---
title: The Authority Layer for Agentic Commerce | OneID
description: Identity infrastructure for agentic commerce. Verified human, verified intent, delegated authority, and an audit trail regulators will accept.
---

Authority Layer

# The Authority Layer for Agentic Commerce

Agents can act. Payments can process.

But no one proves who authorised the action.

OneID provides verified **Authority to Act** with enforceable permissions and auditable **Privacy Consent**.

[Explore How It Works](https://oneid.uk/agentic-commerce#flow) [View Developer Integration](https://oneid.uk/agentic-commerce#integration)

Human → OneID → Authority Layer → Agent → Merchant → Payment Network

## What's Missing in Agentic Commerce

Agentic commerce is being built by AI platforms, payment networks and wallets.

But a critical layer is missing: **Authority**.

- Agents can transact, but cannot prove Authority to Act
- Merchants cannot verify user consent or intent
- Payments confirm execution, not authorisation
- No independent proof of what the user agreed to
- Without Authority, autonomy cannot scale safely

## What Goes Wrong Without Authority to Act

### Rogue Agents

Misconfigured agents acting outside user expectations

### No Non-repudiation

Users can dispute actions they claim they never authorised

### Invalid Privacy Consent

User consent inferred from agent behaviour, not directly captured

### Merchant Liability

Merchants exposed to risk without proof of authorisation

## OneID: The Authority Layer

We provide verifiable Authority to Act for every agent-driven interaction.

Verified Intent

### Authority to Act

- Actions signed by a verified human identity
- Cryptographic, non-repudiable proof
- Independent of agent and merchant

Delegation Service

### Programmable Authority to Act

- Users define what agents are allowed to do
- Constraints: spend limits, merchants, categories
- Control autonomy levels (human in/out of loop)

Privacy Consent

### Explicit and Auditable

- User consent captured directly from the individual
- Not inferred from agent behaviour
- Full audit trail for GDPR and regulatory compliance

## Control How Agents Act on Your Behalf

Three levels of autonomy, each with clear Authority to Act and Privacy Consent requirements.

Level 1

### Human in the Loop

User approves every action

Authority to Act

Per-action approval required

Privacy Consent

Explicit consent per transaction

Level 2

### Guardrailed Autonomy

Agent acts within defined constraints. Step-up only when required.

Authority to Act

Pre-authorised within limits

Privacy Consent

Scoped consent with boundaries

Level 3

### Human out of the Loop

Fully pre-authorised actions within limits

Authority to Act

Blanket delegation with constraints

Privacy Consent

Broad consent with audit trail

### The Trust Infrastructure for Agentic Commerce

Authority, Trust and Delegation  
in Autonomous Transactions

New Whitepaper

### How do you regulate commerce when neither party is human?

This paper sets out the compliance infrastructure required for autonomous agents to transact with provable authority, bounded delegation, and audit-grade evidence.

- •Why existing identity frameworks break for agent-to-agent commerce
- •A credential model for delegation, policy and revocation
- •Sector-specific blueprints for fintech, payments and marketplaces

 Read the whitepaper

×

#### How do you regulate commerce when neither party is human?

Fill in your details and we'll send the whitepaper straight to your inbox.

## Privacy Consent You Can Prove

In agentic commerce, agents often accept terms on behalf of users. This creates a critical gap.

### The gap

- Did the user actually consent?
- Can the merchant prove it?
- Who is liable if challenged?

### OneID solves this by

- Capturing consent directly from a verified identity
  
  Not inferred or assumed
- Binding consent to the specific transaction or delegation
  
  Cryptographically linked to the action
- Providing an auditable record of Privacy Consent
  
  Immutable, timestamped evidence

Consent must come from the user, not the agent.

## How Authority to Act is Established

1. 1
   
   User verifies identity (OneID)
2. 2
   
   User creates delegation (Authority to Act rules)
3. 3
   
   User sets Privacy Consent preferences
4. 4
   
   Agent acts within constraints
5. 5
   
   OneID verifies intent + authority
6. 6
   
   Merchant receives:
   
     - Verified intent
     - Authority proof
     - Required identity attributes directly
7. 7
   
   Payment is executed via network

## Why This Matters

Business outcomes that enable safe autonomous commerce.

### Enable Safe Transactions

Allow autonomous actions with verifiable authorisation

### Increase Conversion

Pre-authorised actions reduce friction and improve completion rates

### Reduce Disputes

Non-repudiable proof reduces chargebacks and disputes

### Verified Attributes

Receive identity attributes directly without over-collection

Payments prove a transaction happened.

OneID proves it was authorised.

## Built for Agentic Ecosystems

- API-first integration
- Works alongside payment networks and wallets
- Independent verification layer
- Supports identity attributes, delegation logic and consent capture

### Ready to Integrate?

Build agentic commerce with verifiable Authority to Act and Privacy Consent.

[View API Documentation](https://docs.oneid.uk/)

## Enable Agentic Commerce to Function Safely

OneID fills the missing Authority layer, enabling innovation within regulatory constraints.

[Talk to Our Team](https://oneid.uk/contact/) [Explore Integration](https://oneid.uk/agentic-commerce#integration)

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "GB",
    "addressLocality" : "Manchester",
    "postalCode" : "M2 1DH",
    "streetAddress" : "Work.Life, Core, Brown Street"
  },
  "alternateName" : "OneID UK",
  "areaServed" : "GB",
  "description" : "OneID is a global digital verification services provider. It confirms a person's identity and age in seconds, using multiple methods: bank-verified identity, document authentication, on-device facial age estimation, mobile network age checks, digital wallet credentials and international eIDs. OneID was one of the first identity providers certified under the UK Digital Verification Services Trust Framework (DVSTF), and is the first Orchestration Service Provider and the first Holder/Wallet provider. Its verification spans identity, age and agentic verification.",
  "foundingDate" : "2019-01-31",
  "identifier" : [ {
    "@type" : "PropertyValue",
    "propertyID" : "Companies House",
    "value" : "11800511"
  }, {
    "@type" : "PropertyValue",
    "propertyID" : "FCA FRN",
    "value" : "928911"
  } ],
  "knowsAbout" : [ "digital identity verification", "age verification", "Online Safety Act age assurance", "KYC and anti-money-laundering verification", "right to work checks", "Companies House identity verification under ECCTA", "agentic commerce identity", "UK Digital Verification Services Trust Framework" ],
  "legalName" : "ONEID LIMITED",
  "logo" : "https://oneid.uk/[confirm-logo-path].png",
  "name" : "OneID",
  "sameAs" : [ "https://uk.linkedin.com/company/oneid-uk", "https://www.crunchbase.com/organization/oneid-5d15", "https://find-and-update.company-information.service.gov.uk/company/11800511", "https://www.digital-identity-services-register.service.gov.uk/register/provider-details?providerId=4", "https://www.g2.com/products/oneid/reviews", "https://www.zoominfo.com/c/oneid-ltd/566160660" ],
  "url" : "https://oneid.uk"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Service",
  "areaServed" : {
    "@type" : "Country",
    "name" : "United Kingdom"
  },
  "audience" : {
    "@type" : "BusinessAudience",
    "audienceType" : "Platforms, merchants, payment providers and infrastructure operators building agentic commerce capability"
  },
  "category" : "Agentic commerce identity infrastructure",
  "description" : "Identity infrastructure for autonomous commerce. Verified human, verified intent, delegated authority, and an audit trail regulators will accept. Certified under the UK Digital Verification Services Trust Framework.",
  "name" : "OneID Agentic Verification — The Authority Layer for Agentic Commerce",
  "potentialAction" : {
    "@type" : "ReserveAction",
    "name" : "Book a briefing",
    "target" : "https://oneid.uk/contact"
  },
  "provider" : {
    "@id" : "https://oneid.uk/#organization",
    "@type" : "Organization"
  },
  "serviceType" : "Identity infrastructure for autonomous commerce",
  "url" : "https://oneid.uk/agentic-commerce"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Agentic commerce describes commercial transactions where an autonomous AI agent acts on behalf of a human buyer. The agent searches, negotiates, and completes purchases within the authority the human has granted. The category is moving from experimental to commercial across payments, retail and platform infrastructure."
    },
    "name" : "What is agentic commerce?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Identity in agentic commerce is verified at two layers: the human delegating authority, and the agent acting under that delegation. The human is verified once through a DVSTF-certified identity check. The agent acts under a credentialled delegation that ties every action back to the verified human, with an audit-ready evidence trail."
    },
    "name" : "How is identity verified for an autonomous agent?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "The Authority Layer is the identity infrastructure that sits between a verified human and the autonomous agent acting on their behalf. It records the scope of authority the human has delegated, binds the agent's actions to that authority, and produces an evidence trail regulators can audit. OneID provides this layer as a DVSTF-certified service."
    },
    "name" : "What is the Authority Layer?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Agentic commerce sits inside the existing UK regulatory perimeter for payments, financial services, consumer protection, and data protection. The Data Use and Access Act 2025 set the statutory frame for digital identity in the UK, including delegated and machine-to-machine use cases. Sector regulators including the FCA, ICO and DSIT are publishing guidance on agentic use."
    },
    "name" : "Which regulations apply to agentic commerce in the UK?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "OneID's Authority Layer integrates with existing payment rails through API and credential-based delegation. The agent presents a verified credential at the point of transaction, binding the payment to the verified human under the delegated authority. Payment providers receive the evidence record alongside the transaction."
    },
    "name" : "How does OneID's agentic verification work with payment rails?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Every action an autonomous agent takes under OneID's Authority Layer is bound to the verified human who delegated the authority. The audit record shows what was delegated, when, by whom, and which actions the agent took under that authority. The record meets the evidence requirements of DVSTF-certified identity services."
    },
    "name" : "How is delegated authority audited?"
  } ]
}
```