Argument Map
civic-proof Foundations (0' Academic Restatement): PRF, civic-proof, and the Conditional Floor of Democratic Legitimacy
civic-proof Foundations 0' (article 0') — Argument Map (v2)
When digital-identity infrastructure enters the public realm of a democratic polity in the concrete form of wallets, verifiable credentials, selective-disclosure user interfaces, and cross-jurisdictional trust lists, the normative lower bound of democratic legitimacy is borne by the Public Realm Floor (PRF) — the conjunction of Arendt's plurality, Habermas's validity, Pettit's contestation, and Mouffe's agonism. Civic proof is the operational concept that carries this floor into concrete engineering (wallets, AI-agent delegation, civic-action receipts, selective-disclosure UX, trust governance). The animating thesis — accountability does not require real-name identification — converges from three independent lineages (cryptography ∪ normative political theory ∪ US constitutional case law). The article bears a conditional floor: presupposes democratic context, does not claim PRF as unique standard, does not claim extrapolation to non-democratic regimes, does not claim definitive ground truth for cryptographic engineering. The 19 May 2026 revision adds AllenBridge as the institutional translation layer between PRF and Digital Civic Infrastructure (DCI), not as a fifth axis.
The academic 0' restatement of civic-proof. Two-layer analysis (issuance legitimacy + exchange architecture) + four demand types + four normative conditions + PRF four-strand conjunction + four engineering bearings + AllenBridge translation layer + cross-jurisdictional four-tier governance + universal-conditional comparative methodology + seven cross-country cases + Taiwan deep-dive + age-verification stress test + minimum-proof engineering + civic / sub-national experiments + public-blockchain trust layer + five policy principles × five methodological tools + conditional closure.
Two_Layer_Analysis : DigitalIdentity ≜ ⟨I_layer, E_layer⟩
Civic_Proof_Demand ∈ {LegalID, AttributeProof, UniquenessProof, PseudonymousParticipation}
NormativeConditions = anonymity ∧ unlinkability ∧ verifiability ∧ accountability
Convergence_Thesis :
accountability(d) ⇏ realname(d)
proof_lineages = crypto ∪ normative_political_theory ∪ US_const_caselaw
PRF ≜ plurality ∧ validity ∧ contestation ∧ agonism
T_PRF1..4 : each component individually necessary, irreducible
T_PRF5 : engineering unreachability — no engineering design bypasses the floor
LegitimacyDegrade(d) = σ(Σ βᵢ violation_intensityᵢ) ; θ_dem ≈ 0.5 (analytic suggestion)
Engineering_Bearings :
Wallet : three_presupposition (individual ownership ∧ identification ∧ private_key) — degradation paths
AI_Agent : 5×3 = 15 cell matrix, two structurally_non_delegable cells (first-personal mens rea + legitimate adversary)
Receipts : 14 field groups + 23 leaf fields + C1–C6 + T1–T4 + T2' UI unreachability
UX : C7–C10 + supporter UI three-layer separation (CRPD Art. 29 + GC No.1 §26–29)
AllenBridge(d) = political_equality ∧ rights_of_participation ∧ no_monopoly ∧ co_ownership ∧ input_to_action_loop
AllenBridge ⊥ PRF ; not fifth axis ; translation layer between PRF and DCI
CrossJurisdictional_Governance = ⟨G_industry, G_state, G_recognition, G_oversight⟩
+ four_redress_gaps + three_tier_rights_language + functional_demos(operational)
Comparative_Methodology : universal_conditional_distinction
universal_part = structural_necessity ; conditional_part = mechanism_bearing + coupling + scope
Policy_Agenda : 5 principles × 5 tools (likelihood-by-mechanism, working/strengthened thesis, universal-conditional, anti-mythologization, intuition-vs-claim separation)
Conditional_Closure :
¬claim(PRF = unique_standard)
∧ ¬claim(universal(across_all_regimes))
∧ ¬claim(definitive_ground_truth(crypto_engineering))
∧ presuppose(democratic_context)
The article is the academic 0' restatement of the 0417 origin presentation. It integrates the 25-article civic-proof series, four retrofits, Taiwan deep-dive, capstone, and the AllenBridge revision into one bearing structure with explicit conditional closure. Each section bears one component of the structure; the closure binds the article to a floor reading (necessary conditions), not a unique-standard reading.
PRF- Public Realm Floor — Arendt plurality ∧ Habermas validity ∧ Pettit contestation ∧ Mouffe agonism; the normative floor of democratic legitimacy under digital-identity intervention.
civic_proof- The operational concept carrying PRF into engineering — four demand types each with minimum normative conditions.
AllenBridge- The institutional translation layer between PRF and Digital Civic Infrastructure (DCI); added by the 19 May 2026 revision.
T_PRF5- Engineering unreachability lemma — no engineering design can bypass PRF; F1's two structurally-non-delegable cells (first-personal mens rea + legitimate adversary appearance) are firm.
θ_dem- Analytic-suggestion threshold ≈ 0.5 for LegitimacyDegrade(d); not empirically calibrated; calibration is future work.
functional_demos- Operational retreat from democratic constitutional community (demos) for cases of contested sovereignty recognition; analytic scope internal to the polity.
Civic-proof as engineering-only or normative-only frame
Two failure modes are explicitly rejected. (i) Engineering-only: civic proof as just selective disclosure + ZKP + wallet engineering; the political-philosophical floor is treated as motivation, not as binding constraint. This collapses civic-proof into a privacy-tech vocabulary that cannot speak to legitimacy questions. (ii) Normative-only: civic proof as just a political-philosophical claim with engineering attached as illustration; the four engineering bearings are treated as examples, not as structurally constrained by T_PRF5. This collapses civic-proof into a manifesto.
engineering_only ⇒ collapse(legitimacy_register)
normative_only ⇒ collapse(structural_constraint)
Two-layer + four-component + four-bearing + bridge + conditional closure
The article holds engineering and normative registers in mutual constraint: PRF imposes T_PRF5 (engineering unreachability), so engineering cannot bypass the floor; conversely, normative claims must be borne by engineering-checkable form (civic proof, AllenBridge five criteria) to remain operationally relevant. The conditional closure explicitly bounds the article from manifesto register and universal-template readings.
PRF ⊨ T_PRF5(engineering_unreachability) ; engineering ⊨ AllenBridge_check(institutional_direction)
conditional_closure binds reading
P1
Two-layer analysis (I + E)
whyConceptual scaffolding — separates sovereignty / legal-effect questions from transport / presentation questions.
I_layer (issuance legitimacy) concerns sovereignty, revocation rights, legal effect — why a credential is worthy of belief. E_layer (exchange architecture) concerns wallet, browser, presentation, verifier, trust list — how a credential is held, transported, presented, audited. The last decade's real change is at E, not I. Conflating the two produces tangled policy debates; separating them makes the four engineering bearings tractable.
DigitalIdentity = ⟨I, E⟩ ; analytic_separability ; jointly_required
P2
Civic proof: four demand types + four normative conditions
whyThe operational concept — replaces 'who you are' with 'what the situation requires you to prove.'
Four demand types: legal identity (verifiable + redressable); attribute proof (selective disclosure + unlinkable + no phone-home); uniqueness proof (pseudonymous + Sybil-resistant); pseudonymous participation (anonymous + accountable + supervised audit chain). Four normative conditions: anonymity, unlinkability, verifiability, accountability — must hold conjunctively for the demand type. The surface contradiction between anonymity and accountability is dissolved by P3.
∀ demand : ∃ subset(NormativeConditions) : minimum_required(demand)
surface_contradiction(anonymity, accountability) dissolved_by P3
P3
Accountability ⇏ real-name (three-lineage convergence)
whyAnimating thesis — every subsequent section refines or stress-tests this convergence claim.
(i) Cryptography: selective disclosure, ZKP, BBS+ unlinkable signatures, revocation status lists, auditable evidence chains enable presentation without full identity yet support ex-post audit. (ii) Normative political theory: Bovens 2007's answerability + enforceability does not presuppose specifically-natural-person-identifiable addressee; Pettit 2012's contestability operates on positions, not on real names. (iii) US constitutional case law: Talley v California 1960, NAACP v Alabama 1958, McIntyre v Ohio 1995 — anonymous expression preserved while accountability mechanisms preserved.
⋀ lineageᵢ ⊨ accountability ⇏ realname ; convergence ≠ single_lineage_argument
P4
Public Realm Floor (PRF) — four-strand conjunctive floor
whyNormative core — bears the regulatory lower bound of democratic legitimacy for digital-identity interventions.
Arendt plurality (three ontological layers: natality + mortality + uniqueness); Habermas validity (Geltungsansprüche: Wahrheit / Richtigkeit / Wahrhaftigkeit; Öffentlichkeit + Sluice model); Pettit contestation (active stance + Equally Accepted Terms + Equally Accessible Influence + editorial democracy); Mouffe agonism (legitimate adversary: mutual recognition + shared rules + agonistic frame). Each individually necessary (T_PRF1–4); none substitutable by the others. T_PRF5: engineering unreachability — no engineering design bypasses the floor. PRF is a floor, not the unique standard; open to Rawls / Sen / Nussbaum / Honneth as ceiling or boundary conditions.
PRF = plurality ∧ validity ∧ contestation ∧ agonism ; T_PRF1..5
LegitimacyDegrade(d) = σ(linear_combination) ; θ_dem ≈ 0.5 analytic_suggestion
PRF ⊂ NormativeFloors ; not unique
P5
AllenBridge — translation layer (not fifth axis)
why19 May 2026 revision — adds Allen as direction, not floor.
Political equality + rights of participation + no monopoly + co-ownership + input-to-action loop. The bridge does not introduce new normative ground; it converts PRF's necessary conditions into engineering-checkable directional criteria. Not admitted as fifth axis (would double-count Pettit / Arendt / Habermas / Mouffe, force matrix reopening, mismatch altitude). The full bridge argument is borne by the separate Danielle Allen bridge article (article 26).
AllenBridge ⊥ PRF ; ↣ DCI ; bridge_check ≠ floor_violation
P6
Four engineering bearings + AllenBridge check
whyOperational core — the four concrete engineering surfaces where PRF is borne, plus a fifth bridge check.
(i) Wallet: three presuppositions (individual ownership + identification + private key) and their degradation paths — exclusion of dementia patients, cognitive-impairment users, minors, undocumented refugees ⇒ plurality violation. (ii) AI agent: Tomasev five-element × civic-proof three-element = 15 cell matrix; two cells structurally non-delegable (first-personal mens rea + legitimate adversary appearance). (iii) Civic-action receipts: 14 field groups + 23 leaf fields + C1–C6 necessary conditions + T1–T4 + T2' UI unreachability theorem. (iv) Selective-disclosure UX: C7–C10 + supporter UI three-layer separation (CRPD Art. 29 + GC No.1 §26–29). (v) AllenBridge engineering check: non-monopoly + intelligibility + input-to-action loop + co-ownership + backup capacity.
⋀ bearingᵢ ⊨ PRF_translation ; T_PRF5 ⊨ none_bypass_floor
P7
Cross-jurisdictional governance + comparative methodology
whyInstitutional infrastructure — four-tier governance, four redress gaps, three-tier rights language, universal-conditional methodology.
Four-tier governance: G_industry (W3C / OpenID / ISO) + G_state (sovereign legal authorisation) + G_recognition (cross-national MoUs, soft law) + G_oversight (DPAs, human-rights commissions, civic audit). Four redress gaps: verifier refusal + erroneous revocation + vendor failure + cross-border privacy leak (+ candidate fifth: AI-agent cross-border attribution). Three-tier rights language: pre-legal interest / institutional entitlement / treaty-level human right. Functional-demos operational definition for sovereignty-contested cases. Universal-conditional distinction: structural necessity (universal) separated from mechanism / coupling / scope (conditional).
Governance = ⟨G_industry, G_state, G_recognition, G_oversight⟩
Redress_Gaps = {verifier_refusal, erroneous_revocation, vendor_failure, cross_border_leak} ∪ {AI_attribution}
Rights_Tiers = {pre_legal, institutional, treaty}
Methodology = universal_conditional_distinction
P8
Cases (7 cross-country + Taiwan deep-dive)
whyComparative empirical grounding — under explicit anti-mythologization clause.
Seven cases: Taiwan (MOICA + TW DIW hybrid; trust list on chain); EU (eIDAS 2.0 + EUDI Wallet); Sweden (commercial BankID); US (state-level mDL + federal NIST guidance); MOSIP (modular open source); India Aadhaar (national-scale eKYC); Bhutan NDI (Ethereum-mainnet anchored). Cross-case comparison constrained by universal-conditional methodology — universal part (PRF structural necessity) shared; conditional part (mechanism / coupling / scope) varies. Taiwan deep-dive (article 24) bears conditional-typical case + existence-pressure proof under triple pressure (α cognitive warfare + β cable disruption + γ grey-zone).
cases = {TW, EU, SE, US, MOSIP, IN, BT} ; comparison ⊨ universal_conditional_only
Taiwan = conditional_typical + existence_pressure ; anti_mythologization binding
P9
Policy agenda — 5 principles × 5 tools + AllenBridge reinforcement
whyOperationalisation of the framework into policy-relevant discipline.
Five principles: privacy-first baseline; open wallets + standardised provisioning; procurement sandbox; testbed network; AI-agent delegation into main line. Five methodological tools: working / strengthened thesis discipline; universal-conditional distinction; likelihood-by-mechanism four-level; anti-mythologization clause; design-intuition / normative-claim separation. AllenBridge reinforcement re-frames each principle under power-sharing: privacy as co-ownership; interoperability as platform-monopoly reduction; procurement as exit + audit + alternative-path acceptance; testbed as input-to-action measurement; AI agent as participation-capacity extension.
PolicyAgenda = (5_principles × 5_tools) + AllenBridge_reinforcement
B1
But the four PRF strands are not necessary — three would suffice
pivotT_PRF1..4 reductio_construction ⊨ ¬∃ valid 3-strand reduction
The necessity argument is borne by T_PRF1–4 in reductio form: for each strand i, no design d that violates i and satisfies the other three can be legitimate (proof by structural-necessity counter-example construction). The four strands bear independent normative content (plurality = ontological 'who'; validity = communicative-reason rationalisation; contestation = redress structure; agonism = political-opposition structure). Reducing to three loses one independent normative ground.
B2
But θ_dem ≈ 0.5 is empirically uncalibrated — the LegitimacyDegrade function is vacuous
pivotanalytic_suggestion ⇏ empirical_calibration_claim ; falsification_path well_defined ; calibration ∈ future_work
θ_dem is explicitly an analytic suggestion, not an empirical measurement; the article does not claim empirical calibration. The function's bearing is structural: it formalises 'violation of PRF triggers legitimacy degradation' as a conditional implication whose falsification path is well-defined (find a case violating PRF without legitimacy degradation). Empirical calibration is enumerated as a priority future-work item (capstone §8).
B3
But the engineering bearings are too specific — they will become obsolete
pivotstructural_condition_level ⇒ primitive_obsolescence_robust ; T_PRF5 ⇒ exclusion_persists
Specific cryptographic primitives (BBS+, ZKP, status list) will evolve. The four engineering bearings are stated at a structural-condition level (e.g., 'six necessary conditions for civic-action receipts'; 'supporter UI three-layer separation') that is independent of specific primitives. New primitives that satisfy the conditions are absorbed into the framework; primitives that do not (e.g., 'AI agent can substitute for first-personal mens rea') are excluded by T_PRF5.
B4
But the framework presupposes democratic context — what about authoritarian regimes?
pivotdemocratic_presupposition explicit ; non_democratic ⇒ independent_framework ; ¬ scope_overreach
The conditional closure makes this presupposition explicit. PRF's normative force depends on judicial-audit capability, electoral cycles, civil society — none guaranteed under authoritarian conditions. Pseudonymous-accountability mechanisms (audit chain + court-supervised re-identification) require an enforceable judicial overseer; without one, the same mechanism becomes a tool of harassment. The article does not claim universal applicability; non-democratic contexts require an independent argumentation framework.
Conditions under which the foundations 0' framework holds
The article's bearing is conditional. It presupposes a democratic political context with judicial-audit capability, trust-root availability, and deployment-mature cryptographic infrastructure. Outside these conditions, the framework's normative force is weaker or absent. Each condition is enumerated.
PRF's four-strand conjunction and the pseudonymous-accountability mechanism both depend on democratic institutions. The article does not extend to authoritarian regimes.
democratic(polity) ⇒ applicable(PRF) ; ¬democratic ⇒ independent_framework Some authoritative I-layer must exist — sovereign state credential or recognised institutional issuer. Pure self-sovereign roots remain experimentally interesting but have not (as of 2026) sustained legal-identity-grade civic action at scale.
∃ trust_root ∈ {sovereign, recognised_institution} : anchors(civic_proof) Selective disclosure, unlinkable presentation, client-side proving, supporter UI, and revocation infrastructure must be deployment-mature. As of 2026, revocation infrastructure remains the weakest link in most national systems.
mature(crypto) ∧ mature(supporter_UI) ∧ mature(revocation) ⇒ deployable(civic_proof) For cases of contested sovereignty recognition (Taiwan), the analytic scope is the functional democratic community (citizens + long-term residents actually participating in elections, taxation, health insurance, private associations). Cross-border issues require independent argument.
contested_sovereignty(polity) ⇒ functional_demos(operational_scope) The 0.5 threshold is analytic suggestion. Empirical calibration via regression across at least five independent cases is future work.
θ_dem(empirical) ∈ future_work The 0' restatement bears one structure: PRF as conjunctive floor of democratic legitimacy; civic proof as the operational concept; the convergence thesis (accountability ⇏ real-name) as animating claim; four engineering bearings as PRF translation; AllenBridge as direction-translation between PRF and DCI; four-tier cross-jurisdictional governance + universal-conditional comparative methodology + seven cross-country cases + Taiwan deep-dive + age-verification stress test + minimum-proof engineering + civic/sub-national experiments + public-blockchain trust layer + five policy principles × five methodological tools.
The conditional closure binds the article to four constraints: (i) PRF is a floor, not the unique standard — open to Rawls / Sen / Nussbaum / Honneth; (ii) framework presupposes democratic context, does not extend to authoritarian regimes; (iii) does not claim definitive ground truth for cryptographic engineering — T_PRF5 forbids engineering bypass but does not assert engineering optimality; (iv) the Taiwan deep-dive bears anti-mythologization clause — universalisation strength downgraded to 'hypothesis extrapolable to a weaker conditional subset.'
The 19 May 2026 revision adds AllenBridge as the institutional translation layer between PRF and Digital Civic Infrastructure. Civic proof's task is therefore not merely to make credentials more private, verifiable, and portable — but also to keep the gateway to public action participable, contestable, co-ownable, and responsive. The full bridge argument is borne separately by article 26.
Higher-priority future work: empirical calibration of θ_dem (regression across ≥ 5 cases); independent argument for the civilian-backup PRF mapping (avoiding smuggling civilian advocacy texts as normative claims); delegation-boundary expansion under AI-agent proactivity upgrade (when agents move from passive delegation to active reasoning); minimal-conditional-variable set for cross-case comparison (e.g., Taiwan / Estonia / Bhutan); PRF temporal dynamics under election / crisis / regime-transition cycles; Chinese-localisation bearing (qun / gong / jianyi / zheng-you); cross-domain application of universal-conditional distinction as general methodology.
PRF ⊨ floor(democratic_legitimacy) ; civic_proof ⊨ operational_concept
accountability ⇏ realname (convergent : crypto ∪ normative_theory ∪ const_law)
Engineering_Bearings ⊨ PRF_translation (T_PRF5 : no bypass)
AllenBridge ⊥ PRF ; ↣ DCI (translation layer, not floor)
ConditionalClosure : democratic_context ; not unique ; not universal ; not ground_truth
→ civic proof as conditional, structural, and engineering-checkable bearing of democratic legitimacy under digital-identity intervention.