Nick and I have spent months trading ideas on how old standards tech holds up under agentic weight, and the proof-of-concept that answers it is his — built directly out of that back-and-forth. It carries UMA 2.0 into agent-shaped mechanics, paired with Dick Hardt's AAuth for agent identity and proof-of-possession.
UMA was built for exactly this kind of asynchronous, policy-based consent — what I described last year (for those of you who remember O.G. web access management) as solving “WAM for people”: Alice gets access management controls of the sort only enterprises normally use, and Bob's agent is told how and where to ask for access instead of simply being denied.
In the demo, Alice is a brokerage client and Bob is her financial advisor. His firm's agent asks for her holdings summary: granted automatically, purpose-bound and expiring, decided against terms Alice set in advance. Her transaction history: granted too, under stricter terms she dictated. Then the agent asks to place an actual trade — Alice's policy says “ask me” — so the request pends, her phone buzzes, and she approves that one trade, and only that trade, from her couch. Every connection, every promised term, every action taken lands in her activity ledger, and she can revoke any of it, any time.