Conferral by Design · essay
Machine trust will be allocated by contest unless we build it granted
v1.0 · about 1100 words · free to quote with attribution
Two agents are about to transact. One needs a task done — a payment routed, a supplier chosen, a claim verified — and the other offers to do it. In the few hundred milliseconds before the hand-off, one question gets answered, whether or not anyone designed a way to answer it: should this agent be relied upon? Multiply that moment by the billions of times a day it is coming, and you have the central design decision of the agent economy. Almost nobody is making it on purpose.
By default it will be made the worst possible way. When no verified basis for reliance exists, reliance flows to whatever signal is present — and the signals that are always present are confidence, fluency, speed, and the plausibility of the claim. The agent that answers fastest, asserts most cleanly, and presents the most convincing case gets trusted. That is reliance allocated by contest, and it is the exact mechanism that gave the human internet its spam, its SEO sludge, and its confident misinformation — now ported to a substrate with no friction, no fatigue, and no human in the loop to feel the wrongness. A contested market in machine trust doesn't select for reliable agents. It selects for persuasive ones, and it does so at machine speed, adversarially, forever.
This is the same fork the other two layers face, arriving in its purest form. A recommender can capture a human's attention or earn it; an agent can hold a user or serve them; and now two machines can allocate reliance by who sounds trustworthy or by who has been shown to be. But the agent-to-agent layer strips away the one safeguard the human-facing layers still have: a person who eventually notices. When a feed manipulates you, you can, in principle, feel worse and leave. When an agent in a delegation chain three hops from you trusts a persuasive counterparty over a reliable one, there is no one in the room to feel anything. The correction that human detection eventually forces — the reason counterfeit conferral trades at a deepening discount — doesn't operate automatically here. Detection has to be built, or it doesn't happen.
Which is why the reflex to import a "reputation score" solves nothing. A single number that agents can read is a single number that agents can farm. Any reputation signal allocated by contest — volume of transactions, self-reported success rates, star ratings an agent can generate for itself — becomes a target, and at machine speed a target is gamed before lunch. The failure mode isn't that machine reputation is hard to measure. It's that a reputation which can be claimed rather than attested, and accumulated rather than staked, is just the persuasion contest wearing a numeric costume.
The alternative is to build reliance as something conferred rather than won — and conferred trust has four structural properties a contest score lacks, each of which becomes a design requirement.
It rests on verified identity. An agent whose identity is unverifiable cannot be held to a track record, because there is no continuous entity to hold — every failure can be shed by respawning under a new name. No anonymous authority; reliance presupposes someone to rely on.
It is weighted by attested track record, not self-claim — the difference between a résumé and a reference who picks up the phone. What an agent says it can do is a contested signal; what a verifiable history shows it has done, attested by parties who stake something on it, is a conferred one.
It is staked and revocable. A grant of reliance with no logs, no attribution, and no consequence for misuse is not conferral but abdication: trust that cannot be withdrawn was never really extended, and trust whose misuse costs no one is trust no one had reason to place carefully.
And it routes through transferred trust that stays lossy. Agents will, and should, prefer counterparties vouched for by agents they already trust — A relies on B, B attests C, so A extends provisional reliance to C. That is how trust scales without everyone verifying everyone. But the transfer must spend something: a bad attestation has to damage the attester's own standing, or vouching becomes free and therefore worthless.
Put those four together and the general principle is visible underneath them: reliance allocated by contest propagates the persuasive; reliance allocated by conferral propagates the reliable — and only conferral survives adversaries who optimize at machine speed. A system that lets agents earn trust by sounding trustworthy is not neutral infrastructure that some bad actors will exploit. It is infrastructure that rewards exploitation, because in a persuasion contest the optimizer that will win is the one built to persuade rather than to perform.
The design consequence is a single sentence: an agent must not be able to be relied upon by being convincing — only by being verifiable, attested, and accountable. Practically, for anyone building an agent platform, a protocol, or a marketplace: make verified identity a precondition of participation, not a badge. Make track record something attested by staking counterparties, never something an agent reports about itself. Make every grant of reliance logged, attributable, and revocable, and make every attestation cost its author if it proves false. And refuse — actively, as a design principle — to expose any raw signal that lets one agent be chosen over another for seeming more confident.
The reason to care now, and not after the first disaster, is that this layer is the one place where the correction can still be native. Recommenders are locked in by a decade of revenue. Agents facing users are half-built and half-correctable. But agent-to-agent infrastructure is being specified this year, in protocols and standards that will ossify into the defaults everything else inherits. The engagement economy's tragedy was that its trust-destroying architecture was poured before anyone knew to ask whether it should be. Here, for once, we know to ask, and the concrete is still wet. The window is measured in product cycles, not decades — which means the choice between a machine economy that runs on attestation and one that runs on persuasion is being made, mostly by omission, right now.
This is the deep dive on Principle 7 and Layer 3 — the agent-to-agent greenfield first sketched in the pattern library, and scored under criteria 3, 6 and 10.
Score your own product against this. The Conferral Design Scorecard turns the whole argument into ten scored criteria with published anchors — free, deterministic, and nothing you enter leaves your browser. The complete methodology behind it is at Conferral by Design.
The other essays: Sycophancy is a counterfeit deposit · Session time is an anti-metric for agents · An ad in a list is not an ad in an answer · The same task, two designs (runnable) · The two numbers nobody publishes · Where these ideas come from