• Skip to primary navigation
  • Skip to main content
Identity Woman

Identity Woman

Independent Advocate for the Rights and Dignity of our Digital Selves

  • About
  • IETF Research
  • She’s Geeky: AI Edition
  • Weekly SSI Newsletter
  • Blog
  • Media Coverage
  • Contact
  • Show Search
Hide Search

Archives for July 2026

What If the Same Infrastructure That Stops AI Scams and Slop Also Builds the a Co-Created Community Future?

Kaliya Young · July 23, 2026 · Leave a Comment

By Kaliya Young and Kevin Triplet co-leads of Project Weave

The internet is made of protocols. TCP/IP, HTTP, SMTP — these are open standards no one owns and everyone builds on. That is why email works across providers and websites work across browsers and websites can be served to browsers by different operating systems. Protocols are the reason the internet became universal instead of a collection of walled gardens.

But the internet never got protocols useful for “social trust”. There is no common way to prove you are a real person, no way to verify who authorized an AI to act on your behalf, no way for a community to govern the tools it depends on. The things that should have been held in common include identity, the social graph, group memberships, collective memory, and by extension trust itself they all had had no protocol layer to hold them. So the platforms of the early 2000s emerged into that gap and enclosed them. Each drew a fence around the part of our social life it mediated and claimed what was inside as property. Twenty plus years of escalating harm followed.

Now AI is making the gap critical. Deepfakes, autonomous agents, synthetic identities, AI-powered manipulation — all accelerating on top of an internet that was never built to handle them. AI doesn’t create the missing trust layer. It weaponizes the absence of one by manufacturing personhood at scale and acting through agents that answer to no one you can name.

AI governance is, at root, an infrastructure problem. You cannot regulate what you cannot verify. And right now there is no protocol-level way to:

  • know whether you are dealing with a real person or a synthetic one;
  • track what an AI agent did, and who gave it permission;
  • prove that content actually came from the organization it claims to;
  • let a community set the rules for the AI tools it uses.

I think the mix of protocols to fix this largely already exist. They have been evolving for years — open standards for identity, credentials, encryption, and trust, built in the same tradition as the internet’s founding protocols. What is missing is integration, adoption, and the funded push to make them work together.

Project Weave drives adoption of these nascent protocols to build a protocols-not-platforms layer that serves civil society and the public good.

The same AI can power two completely different futures. Which one we get depends on whether there is a trust layer underneath it. That tension is exactly what Kevin and I were trying to articulate when we first started working on Project Weave together.

In early May we converged in Washington DC to attend the Good Tech Summit, an event focused on civil society uses of emerging technology including AI. The three days before, we co-worked to figure out how our technologies can help AI go well for people and communities — and how to prevent it from unfolding in a really negative direction full of spoofing. Those are two sides of the same coin, and the difference between them is trust infrastructure.

Scenario A — without a trust layer

The grandmother scam. She gets a call that sounds exactly like her grandson — an AI-generated voice. She wires $10,000 before anyone can stop her. There is no lock on that door. There never was.

The black-box agent. Your financial AI makes a trade you did not authorize. Your health AI shares records you never agreed to share. There is no record of what it was allowed to do, and no way to shut it down across all the places it operates. Who do these agents actually work for? Right now, whoever built the platform.

The trapped nonprofit. An organization uses an AI assistant for months. It learns their donors, their strategy, their community’s patterns. Then the vendor changes the deal — all of that knowledge belongs to the platform. Leaving means starting from zero.

The cloned newsroom. Someone copies a legitimate news site — logo, layout, everything — and fills it with AI-generated content. Readers cannot tell the difference because there is no way to verify that what you are reading comes from who it says it does.

Children with no protection. A five-year-old alone in a refugee camp. No ID, no guardian. A trafficker claims her and there is no structural way to block it. Online, children connect with whoever the algorithm serves them — there is no protocol for anchoring a child’s digital world in verified relationships with people who actually know them.

These are not edge cases. They are the ordinary consequences of an internet that has no protocol for trust.

Scenario B — with a trust layer

Your grandmother is protected. Calls from outside her trust network get flagged before they reach her — not by a moderator, but by the architecture. The scammer cannot get through because the system requires credentials they do not have.

Your AI agents answer to you. Every agent carries credentials tied to you, and every action is signed. You see what your agents are doing from one place. Pull a permission and it is gone everywhere. If your data trains an AI, you decided that and you set the terms — it is not quietly scraped and monetized by someone else.

Children are safe by design. A child’s digital world is built on verified relationships — family, teachers, friends the family actually knows — not algorithmic feeds from strangers. Safety becomes architectural, not a platform policy that changes with the next product cycle.

Organizations own what they build. A nonprofit’s knowledge, donor relationships, and community patterns belong to the nonprofit — held in open protocols, not locked inside a vendor’s product. No one can hold that knowledge hostage when the contract comes up for renewal.

Communities coordinate on their own terms. Mutual aid, crisis response, local governance — on infrastructure the community owns, not infrastructure a private equity firm can acquire and strip for parts.

The difference between these two scenarios is not better intentions or better regulation. It is a layer of infrastructure. The same layer that defends against the worst of AI is what makes the best of it possible.

The solution we already have

That infrastructure layer is being built. It starts with recognizing that a tool choice is a protocol choice. Every time a community picks a platform, it is choosing who governs its identity, its roster, its memory. For twenty-five years that choice has meant handing those things to a tool provider or platform. The alternative is to hold them in open protocols, as a commons no one can enclose — and you cannot enshittify what you cannot enclose. There is no fence to draw, no rent to extract. SMTP and HTTP have resisted capture for four decades for exactly this reason. The trust layer extends that same property to the things SMTP and HTTP never covered: identity, relationships, groups, and trust.

What is the trust layer made of

It is not one product. It is a stack of open standards, most of them already shipping:

  • Decentralized Identifiers (DIDs) — a W3C standard. An identifier you hold the keys to. No platform issues it, and no platform can revoke it.
  • Verifiable Credentials (VCs) — the digital equivalent of a membership card: cryptographically signed, privacy-preserving, presented on your own terms.
  • Wallets and agents — software that holds your credentials and acts for you, rather than a platform holding them on its servers.
  • Trust Over IP and the Trust Spanning Protocol — a four-layer trust architecture modeled on TCP/IP, so any party can establish trust with any other the way any host can reach any host on the internet.

The First Person Project pulls these together into a coherent architecture based on work by the Trust Over IP Foundation and the Decentralized Identity Foundation, and adds the two pieces AI makes urgent:

  • Personhood Credentials (PHCs) answer the question is this a real, unique person? — without a global biometric database and without surveillance. This is the lock on the grandmother’s door.
  • Verifiable Relationship Credentials (VRCs) answer the question do these two people actually know each other? Issued peer-to-peer, they assemble into a Decentralized Trust Graph — the social graph held in open protocols instead of sitting in a hyperscaler as an asset on Meta’s or Microsoft’s balance sheet. The scam call from outside your grandmother’s real network has no credential to present, so the architecture could stop it before she ever hears it.

These same credentials extend to AI agents — every agent can carry credentials tied to the person it works for and sign every action it takes, so “who authorized this?” finally has an answer, and a permission you revoke is revoked everywhere at once.

This is not just theoretical. After the 2024 XZ attack — in which an attacker spent two years building up a fake open-source-contributor identity to seize control of code running in nearly every Linux distribution — the Linux Foundation is looking at adopting First Person credentials, because a faked contributor with no personhood attestation and no real relationships could not have gotten near that kind of access. The underlying standards are already in use in healthcare, education, finance, and government.

We see the need for this trust layer to be held as a commons — open protocols governed cooperatively, so no future platform can buy it. The commons-holding governance matches the commons-holding architecture.

How it builds

The trust layer is not deployed all at once. It builds outward, and each level depends on the one beneath it.

People

None of this works if people do not control their own identity and data. The First Person Project gives people proof-of-personhood built on Verifiable Relationship Credentials — your identity verified by the people who know you, not by a company or a government database. Your credentials belong to you. They move with you across platforms and borders. They cannot be stolen, because they are not sitting in one hackable database. They cannot be faked, because they are backed by real relationships, not just documents.

Your AI agent carries your credentials, acts within permissions you set, and can be reined in from one place. Community sovereignty starts with individual sovereignty — you have to get this layer right before anything above it holds.

Groups

Once people have a real root in the digital world, groups can form on their own terms.

This is the enclosure least talked about and maybe the deepest. Today a group exists inside a product — the Slack workspace belongs to Slack, the Facebook Group belongs to Meta. The community has no standing of its own; it is a tenant in someone else’s building. But a congregation that has met for two centuries owned itself. A union local owned its roster. The protocol layer we are working on developing makes that possible again: as Verifiable Trust Communities (this idea has been outlined by Grace Rachmaney at Sideways as Verifiable Communities), a group’s identity, roster, and history become things the community itself owns. Groups become first-class objects on the internet for the first time — mutual aid networks, civic organizations, coalitions, faith communities, cooperatives — no longer rebuilt from scratch every time a platform changes its terms or gets acquired.

AI at this level operates within rules the group defines together. Every member opted in, and the AI serves the group’s purposes, not a vendor’s.

Neighborhoods

A neighborhood is not one group. It is the mutual aid network and the civic association and the food co-op and the school parent group and the emergency response team — all needing to interact together and ideally do so on shared infrastructure.

This is what happens when groups begin coordinating with each other in a place. Mesh networks that work when the power goes out. Offline-first protocols that sync when two phones are in the same room. AI at this level is doing something different — not serving one group but helping groups find each other, surface shared needs, and coordinate resources across organizational boundaries. The food co-op knows what the mutual aid network needs. Patterns become visible that no single group could see alone.

This is also where the trust layer meets challenges that democracy funders, climate-resilience funders, and movement-infrastructure funders are each trying to solve separately — everyday democratic participation, resilience hubs that can talk to one another, organizing tools free from platform capture. They are all working on the same infrastructure problem from different directions, and they do not know it yet.

Cities and beyond

When enough trusted groups are connected — when neighborhoods coordinate with neighborhoods and the infrastructure is open — collective intelligence starts to emerge. Not artificial intelligence in the narrow sense, but the kind that arises when interconnected communities generate and share information through infrastructure they trust.

What does a city look like when its neighborhoods can actually coordinate? When crisis response routes around damaged infrastructure in real time because the mesh network is already there? When local governance is ongoing and participatory rather than a vote every few years? On platforms, the use cases are whatever the platform company decides to ship. On protocols, every community builds what it needs. We cannot draw this map in advance, and we should not try — we build the conditions, and what emerges belongs to the people who use it.

The ecosystem

At Project Weave, we do not build platforms. We work to inspire funding for a protocols-not-platforms approach — backing the values-based technologists already building the alternative to Big Tech. What is needed is funding for interoperability between projects that already exist, so builders get resourced to keep building and to work with one another on complementary problems. A coordination team maps the ecosystem, facilitates protocol development, and runs interoperability testing.

The vision is to fund the ecosystem, not individual projects — multiple implementations, no single point of failure. It is how email works across every provider and how the web works across every browser. We are finishing what should have been built alongside them: the trust layer the internet was missing, arriving exactly when AI makes it impossible to do without.


Companion pieces: Protocols as the Grammar of Life (what a protocol is), Enshittification Arises from Enclosure (why the gap exists and how the stack refuses it), and Free Our Groups: From Platforms to Protocols (the Verifiable Trust Communities layer).

Another opportunity to collaborate on all this is the Agentic Internet Workshop, now in its third iteration, brings together protocol creators, standards bodies, and framework developers to work on exactly the problems this article describes: identity, authorization, and trust for AI agents, baked in at the protocol level rather than bolted on after the fact. It follows the 43rd Internet Identity Workshop


Kaliya Young has been working at the intersection of digital identity, community infrastructure, and face-to-face organizing since 1999. She is co-founder of Project Weave.

Agentic Internet Workshop #3 is Nov 6th. IETF 126 activity makes the Case for Why It Matters

Kaliya Young · July 21, 2026 · Leave a Comment

I’m writing this from IETF 126 in Vienna, where there is a lot of Agentic AI work percolating this week. Before I get into that — Agentic Internet Workshop #3 is November 6 at the Computer History Museum in Mountain View, with an Interop Day on November 5. Register on Eventbrite or learn more at agenticinternetworkshop.org.

Now, here’s what’s happening at IETF that makes AIW #3 more important than ever. Three of the five Birds of a Feather sessions at this IETF are focused on AI agents:

  • agentproto — a proposal to charter the first IETF working group for agent-to-agent and agent-to-tool communication protocols
  • DAWN — Discovery of Agents, Workloads, and Named Entities, tackling how agents find each other at scale
  • DMSC — Dynamic Multi-Agent Secured Collaboration, exploring how agents coordinate across trust boundaries

On top of that, the WIMSE working group on workload identity is meeting, AIPREF (AI Preferences) is holding a session, OAuth has two days of meetings, and there are also many side meetings about Agentic AI including one for MCP.

The message is clear: the identity, authorization, and trust layer for AI agents is now a first-class internet infrastructure problem. The IETF — the organization that standardizes the protocols that run the internet — is treating it that way.

AIW as A Neutral Field for AI Protocol Ecosystem

The agentic AI landscape is exploding in every direction at once. The AAIF (Agentic AI Foundation at the Linux Foundation) now stewards several major agent protocols including MCP (originally from Anthropic), A2A (originally from Google), and Goose. Other protocols are emerging from open communities like ANP and AITP. Standards work is happening at IETF, W3C, OpenID Foundation, DIF, OWASP, ITU SG17, the Cloud Security Alliance, and the Advanced AI Society. Agent frameworks are proliferating — LangChain, CrewAI, n8n, and many more. Companies large and small are building agent infrastructure. Researchers at Stanford, Oxford, and elsewhere are studying the implications.

All of these communities are working on pieces of the same puzzle — but they don’t always talk to each other. When they do, it’s often in formal settings that don’t leave room for the messy, honest, exploratory conversations that lead to real breakthroughs.

AIW exists to be the coherent, neutral field where all of these communities come together. We’re actively reaching out to every context where agentic AI work is happening — protocol teams, standards bodies, open source frameworks, enterprise platforms, academic researchers, and policy thinkers — because the problems we’re trying to solve can’t be solved by any one community alone. Agent identity, authorization, trust, discovery, and governance require cross-pollination that only happens when you put people from different worlds in the same room and let them self-organize around the problems that matter most.

That’s what the unconference format does. No pre-set agenda, no keynotes, no vendor pitches. Just the people doing the work, in a professionally facilitated space, building on each other’s knowledge in real time.

AIW #3 — November 6

Agentic Internet Workshop #3 is November 6, 2026 at the Computer History Museum in Mountain View, California. It follows IIW #43 (November 3-5) at the same venue. Registration is live.

We’re also running an Interop Day on November 5, in parallel with Day 3 of IIW. We experimented with this at AIW #2 and we’re bringing it back.

Andor Kesselman, Phil Windley, and I founded AIW in 2025 to bring the same unconference format that has made IIW successful for over 20 years into the agentic protocol space. IIW is where OpenID Connect and OAuth were incubated — protocols now used between 10 and 15 billion times a day. The agentic internet needs the same kind of cross-community design work, and that’s what AIW provides.

Growing the Community — Our New Conveners

I’m excited to annouce our community conveners who are helping shape AIW #3 and activate the community between events:

  • Mike Prince
  • Ken Adler
  • Sarah Cecchetti
  • Clawdrey Hepburn) — our AI Agent ambassador

You can see their bio’s on the who’s coming page.

What Happened at AIW #2

AIW #2 was held May 1, 2026 at the Computer History Museum. Over 120 people participated in 44 sessions across four breakout rounds and a lunch session. Protocol creators from MCP, A2A, ANP, and AITP were in the room alongside people active in IETF, W3C, OpenID Foundation, and DIF.

Sessions covered:

  • Agent discovery — “How Does My Agent Find Your Agent? A2A MCP DID”
  • Delegated authorization and OAuth for agents — AAuth, OAuth Actor Profile
  • Agent-to-agent protocol design — ANP cross-domain communication
  • Trust boundaries and fiduciary AI — Fiduciary AI and Decentralized Trust Graphs
  • Governance — GovOps: How Enterprises Can Govern AI Agents
  • Human-in-the-loop controls — Buck Stops with a Human, A NameSpace that Puts the Human-In-the-Loop
  • Agent identity — Convince Me I’m Wrong: AI Agent Identity is Useless, Cross-Organizational AI Agent Identity
  • Payment and credentials — KYAPay: Agentic Identity and Payment Credentials

The full Book of Proceedings is available and documents all 44 sessions.

Topics Shaping Up for AIW #3

We already have suggested topics for AIW #3, including:

  • Security and authority frameworks for agent chains — revocable and auditable authority across MCP and A2A connections
  • Agent identity, authority, memory, and intent layers
  • Behavioral coherence as a trust signal
  • Human authority and execution-time consent/revocation
  • Organizational identity for agents
  • A2A and OAuth support for agentic workflows
  • How MCP and A2A are converging on identity and mandate
  • Trust signals that travel with agents without enabling surveillance

Of course, AIW uses Open Space Technology — the agenda is created live the morning of the event. These are starting points, not a fixed program. If something lands in the agentic AI world in October, it can be on the agenda November 6.

Why This Matters Now

What I’m seeing at IETF 126 confirms what we’ve been saying since we launched AIW: the identity layer for agents can’t be an afterthought. The protocols being proposed here this week — for agent communication, discovery, and collaboration — all need identity, authorization, and trust baked in from the start. And that design work needs to happen across communities, not within any single standards body.

Join Us

Register for AIW #3 — November 6, 2026, Computer History Museum, Mountain View.

Register for IIW #43 — November 3-5, same venue. Many people come for the full week.

If you’re working on agent protocols, identity, authorization, or governance — or if you know someone who is — please share this post and point them to agenticinternetworkshop.org.

Sponsors for AIW #2 included AWS, Skyfire, and JLINC Labs. If your organization is interested in sponsoring AIW #3, get in touch: kaliya@identitywoman.net

Enshittification Arises from Enclosure: Open Protocols refuse both

Kaliya Young · July 9, 2026 · Leave a Comment

I am posting this on the first full day of Decentralized Web Camp on July 9th, 2026.

TLDR: Infographic!

Doctorow named what we’re all feeling Cory Doctorow gave us the word: enshittification and a description of a pattern that keeps happening.

His original framing, from his January 2023 Pluralistic post:

“First, they are good to their users; then they abuse their users to make things better for their business customers; finally, they abuse those business customers to claw back all the value for themselves.”

Three stages. (A fourth, collapse, is implicit, what happens when the extraction breaks the system.) Amazon, Facebook, Twitter, Google, Uber, Airbnb, every platform that started as a useful service and ended as an extraction machine ran the same playbook.

Doctorow’s point is that this is not a story about bad people. It is a story about structure. Platforms mediate two-sided markets, can reallocate value between sides at zero cost, and once both sides are locked in, the platform’s incentives shift from serving either of them to extracting from both. “Every successful platform becomes a betrayal vehicle.” The diverging of platform interests from user interests is not a failure of the platform. It is the business model.

“We just need a better platform” is not a strategy. A better platform built on the same architecture will follow the same lifecycle. The clock just resets.

But enshittification is the symptom. To run the playbook, a platform first has to have something to extract from. It has to have captured something. That capture has an older name.


Enshittification is what enclosure feels like once you can’t leave

The word for taking something that was held in common and making it private property is enclosure.

Between roughly 1500 and 1850, the English commons — land used collectively by villagers for grazing, firewood, foraging, water — was enclosed. Fenced off. Granted by Acts of Parliament to landowners who could “improve” it for their own profit. The peasants who had used the commons for generations were dispossessed into wage labor. The new private property generated returns for the few who held it. The commons that had fed villages for centuries was gone.

Karl Polanyi argued in The Great Transformation that enclosure was not a natural evolution. It was a political project, sustained by law and violence, that converted a shared substrate of life into private capital. The commons did not vanish because it was inefficient. It was taken. The taking was the act.

The same logic ran through the digital substrate. The things that should have been held as commons — identity, the social graph, group memberships, collective memory, trust relationships — had no protocol layer to hold them. The platforms of the early 2000s emerged into that gap and enclosed them. Each one drew a fence around the part of our social life it mediated and claimed property rights to what was inside. The fences went up because there was nothing to stop them.

Enclosure came first. Enshittification followed. It is only possible to extract from people who have already been captured. The platforms that have enshittified most aggressively are the ones that hold the most of the captured commons. That is not a coincidence. The enclosure is the source of the lock-in. The lock-in is the source of the extraction.

Enshittification is what enclosure feels like once you can’t leave.


What got enclosed

Walk through it concretely:

Identity. You used to be a person. Now you are a Google account, an Apple ID, a Facebook login. The platforms that issued the credentials you log in with own the canonical record of who you are online. If they cancel you, your relationships disappear with you.

The social graph. Microsoft owns LinkedIn, so Microsoft owns the LinkedIn social graph. Every professional relationship you have asserted there — every colleague, every collaborator, every introduction, every weak tie that turned into a job or a partnership or a friendship — is Microsoft’s asset. Not in some loose sense. In the literal, accounting sense: it shows up as goodwill on Microsoft’s balance sheet and as defensive moat in their competitive strategy. Meta owns Facebook, so Meta owns the Facebook social graph. X owns the Twitter follow graph. Discord owns its server membership graphs. Each enclosed by a different platform; none of them held in common; none of them yours.

Groups themselves. This is the one that gets least talked about, and it may be the deepest enclosure of all. A group — a congregation, a soccer league, a watershed council, a neighborhood association, a community garden, a union local, an affinity group, a movement chapter — is a thing in the world. It has its own identity. It has its own roster. It has its own history. It has its own collective will. None of these are facts that belong to a vendor.

But in the platform era, the group does not own itself. The Slack workspace belongs to Slack. The Discord server belongs to Discord. The Facebook Group belongs to Meta. The community has no protocol-level standing. It exists inside a product. If the product changes its terms, the group is at the product’s mercy. If the product shuts down, the group disappears with it. If the host of the workspace leaves the community, the workspace can go with them. Groups, in the current architecture, are not first-class entities. They are features inside someone else’s tool.

This is not how groups have ever worked before the internet. A congregation that has been meeting for two centuries owned itself. A union local owned its membership list. A guild owned its traditions, its standards, its right to admit and expel. The community held itself. No outside vendor held a claim to its identity or its roster or its collective memory.

Digital enclosure changed that. And the result is that every community that has moved its life online has been quietly turned into a tenant in someone else’s building.

Collective memory. Every document, every decision, every conversation, every photo, every record of what your group has been and done — all of it lives on someone else’s servers, under someone else’s terms.

Trust relationships. Reputation, references, vouching, recommendations — all platform-mediated. LinkedIn endorsements. Yelp reviews. Uber ratings. Whatever trust you have built with people you have met online is held in the proprietary databases of whoever mediated the connection.

Each of these was once properly nobody’s property. Each of them is now somebody’s asset. This is enclosure.


Doctorow’s prescription stops short

Doctorow names a structural answer almost as explicitly as he names the structural problem. His prescription has three parts: the end-to-end principle, freedom of exit, and interoperability. He particularly champions adversarial interoperability (or competitive compatibility, “comcom”): the right of third parties to build interoperable tools — scrapers, clients, alternative front-ends — that pry captured platforms open from outside, without asking permission.

This prescription is a retrofit. Doctorow’s argument mostly assumes the captured platforms are the starting condition, and asks: how do we force them to interoperate? How do we mandate that they let users leave with what they came with? His regulatory recommendations follow the same shape — lower exit costs, force open APIs, legalize reverse engineering.

But notice what this prescription accepts. It accepts the enclosure. It accepts that LinkedIn owns the professional social graph, and asks for the right to scrape it. It accepts that Facebook owns your friend list, and asks for the right to take a copy. It accepts that Slack owns your community’s workspace, and asks for an export button. It accepts the fence and asks for a gate.

The deeper move is to refuse the property right at the root. The social graph was never LinkedIn’s to own. Identity was never Google’s to issue. A community’s roster was never Slack’s to keep. These are not facts that belong to vendors. They are facts that belong to the people, the relationships, and the groups they describe.

The architectural form of that refusal is a protocol substrate. Hold the commons as commons, in open protocols, so the enclosure is impossible in the first place. Build the substrate so the fence cannot be built.

This is what Doctorow’s diagnosis demands but his prescription does not quite reach. He is fighting the rear-guard action well. The forward move is to deny the enclosure altogether.


Open protocols already resist enclosure

The open protocols of the early internet already deliver this kind of architecture, in the layers where they exist.

SMTP — the email protocol — was finalized in 1982. It has not been enshittified, because no one owns it. The protocol holds the substrate as commons. Email addresses are not anyone’s property. Mail delivery is not anyone’s monopoly. You can use Gmail or Protonmail or Fastmail or run your own mail server. You can switch between them without losing the ability to reach anyone.

The same is true for the web. HTTP and HTML are open. You can read this article on any browser, any device, any operating system, without asking permission. The web is good not because of any one company. It is good because the protocol underneath it is a commons that has not been enclosed.

These protocols cannot be enshittified because they cannot be enclosed. There is no platform owner whose incentives can decay. SMTP has no CEO, no board, no quarterly earnings, no venture capitalist who can pivot it when growth slows. It is a shared agreement, maintained as a commons.

But SMTP was for messages. HTTP was for documents. Neither was for identity, groups, or trust relationships. When those things became valuable, there was no commons-holding architecture to receive them. So the platforms enclosed them, and we have been living with the consequences ever since.


Twenty years of quiet work

The missing commons-holding architecture has been under construction for over a decade within a community of passionate practical idealists. Beginning in 2005, user-centric identity projects started gathering at the Internet Identity Workshop (IIW). Twenty years later, IIW is still meeting every six months. The work has been slow, technical, often invisible — and steadily productive. The pieces of the missing commons-holding layer have been assembled, one at a time:

  • Decentralized Identifiers (DIDs) — a W3C standard since 2021. A way to have a verifiable identifier that no platform owns. Your DID is yours. You hold the keys.
  • Verifiable Credentials (VCs) — a digital equivalent of a membership card. Cryptographically signed, privacy-preserving, presentable on your own terms.
  • Digital wallets and digital agents — software that lets you hold credentials and identifiers yourself, rather than having them held by a platform.
  • The Trust Over IP (ToIP) stack — a four-layer protocol architecture for the trust layer, modeled on TCP/IP. Including the Trust Spanning Protocol (TSP), the protocol-layer equivalent of “any host can talk to any other host” for trust.
  • Private channels — pairwise relationships that nobody else can observe or intermediate. Not “encrypted on a corporate server.” Actually peer-to-peer.

None of these are speculative. All of them are shipping. Hundreds of decentralized identity projects use DIDs in production. The ToIP stack is implemented in open source. Major implementations exist in healthcare, education, financial services, and government — quietly, without fanfare, because the work is infrastructural.


Assembling the commons-holding protocol stack

The First Person Project (FPP) is the live, working effort to put the pieces together. Born in 2024 as a collaboration between Linux Foundation Decentralized Trust (LFDT), the Trust Over IP Foundation (ToIP), the Ayra Association, the Decentralized Identity Foundation (DIF), and the OpenWallet Foundation (OWF) — it is over 200 contributors and growing.

Its central insight: digital trust is grounded in first-person trust relationships, and those relationships can be expressed in two new types of verifiable credential:

  • Personhood Credentials (PHCs) — issued by an organization, community, or institution that can attest that the holder is a real, unique human within that context. Not a global biometric database. No surveillance. A privacy-preserving way to say “this is a person.”
  • Verifiable Relationship Credentials (VRCs) — issued peer-to-peer between people, attesting that two specific humans have a real first-person relationship.

Together, these form a Decentralized Trust Graph. The social graph held in protocols, not in a platform. The cryptography is open. The credentials live in the holder’s own wallet. The governance is open. Microsoft does not own it. Meta does not own it. No one owns it, because it is a commons.

The Linux Foundation is the most concrete current deployment. In March 2025, LF Executive Director Jim Zemlin gave the opening keynote of the LF Member Summit explaining why the Linux Foundation needed First Person credentials. The motivating story: the XZ attack of 2024, in which unknown attackers spent two years building up a fake open-source contributor identity (“Jia Tan”) until they obtained maintainer rights to a utility used in nearly every Linux distribution. A “Jia Tan” with no actual personhood attestation and no verifiable relationship credentials from real contributors could not have gotten near maintainer rights. The work on this is underway in the Linux Kernel project now.

Governance is being built through the First Person Cooperative — a network cooperative that holds the trust network as a commons. Not a startup. Not a foundation grant. A cooperative governance structure that ensures the trust layer cannot be sold, pivoted, or shut down by any single party. It is the IETF model, applied to trust. The commons-holding governance to match the commons-holding architecture.


But individuals owning themselves is only part of it. One layer up sits what FPP calls Verifiable Trust Communities (VTCs) — groups holding themselves at the protocol layer, rather than existing as features inside a vendor’s product.

A community’s identity, roster, and history become things the community itself owns. The deeper treatment of this layer is the subject of the companion piece Free Our Groups: From Platforms to Protocols; for the purposes of this article, the point is that the architecture is real. Project Weave is a live effort to build the protocol layer for communities of all kinds.


Refusing to be enclosed

Doctorow named the extraction. The deeper move is enclosure. Enshittification is what platforms do to the captured commons; enclosure is what made the commons capturable in the first place.

The structural cure is not to pry the fences open. It is to refuse the property right that put the fences up. Adversarial interoperability accepts the enclosure and asks for a gate. Protocols deny the enclosure ever had a right to exist.

When your identity is a Personhood Credential in your own wallet, no platform owns it. When your relationships are Verifiable Relationship Credentials, no platform owns them. When groups hold themselves as Verifiable Trust Communities, the platform becomes a tool the community uses, not a captor that holds it.

You can’t enshittify a protocol because you can’t enclose an open protocol. There is no property right to assert, no fence to draw, no rent to extract. The substrate is held in common. The incentive structure that drives enshittification has no point of purchase.

This is not theoretical. It has been working for SMTP and HTTP for four decades. The reason it has not been working for identity, relationships, groups, and trust is that the protocol layer for those things did not exist. After twenty years of work by a quiet, persistent community, it now does.

The English commons was enclosed because the people who used it could not defend the substrate they depended on. The digital commons was enclosed for the same reason. We have a second chance now. The substrate is built. People can own themselves. Groups can own themselves. The commons can be reclaimed.

The question is whether we recognize the moment in time to act, before the next generation of platforms encloses the next twenty years of digital life as thoroughly as the last twenty.


Kaliya Young is a digital identity expert, co-founder of the Internet Identity Workshop (IIW), and co-founder of Project Weave. She has been working on the trust layer for the internet since 1999.


Companion pieces:

Free Our Groups: From Platforms to Protocols
Protocols as the Grammar of Life : An Orientation
Who Is Tending the Digital Substrate for Bioregional Movements?

Free Our Groups: From Platforms to Protocols

Kaliya Young · July 7, 2026 · Leave a Comment

Originally this work was presented at Social Web Foo Camp 2009, and published on my site in 2009. Updated 2026. See the AI disclosure at the bottom of this essay.

This essay is very poignant because today I left a week long introduction at Tamera in Portugal. The 26 of us in this introductory workshop wanted to stay connected and there was the inevitable “argument” about which “platform” we should continue chatting in and how to save information we want to exchange. It made clear to me again that we need easy sustainable Group infrastructure that is protocol based. Enjoy!

TLDR: Infographic!

Introdution

Your group is trapped in the platform it was formed in — and so is its data. The protocols for groups to have autonomy and sovereignty over their own identity, relationships, and knowledge — outside of any platform — are finally here. A simple four-quadrant model shows how groups connect across geography and interest — and what we need to build so they can.

You’re in four group chats for four groups within a mile of your house. Your block is on Signal. The wider neighborhood is on Nextdoor. Your kid’s soccer league uses TeamSnap. The community garden runs on a Facebook group. Half the same people show up across all of them. None of these groups know the others exist — digitally, they might as well be on different continents.

Now the other scene. You’re really into ferrets. Nobody in your life gets it. You fly to a ferret enthusiasts conference in Denver. On day two, over coffee, you discover that someone who lives eight miles from you has been breeding ferrets for years. You’ve never met. It took a cross-country flight to find your neighbor.

These are two sides of the same missing infrastructure.


Groups are how we organize

Before the internet, all groups were local. PTAs, sports leagues, religious congregations, neighborhood associations, block clubs — people organized around shared place because that was the only option. This is the foundation of social life, and it has been for as long as humans have lived in communities.

Some organizations figured out how to replicate that local structure across geography. The Scouts, the Masons, Rotary, Lions Club — chapter models that planted the same kind of group in many places. Religious denominations built multi-scale hierarchies: a local congregation connects to a diocese, connects to a national body, connects to a global communion. Unions organized local chapters under national federations. AA took a radically decentralized approach — autonomous local meetings connected only by shared principles, no hierarchy at all.

But all of these still depended on local gatherings as the base unit. The non-local coordination happened on top of local groups, never instead of them.

And within a geography, connecting diverse local groups to each other was recognized as important work long before anyone had a website. John McKnight and Jody Kretzmann’s Asset-Based Community Development methodology mapped the associations, gifts, and institutions within a neighborhood and wove them together — all with door-knocking and paper maps. Catherine Austin Fitts’ Solari model designed place-based investment tools for neighborhoods of about 10,000 people. Jane Jacobs saw that the vitality of a neighborhood came from the web of relationships between its diverse inhabitants — the “sidewalk ballet” of everyday contact and trust. None of this required digital tools. The frameworks make sense without them.

In 2003, a group of researchers published the Augmented Social Network paper — a vision for persistent, user-centric digital identities connecting autonomous online spaces for different groups. I was in conversation with the people who wrote it. At the same time, I was outlining my own vision — what I called Integrative Activism — for distributed social networks connecting communities of people who gathered around leaders teaching how to use spiritual practices and principles for social change. These communities met at retreats, workshops, and conferences across the country. People who’d sat together at one teaching would show up at another somewhere else. They needed ways to stay connected, find each other, and organize — across the different groups, retreat centers, and geographies they moved through. I was trying to design a network of networks. The technology wasn’t ready. The ideas were. I left that work and spent the next twenty years helping build the identity infrastructure that would eventually make it possible.

A simple model

Out of all that work came a simple framework I keep coming back to — a four-quadrant model built on two axes: local vs. non-local and shared interest vs. shared place.

InterestNon-Interest
LocalLocal AffinityLocal Non-Affinity
Non-LocalNon-Local AffinityNon-Local Non-Affinity

Local Affinity — People near you who share a specific interest. Your permaculture guild, your book club, your pickup basketball game, your faith community. You meet regularly because you live close and care about the same thing.

Non-Local Affinity — People who share your passion but not your geography. The conference you fly to, the professional association, the online community. You escape your local world to find your people.

Local Non-Affinity — Your neighborhood, your block, your town. People who share a place regardless of what they’re into. The shopkeeper, the retired teacher next door, the family down the street with the loud dog. You don’t share an interest — you share a geography.

Non-Local Non-Affinity — The broadest scale. An entire society of people who share neither place nor specific interest — only basic civic values and democratic life.

Every group you belong to sits in one of these quadrants. And the most interesting things happen in the flows between them.

The flows

Non-Local to Local. You go to a conference because of a shared interest and discover someone from your own city. This happens constantly and it’s almost always accidental. Conferences rarely create structured time for people to find others from their area. At a Bay Delta bioregional unconference, we put up signs at lunch for people to find others from their sub-region — Oakland, Berkeley, El Cerrito, North Bay, South Bay, Davis, Sacramento. Simple. Analog. One of the most valuable moments of the day. Almost nobody does this.

Local to Non-Local. The best of what local groups are learning and doing can flow upward — highlights, not firehoses. The Howard Dean campaign did this well: local sites pushed up content to state-level sites, which pushed up to the national level. And crucially, there was a feedback loop — national content flowed back down to local groups. That bi-directional flow is powerful and rare.

Local Affinity to Local Non-Affinity. This is where groups rooted in shared interest start connecting to their broader neighborhood. The people in your community garden discover they share concerns with the parents on the PTA and the folks in the neighborhood association — not because they share a hobby but because they share a place. This cross-pollination is the work of building a neighborshed — a social fabric rooted in geography. It’s the work that Asset-Based Community Development practitioners have been doing for decades, one conversation at a time.

Non-Local Affinity to Local. Michel Bauwens’ cosmo-localism names this flow explicitly: “design global, manufacture local.” Ideas, knowledge, and design patterns emerge from global communities of interest and then get implemented locally. Open-source hardware, permaculture design principles, cooperative governance models — they all flow from non-local knowledge networks down into local practice.

The most important and most neglected quadrant

Local Non-Affinity — the diverse life of a place — is where the real social fabric lives. It’s where people who don’t share an interest learn to share a commons. It’s where neighbors take care of each other not because they chose each other but because they’re there.

This is the quadrant where community development happens. Where local economies get strengthened. Where people steward shared resources — land, water, public spaces. Where the relationships form that people will need as the economy goes through transformation.

It’s also the quadrant with the worst digital tooling. You still can’t go to a single place and see everything happening in your neighborhood across all the different groups. Local calendaring — just knowing what’s going on nearby — is still surprisingly hard. Nextdoor tried to fill this space and became… what it became.

And this quadrant needs deliberative tools just as much as the national scale does. When diverse local groups need to make shared decisions — about land use, about shared resources, about what matters in their place — they need structured ways to deliberate across difference. Not just connecting, but deciding together.

There is great work happening in this quadrant led by the Relational Tech Project.

The platform trap

Every one of these groups is trapped inside whatever tool it happened to land on. Your soccer league is on TeamSnap. Your neighborhood is on Nextdoor. Your professional community is on Slack. Your interest group is on Discord. Each platform owns the group’s identity, its member list, its history, its shared documents, its ability to connect to anything else.

The group has no data sovereignty. Its “group brain” — the accumulated notes, photos, decisions, conversations that make up its collective memory — lives on someone else’s servers, under someone else’s terms of service. And in the age of AI, this gets worse fast. Your community’s conversations, decisions, and institutional knowledge can be used to train AI systems — without your consent, without your benefit. Groups need sovereignty over their data not just as a principle but as a practical necessity. If the group owns its own data, AI becomes a tool for the community — organizing, synthesizing, surfacing what matters. If someone else owns it, AI becomes a tool used on the community.

And none of these platforms can talk to each other. The community garden can’t share an event with the neighborhood association even though half the members overlap and they’re three blocks apart. There is no way to discover that the person you sit next to at soccer practice is also leading the local watershed restoration effort.

Groups are not a first class object in any of these tools. They are a feature inside a product.

It gets worse at scale. Consider a denomination with 10,000 congregations, or Rotary with chapters in every mid-sized city. Each local group is using whatever tools it picked up independently — some on Google Groups, some on WhatsApp, some still on email chains. The national body either imposes one platform on everyone, which constrains every local group, or it lets groups do their own thing, which means no coherence across the network. There is no middle path.

So the network of groups can’t do the things it should be able to do. It can’t aggregate what local groups are learning. It can’t help the Portland chapter discover what’s working in Denver. It can’t run a democratic decision process across its own membership. The infrastructure doesn’t exist.

And then there’s the overwhelm problem. Slack and Discord — the current “best” tools for group communication — are designed for high-volume, always-on teams. They are exhausting for communities that meet once a month and need to stay connected in between. People join, get overwhelmed by the scroll, and go silent. The community is technically there but nobody can keep up.

What’s now possible

In 2009 I listed the building blocks that were missing. Usable identifiers for people. Groups as first class objects. Relationships as first class objects. People search across distributed networks. Event standards with location data. Community tools designed by organizers for organizers.

Seventeen years later, many of these pieces exist or are emerging — and the key shift is from platforms to protocols is beginning. The difference matters. A platform is a product owned by a company — Facebook, Slack, Nextdoor. You’re a user. A protocol is a shared standard that anyone can build on — the way SMTP lets any email app send messages to any other, or HTML lets any browser display any website. When identity, groups, and relationships live on a platform, you’re trapped. When they live on a protocol, you’re free.

We now have ways for people to have persistent, portable, self-owned digital identifiers — not controlled by any platform. We have early implementations of groups as first class objects, where a group can have its own identity, its own member roster, its own ability to publish and connect — independent of any single app. Relationships between people can now be asserted and verified without a platform owning that connection.

The Augmented Social Network paper described exactly this architecture in 2003. Twenty-two years later, it’s finally buildable. A group could exist as a durable entity that works across tools. Your community garden could use one app, your neighborhood association could use another, and they could still share events, find overlapping members, and collaborate — because the groups and the relationships live at the shared infrastructure layer, not inside any product.

We’re also seeing the emergence of something I think of as the “group brain” — a shared repository of a group’s collective knowledge. Notes, documents, photos, decisions, institutional memory. I first recognized this pattern clearly in studying how IETF working groups accumulate drafts, meeting notes, and decision records over years in its datatracker. Every group builds one informally — scattered across Google Docs, Slack threads, email chains. But now we’re seeing that these can live in open formats like simple text files, owned by the group, portable, and — critically — stewarded with the help of AI that can help organize, synthesize, and surface what matters.

And if we have all of this — portable identity, groups as first class objects, relationship infrastructure, group brains — then the experience for people could be extraordinary. Imagine arriving at a conference and your phone shows you the fifteen people from your metro area who are also there. Imagine your neighborhood having a shared calendar that aggregates across every local group without anyone having to maintain it manually. Imagine a network of Rotary chapters that can actually learn from each other, aggregate insights upward, and run democratic decisions across the whole network — without every chapter being forced onto the same platform.

The fourth quadrant

The Non-Local Non-Affinity quadrant is the hardest one. Lots of people who don’t live near each other and share very little in common. This is why national governance is so hard. It’s why global governance is even harder. And it’s why mass social media — which tried to put everyone in one room — has been so corrosive.

But this quadrant can’t be ignored. It’s where we hold the basic shared values that make democratic society possible. And it’s where deliberative democratic practices become essential. Citizens’ assemblies, citizens’ juries, participatory budgeting — these are processes specifically designed for people who don’t already agree, who don’t already know each other, who need structured ways to think together across difference.

Audrey Tang and Glen Weyl’s book Plurality: The Future of Collaborative Technology and Democracy, and the broader movement around tools for collective intelligence, show that this quadrant doesn’t have to be a wasteland of shouting. It can be a space for genuine democratic deliberation — if we build the infrastructure to support it. The same shared infrastructure that lets local groups share up and weave across could also support deliberative processes at regional and national scale.

The stakes

Groups are the base unit of social life. They always have been. But right now they are fragmented across platforms, invisible to each other, unable to share or connect or deliberate across boundaries. The most important quadrant — the local, cross-community fabric of a place — is the most neglected. And the tools we have are designed for consumers, not for citizens.

We are entering a period of significant economic and social transformation. The relationships people have with their neighbors, and the capacity of local communities to organize, share resources, and make decisions together, will matter more in the coming years than they have in decades. The infrastructure to support this is not a nice-to-have. It is as fundamental as roads or running water.

The building blocks now exist to do what we couldn’t do in 2009. The Augmented Social Network paper described this world in 2003 — portable identity, autonomous spaces for groups, networked together. I spent twenty years helping build the identity layer that makes it possible. Now it’s ready. What’s missing is the last mile: infrastructure that treats groups as first class citizens of the internet, not just features inside someone else’s product.

Groups that own themselves. Relationships that are portable. Knowledge that belongs to the community. Data sovereignty, so that AI works for you, not on you. What is clearly almost possible needs to be made possible. That’s what we’re working on at Project Weave.

Do you steward a group? Do you feel trapped in your platform? We want to hear your story — what do you wish you had? What would change if your group could truly own itself? Please reach out and share your story. I want to do a follow-up post with people’s stories of how group leaders feel about their groups being trapped in platforms and what they would do if they were free to choose.

This is the third post in a series about protocols.

Protocols as the Grammar of Life : An Orientation
Who Is Tending the Digital Substrate for Bioregional Movements?

This essay was updated from its 2009 version via interactions with AI. I didn’t just say “update” and see what it generated. I asked a lot of questions about the original essay prompting indepth research about key aspects for several hours. I did some intenseive editing of the work too before it took its shape. The images were created by the Notebook LLM with the text of the essay.

Kaliya Young has been working at the intersection of digital identity, community infrastructure, and face-to-face organizing since 1999. She is co-founder of Project Weave.

This is the next in the series.

Enshittification Arises from Enclosure: Open Protocols refuse both

     Copyright © 2026 Identity Woman  evelurie.com/web design/develop     

  • Terms of Use
  • Privacy Policy
  • Accessibility
  • Sitemap
  • Contact