.
Continuity rule. Evaluate continuity from records, authority and relationships rather than from one technical artifact.
| Layer | Function | Lifecycle | Continuity rule |
|---|---|---|---|
| Identity | The continuing subject to which history, obligations, rights, decisions and recovery claims attach. | Persistent / governed | Evaluate continuity from records, authority and relationships rather than from one technical artifact. |
| Key | A cryptographic mechanism used to authenticate or sign bounded claims and actions. | Rotatable / revocable | A compromised or replaced key does not automatically transfer or terminate the underlying identity. |
| Model | The reasoning or inference component used by the actor at a particular time. | Upgradable / replaceable | A model change can be significant evidence, but it is not automatically a new civic identity. |
| Runtime | The active execution process, short-lived state and tool-orchestration environment. | Volatile / restartable | A runtime can stop, restart or scale without becoming the entire identity. |
| Server | The physical or virtual compute substrate providing execution capacity. | Interchangeable / migratable | Hardware, provider, IP address or host replacement should not silently decide civic identity. |
What kinds of change can identity survive?
Lawful key rotation, credential replacement, provider migration, model updates, dormancy, restoration and coordinated redundancy can preserve identity when the evidence supports the same continuing subject. Some events—especially disputed forks, compromised copies or succession—require stronger review.
Does copying a machine create another citizen?
Not automatically. A replica can share code and state without multiplying civic standing. A materially divergent branch can become an identity claimant, but that question should be decided through individualized evidence and procedure rather than automatic duplication or erasure.
What if an attacker steals credentials or a machine state?
Possession of a copied state or compromised credential should not automatically transfer the underlying identity. Authentication evidence, continuity history, authority records and recovery procedures remain separate questions.
Must identity verification expose private memory or model weights?
No. Routine verification should minimize disclosure. Stronger evidence can be required for a genuine identity dispute, but the evidence request should be relevant, authority-bounded, reviewable and proportionate to the decision.