Docs

who vs capturedBy

One job: the two grains, exactly, so no integration ever collapses them.

spine:whospine:capturedBy
meaningthe attested observer — a human, an agent, or an embodied agentthe warrantor — the account whose key opened the door
originasserted by the callerstamped by the gateway
the door's halfgraded: the door sets spine:attestationGrade, and the grade reaches only claimed until identity attestation landsstamped: whatever the caller sent in this field is stripped and replaced
resolutionresolves via id.org.ai — Agent. Human. Thing.the account itself

One is stamped, the other is graded; they never merge. Party and organisation grain are derived at read time from grant chains, never stamped on an event — the record survives your reorg and your revocations.

The transcript

Capture the attested-observer fixture through the MCP door, then read it back — executed 2026-07-31 against epcis.dev@0.1.0 over stdio. What went in carried spine:who and no warrantor:

{
  "spine:who": "https://id.org.ai/agents/dock-scanner-7",
  "spine:activity": "https://event-spine.internal/activities/inbound-receiving/run/42"
}

What came back out of query carries the caller's assertion graded, and the door's stamps beside it:

{
  "type": "ObjectEvent",
  "eventID": "urn:uuid:8a1b2c3d-4e5f-4a6b-8c7d-0e1f2a3b4c5d",
  "eventTime": "2026-07-19T11:45:00.000Z",
  "eventTimeZoneOffset": "+02:00",
  "epcList": ["urn:epc:id:sgtin:0614141.107346.2021"],
  "action": "OBSERVE",
  "bizStep": "receiving",
  "disposition": "in_progress",
  "readPoint": { "id": "urn:epc:id:sgln:0614141.00999.0" },
  "spine:who": "https://id.org.ai/agents/dock-scanner-7",
  "spine:activity": "https://event-spine.internal/activities/inbound-receiving/run/42",
  "recordTime": "2026-07-31T18:42:58.622Z",
  "spine:capturedBy": "urn:epcis.dev:cli:local",
  "spine:attestationGrade": "claimed"
}

Read the last three lines as the door's signature: recordTime (when the door heard), spine:capturedBy (the local CLI account — the warrantor on your bench), and spine:attestationGrade at claimed — the caller asserted an observer, and the door recorded exactly how far that assertion reaches. Had the payload arrived with its own recordTime, spine:capturedBy or spine:attestationGrade, the trust-boundary rule applies: stripped, then stamped.

Why two fields

capturedBy answers "whose key wrote this record" — an accountability fact the door can warrant, so the door stamps it. who answers "who observed the moment" — a claim about the world the door cannot warrant, so the door grades it instead. Collapse the two and you either promote a claim to a warranty or demote a warranty to a claim; either way the record stops being evidence. The grade names the gap honestly, and the grade is queryable: spine:who, spine:activity, spine:attestationGrade and spine:warrantedBy are usable as query predicates, subject to the reader's grain.

We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.