Sentient Identity

OctoMY's Sentient Identity (SID) system provides cryptographic identity for human operators — and any conscious entity in the future.


What is a Sentient Identity?

A Sentient Identity (SID) is a cryptographic identity representing a human operator. It owns one or more Node Identities (NIDs) — the personalities a robot assumes.

Key properties:

Why "Sentient"? We chose this over "Person" or "User" because it encompasses any conscious entity — humans today, and any being capable of subjective experience in the future.


Shadow vs Full Sentient

Shadow (SSID) Full (FSID)
Password None User-chosen (20+ chars)
Security Physical access only Password + encrypted hive
Identicon Ghost shape Normal face
Created Automatically on first boot User upgrades from shadow
Device owner No First to set password

The ghost identicon (faded, wavy-bottomed face) is the visual indicator that you're using a shadow identity. Tap it to upgrade.


SID vs NID

Aspect Sentient Identity (SID) Node Identity (NID)
Represents A human operator A robot personality
Created Auto (shadow) or manual Via delivery wizard or menu
Owns NIDs, hive, recovery phrase Config, trust, firmware settings
Switching Locks hive, changes encryption Changes active personality
Storage SentientVault in hive Per-NID folder in hive

One SID can own multiple NIDs. NIDs are mutually invisible — "Gustav" and "Johnny" on the same device never see each other's config or peers.


Components

SentientVault

Secure storage inside the encrypted hive containing:

SentientCard

A shareable identity bundle with disclosure levels:

Level Shared
Minimal ID + public key (anonymous but verifiable)
Basic + display name
Full + identicon + attributes

Cards are signed for authenticity and can expire.

Face Identicon

A unique 16x16 pixel-art face generated deterministically from the SID's public key. Each face has unique hair, skin, eyes, mouth, freckles, and blush. The identicon appears in the Lanyard, contact lists, pairing UI, and profile badges.

Shadow sentients show a ghost identicon (wavy bottom edge, cut corners) with the tooltip "Shadow identity — not password-protected."


How It Works

First Boot (Automatic)

  1. App launches → StartupStateMachine finds no identity, runs the §SP-1 silent auto-create
  2. BIP39 recovery phrase generated (12 words)
  3. Ed25519 keypair derived from phrase; SID = sha256(publicKey)
  4. Sentient hive created with the typed on-disk id SID-<sid-hex> and mounted with an internal shadow passphrase
  5. Shadow sentient created with a SentientNameGenerator random name (e.g. curious_otter) + ghost identicon
  6. Optional upgrade prompt fires once via SecurityUnboxingActivity (Set a passphrase or Skip)
  7. Ready to use — first-boot is interruption-free past that single optional prompt

See the First Boot how-to for the full walkthrough.

Typed-Hive Taxonomy

Hives on disk carry their type and owner in their identifier (§HT-1):

On-disk id What it stores Display
SID-<sid-hex> A sentient's vault, contacts, and per-node hive keys Looks up the owning sentient and renders their friendly name + identicon
NID-<nid-hex> A node's per-node data — NodeStore folder, OPAL history db, courier blobs Looks up the owning node and renders its friendly name + identicon
Free-form name General-purpose hive (future) — user-named, not tied to a sentient/node Renders the literal name; no identicon

The user never sees the raw SID-<hex> / NID-<hex> strings — every UI surface (Lanyard, lobby activities, status widgets) looks up the owning entity and renders its display name. Renaming a sentient updates the display everywhere without changing the on-disk id; nothing has to be re-mounted.

This taxonomy replaces the pre-spec "System" hive name. Pre-makeover installations carried a literal "System" hive owned by the device's primary sentient; post-spec each sentient's hive carries the SID-derived id and there is no privileged System slot. The auto-create path in §SP-1 produces the first SID-<hex> hive without ceremony — the user sees their friendly name, never the system internals.

Upgrading to Full Sentient

  1. Tap the ghost identicon in the navigation bar
  2. Optionally change your display name
  3. Set a password (20+ characters)
  4. Hive header re-encrypted with your password (O(1) operation)
  5. You become the device owner (Capture the Flag)
  6. Ghost identicon transitions to normal face

Sharing Your Identity

  1. Open Sentient from the navigation bar
  2. Tap Share Identity
  3. Choose disclosure level
  4. Share via QR code or clipboard

Privacy by Design

  1. Preview the card that will be shared
  2. Click Create Card to generate a QR code
  3. Share the QR code with your contact (in person or via screenshot)
  4. Optionally click Copy to Clipboard for the card data

Pro Tip

For maximum privacy, start with Minimal disclosure. The recipient can verify you're a consistent identity without knowing your name. You can always share a more detailed card later.

Managing Contacts

To view and manage your contacts:

  1. Navigate to Sentient in Hub's main menu
  2. Click Contacts
  3. Browse your contact list

Each contact shows:

Click a contact to view details and manage the relationship.

Trust Levels

You can set trust levels for each contact:

Level Meaning
Pending They shared with you, awaiting your decision
Accepted You've acknowledged this identity
Trusted Higher trust (e.g., verified in person)
Blocked Rejected - won't receive messages from them

Pending Requests

When network sharing is enabled, the Pending badge shows how many contacts are awaiting your decision. Click it to review and accept or reject each request


Security Considerations

Key Storage

Your private key is:

Key Loss

Important: If you lose your private key, you lose your Sentient identity. There is no recovery mechanism (by design - this prevents identity theft).

Consider:

Verification

Others can verify you are who you claim by:


Hive Integration

Your Sentient identity is stored inside the encrypted Hive filesystem:

When switching Sentients, the current session closes first with a confirmation prompt.


Current Status

The Sentient Identity system is functional with the following features:

Coming in future updates:


Component Reference

Component Description
Sentient Core identity data structure
SentientCard Shareable identity bundle with disclosure levels
SentientVault Encrypted storage for identity and contacts
SentientRelationship Contact data structure with trust levels
KnownSentients Contacts database (SimpleDataStore)
SentientIdenticon 16x16 pixel-art face generator (39 parameters, deterministic from ID hash)
SentientIdenticonWidget SvgWidget subclass for displaying face identicons
SentientBadge Card-style profile display widget (uses face identicon)
SentientCardWidget Reusable card display with QR option
SentientListItemWidget Contact list item widget (uses face identicon)
CreateCardWidget Disclosure level selector with preview
ShareSentientWidget QR code share screen
SentientActivity Main sentient profile activity
KnownSentientsActivity Contacts list activity
SentientDetailActivity Contact detail view
CreateCardActivity Card creation wizard
PendingRequestsActivity Pending contact requests
SentientIdenticonEditorActivity Debug editor for identicon parameters
HiveSession Session manager tying Hive + SentientVault
SentientMetadataCache Non-sensitive display cache outside encrypted hive