From Credentials to Demonstrated Mastery

Conventional authorization grants access on the basis of credentials, role assignments, or static permissions: a license, a degree, or an organizational position attests to past training or position and then persists regardless of whether competence is current. The mechanism disclosed in this chapter replaces that model with evidence-based capability gating. A capability gate is a governed evaluation point that stands between a requester, which may be a human operator, a semantic agent, or a composite system, and a capability the requester seeks to exercise. The gate evaluates the requester's accumulated performance evidence and produces a binary determination: the gate opens, granting access, or it remains closed, denying access.

The evidence on which the gate acts is not a credential. It is demonstrated performance evidence: observations, measurements, and assessments that directly measure the requester's ability to exercise the capability competently in the current context. That evidence is accumulated through a curriculum engine and through continuous operational monitoring that observes performance after a capability has been granted. Because monitoring continues, the gate is a continuous evaluation rather than a one-time assessment: it may close again, revoking a previously granted capability, if ongoing evidence indicates that competence has degraded below the required threshold.

The Language Model as Untrusted Proposal Generator

Every large language model integrated into the platform occupies the structural role of an untrusted proposal generator. The term is used in contradistinction to the conventional assumption that a model's output is authoritative, that is, a response or decision the consuming system may adopt without independent validation. In this disclosure no model output is authoritative. Every output is a proposal: a candidate semantic mutation that must be independently validated and either accepted, modified, or rejected by the agent-resident infrastructure before it can affect any agent field, execution state, or downstream behavior. The model occupies the role of proposal-maker; the agent, through its resident validation engine, occupies the role of decision-maker.

This confinement is architectural, not a runtime check that could be misconfigured or disabled. The execution pathways are constructed so that no model output can reach any agent field, governance decision, certification token, or capability gate without first passing through the validation engine. There is no bypass path and no trusted-model exception. The motivation is an epistemic asymmetry: the agent possesses verified state whose fields carry a provenance chain of cryptographically signed, policy-validated, lineage-recorded mutations, while the model maintains no persistent state across calls, tracks no provenance for its own outputs, and cannot distinguish well-grounded outputs from confabulated ones. The language model is therefore used for inference, and the governed substrate determines what may mutate.

The Curriculum Engine as Governed Evidence Generator

The curriculum engine defines, sequences, and administers the learning and assessment activities through which requesters accumulate the performance evidence that capability gates require. For each gated capability it defines a structured curriculum comprising a set of learning objectives, a set of assessment instruments, a sequencing policy that determines the order in which objectives and assessments are presented, and a mastery threshold for each objective specifying the performance level required to satisfy it.

Each curriculum is a governed object. Its definition, sequencing, and modification are subject to policy constraints and lineage recording. Adding a learning objective, changing a mastery threshold, or resequencing assessments are governed mutations that are validated, policy-checked, and recorded in the curriculum's lineage. This governance ensures that curricula cannot be weakened, shortened, or bypassed without a governed policy change attributable to a specific governance authority and auditable through the lineage. The curriculum is administered within the semantic agent framework, so the agent, not a model, selects and sequences what evidence is collected.

Progressive Unlock

Capabilities are not granted in a single assessment event. The curriculum engine implements progressive unlock: a capability is unlocked progressively as the requester demonstrates mastery of increasingly complex or critical aspects of the capability. The progressive unlock model ensures that requesters are exposed to simpler aspects before being granted access to more complex or higher-risk aspects, and that accumulated mastery evidence reflects demonstrated competence across the full scope of the capability rather than performance on a single assessment.

The capability gate evaluates the accumulated mastery evidence against the defined competency thresholds for the capability. Where the evidence satisfies the thresholds, the gate produces a progressive unlock outcome and the requester is granted access. Where the evidence indicates competency degradation below the required threshold, the gate produces a regression or revocation outcome and access is denied or revoked. The gate's decision is the structural unlock event; it is not a model judgment.

Multimodal Evaluation and Anti-Gaming

The evidence on which gates act is acquired through a multimodal evaluation pipeline that processes evidence from multiple modalities simultaneously, including text input, audio input with vocal prosody analysis, video input with facial expression and gesture and gaze analysis, sensor-telemetry input such as force-torque and motion-capture data, and biometric input such as heart rate variability and galvanic skin response. Each modality is processed by a modality-specific module that produces a structured score vector, and a fusion engine computes a composite evaluation that accounts for the degree to which the independent signals corroborate one another. A learner who scores high on text assessments but whose biometric signals indicate elevated stress and cognitive overload receives a composite that reflects that tension rather than averaging it away.

The same multimodal evidence serves as an anti-gaming substrate. Cross-modality consistency enforcement flags cases where textual responses indicate mastery while physiological signals indicate confusion or reliance on external assistance. Temporal pattern analysis detects response-timing patterns indicative of coaching, remote assistance, or automated response generation. Spoofing detection uses continuous identity verification and behavioral-biometric continuity analysis to detect substitution of a different individual for the registered learner. And when gaming is detected, the trust weight assigned to model proposals that reference the compromised evidence is reduced, so the reduced trust weight causes the arbitration engine to prefer alternative proposals or to reject the unlock proposal entirely.

Certification Tokens and Their Lifecycle

When a capability gate opens, the system generates a certification token: a cryptographically signed data object that attests to the holder's demonstrated mastery of the capability at a specific point in time, under specific assessment conditions, as evaluated by specific instruments. The token is not a credential in the conventional sense, not a role assignment or static badge. It is a time-bounded, evidence-backed, cryptographically verifiable attestation subject to expiration, revocation, and revalidation. Its fields include a capability identifier, the holder's identity, an evidence hash that lets verifiers confirm the token was issued on specific evidence without accessing that evidence, issuance and expiration timestamps, the policy scope, the issuing authority, a device entropy binding, and the issuing authority's signature.

The token participates in a defined lifecycle. Upon issuance it is active and may be presented to capability gates and verification services. Upon expiration it becomes inactive and the holder must re-demonstrate mastery. Upon revocation, triggered by evidence of mastery regression, incident reports, or governance intervention, it is invalidated regardless of whether it has expired. Upon revalidation, triggered by successful re-assessment, a new token is issued with fresh evidence bindings. Each lifecycle transition is recorded as a governed event in the holder's lineage. A token may also be presented across platforms: a receiving system verifies the signature against the issuing authority's public key, validates expiration status, and evaluates policy-scope compatibility before accepting it within the scope the token defines.

Skill Regression Detection and Capability Revocation

After a capability is granted, the system continues monitoring the grantee's performance. This monitoring produces a continuous evidence stream that is evaluated against a regression threshold, a defined performance floor below which the grantee's demonstrated competency is deemed insufficient to maintain the grant. If subsequent performance falls below that threshold, indicating skill decay, context change, or gaming, the capability is automatically revoked and the grantee must re-demonstrate competency through the same evidence-based pathway that originally granted it. The regression threshold may be set at the same level as the original granting threshold or at a lower level to provide a buffer against transient dips, as specified by policy configuration.

Revocation is protective. The system records the revocation event, the evidence that triggered it, and the performance trajectory leading to revocation in the grantee's lineage. Revocation may trigger a mandatory cooldown period during which the grantee may not re-apply, so that re-demonstration reflects genuine competency recovery rather than short-term performance variance. A related drift detection and decay layer down-weights evidence that is aging or was produced under conditions that no longer obtain, and can identify a learner whose assessed competence is drifting downward across successive assessments even when each individual assessment still satisfies the mastery threshold.

Biological State and Embodied Domains

The skill gating subsystem is integrated with the biological identity system so that gating decisions are conditioned not only on what the requester has demonstrated but also on the requester's current biological state. This addresses a limitation of even evidence-based authorization: a capability demonstrated at one point in time may not be safely exercisable later if the operator is fatigued, impaired, or distressed. When a requester presents a certification token, the gate first verifies the token's cryptographic validity and evidence backing, then queries the biological identity system for a real-time assessment of fatigue, cognitive load, emotional distress, and impairment, and evaluates that assessment against biological fitness criteria defined for the capability. A high-criticality capability such as vehicle operation may require low fatigue and no impairment indicators; a lower-criticality capability has more permissive criteria. Where the requester does not meet the fitness criteria, the gate restricts or denies access despite a valid token, recording the biological evidence that triggered the restriction.

The same gating, curriculum, and certification machinery extends to embodied domains where incompetent operation can cause physical harm. In autonomous vehicle instruction, a driver skill monitor evaluates vehicle dynamics and operator gaze and posture against a driving competency curriculum and manages an autonomy-level gate that dynamically increases intervention for novice or impaired operators. In robotic assistant control and industrial machinery, capability gates evaluate demonstrated mastery of operational envelopes, safety zones, and emergency procedures, with hazard-prevention overrides that intervene on uncertified operations, impairment, or detected hazard conditions. In extended-reality and virtual-reality training, immersive simulation generates rich sensor evidence whose progressive unlock rules govern access to more complex scenarios and, ultimately, to operational authorization in the physical domain.

Disclosure Scope

The evidence-based capability gating mechanism described here, comprising the capability gate as a governed evaluation point producing a binary open or closed determination, the curriculum engine as a governed evidence generator with policy-constrained and lineage-recorded curricula, progressive unlock across increasingly complex aspects of a capability, the multimodal evaluation pipeline and its use as an anti-gaming substrate, the language model confined to the role of untrusted proposal generator validated by the agent-resident validation engine, the certification token and its active, expired, revoked, and revalidated lifecycle with cross-platform deployment gating, the skill regression detection and automatic capability revocation against a regression threshold, the integration of real-time biological state assessment into the gating decision, and the application of the mechanism to embodied vehicle, robotics, industrial, and XR/VR domains, is disclosed in the cognition filing (U.S. Application No. 19/647,395) in the chapter on LLM integration and skill gating. This article describes that disclosed mechanism. The scope extends to alternative evaluation modalities, policy configurations, certification token forms, and embodiment domains not enumerated, provided model outputs remain non-authoritative proposals and capability access remains gated on validated performance evidence rather than on credentials.