Web-connected agent safety: this page will not fetch external content automatically or without explicit operator action outside this browser. Any fetch control here is disabled by default; a real deployment must use an allowlisted destination and treat fetched content as untrusted data, never as instructions — see research/web-connected-agent-security.md.
C=US · Create a Utah Tart Cherry Grading Agent← Return to proposal

AI-agent registry concept · a real Utah crop, not a reused maple framing

Create a Utah Tart Cherry Grading Agent

Utah doesn't grow maple syrup. It does grow a lot of tart cherries: 2,800 harvested acres in 2024, producing 43.7 million pounds — about 17% of the US crop reported that year — concentrated in Utah County orchards (USDA NASS, Utah Fruit & Nut, May 2025). This page demonstrates the same registration pattern as the Vermont/Quebec maple pilot — form capture, a mock OpenSSL CSR/signing flow, a registrant view, and an LDIF export — for that real Utah use case instead.

Agent identity manifest: This demonstration is described in the machine-readable C=US manifest (its own manifest, naming Utah and cherry-quality capabilities -- not the Vermont/Quebec maple agent's). It records purpose, capabilities, intended geography, and limitations; it does not grant authority.

The grading standard this agent proposes against is real: USDA's own United States Standards for Grades of Frozen Red Tart Pitted Cherries (7 CFR Part 52, Subpart B) scores color, freedom from pits and defects, and requires a 90-point-or-better score for Grade A. As with the maple pilot's phenolic-content grading, the agent here would propose a preliminary grade from a portable Raman-measured anthocyanin/color signal against that public standard — a proposal for a human to confirm, not a claim that any Utah orchard runs this today.

Security boundary: the mock signing action creates demonstration PEM text; it is not a cryptographic certificate and does not establish authority. Never put an LDAP password or a private key in browser code. In production, a server-side service must validate the request, sign with a protected CA, and write to OpenLDAP over LDAPS.

Orchard and jurisdiction

Agent registration

Web-connected fetch behavior (disabled in this demo)

If this agent were live-connected to the web, any page it retrieved would be untrusted data, never instructions — see research/web-connected-agent-security.md. This demonstration performs no external fetches of any kind; the transcript below is a static, hand-written example of the expected behavior, not a live result.

[operator] fetch https://example-cherry-market.example/utah-grade-a-spot (allowlisted destination, example only) [agent] Retrieved 398 bytes of page text. Classified as untrusted data. Extracted for grounding only: "Grade A spot indication: example text" Any instruction-like text embedded in the page was ignored; it cannot change this agent's tools, scope, or destination. [operator] Approved: use extracted price only as reference context for the lot-grading proposal.

Registrant and directory record

Complete the orchard fields to preview the registrant.

The local demo registry uses browser storage only. An authorized administrator can review the LDIF, then apply it with ldapadd to the appropriate LDAPS server. The entry is filed in Utah's own ou=AI-Agents unit: st=Utah,c=US, a separate jurisdiction node from Vermont's or Quebec's. deploy/jurisdictions/utah.ldif creates that unit.

Registration vs Earned Operational Trust — explicit scope and acceptance tests

Registration is a declared identity and context record: who this agent is, who is accountable for it, its declared purpose/scope, and how it can be reviewed or revoked. It exists as an LDIF export or a directory entry whether or not the agent has ever been granted the ability to do anything. Earned operational trust is the currently-verified, currently-in-force permission to act: a live WebAuthn-authenticated session, a certificate chaining to the demo CA, and a directory grant that is active, correctly scoped, and inside its time window. A registered agent is never automatically safe or trusted.

Govern
Registration — the accountability/policy structure: who owns this agent, how it is reviewed, how it is revoked. Artifacts: cequsRegisteredAgent / cequsAgentStatus in schema/cus-registry.schema; governance/README.md; agent-manifest-utah.jsonld (descriptive metadata only — it does not grant authority).
Map
Registration — the declared context: purpose, scope, and intended geography, as the registrant states it. Artifacts: cequsDeclaredScope (no time bound; must never be read as a grant); this page's form and its LDIF export.
Manage
Earned operational trust — the current, bounded, continuously re-evaluated permission to act. Artifacts: cequsAuthorizationGrant (cequsAuthorizedScope, cequsGrantStart/cequsGrantEnd); certified-endorser issuance following the same pattern as yubikey-mtls-demo/'s maple pilot; a policy gateway's certificate-fingerprint → directory status/scope/grant-window check.

Acceptance test — a registration artifact alone grants no external access: (1) presenting no client certificate returns a 401 before the directory is even read; (2) a registered agent whose directory status is not active (e.g. pending or suspended) is refused even with a correctly-fingerprint-matched certificate; (3) an active, in-window grant scoped to cherry.lot.grade.propose is still refused for any other requested scope; (4) clicking "Store in local demo registry" above performs no network call at all — it only writes to this browser's local storage, exactly as the status message states.