Establish identity and key control
The operator first establishes an authenticated relationship with a trust authority. It registers a persistent agent sub under a controlled domain and a P-256 binding key, then completes the authority's domain and key-control challenges. Domain control must have been verified no more than 12 hours before issuance. The operator therefore treats the domain as identity infrastructure because confirmed loss of control blocks every registered agent anchored to it.