Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

U-STACK: What If Apps Were Guests and Users Owned Everything?

Every app you install re-solves the same four problems: who you are, how money moves, where your data lives, and who can access what. Your identity in one app has nothing to do with your identity in another. Your data li

Every app you install re-solves the same four problems: who you are, how money moves, where your data lives, and who can access what. Your identity in one app has nothing to do with your identity in another. Your data lives inside each app's walls. And every AI agent acting on your behalf today does it by borrowing your credentials — which is both insecure and unauditable.

I wrote a working paper formalizing an alternative. It's called U-STACK, and its thesis is simple: identity, value, data, and permission should be user-side infrastructure, and applications should be guests operating under explicit, revocable, auditable grants.

The seven layers

The stack has seven layers, each depending only on the ones below it:

  1. U-ID — one portable identity for humans, organizations, devices, and AI agents. Agents are first-class citizens with a declared principal — never credential-borrowing hacks.
  2. U-WALLET — one value layer per identity: ledgers, escrow, subscriptions, royalty splits, with compliance as pluggable policy rather than an afterthought.
  3. U-VAULT — your data, encrypted, versioned, living with you. Apps hold grants, never ownership. Revoking a grant provably ends access.
  4. U-PERM — the consent engine: fine-grained, time-bound, legible permissions with an append-only audit log. Default-deny everywhere; delegation can only narrow, never widen.
  5. U-WORK — an event-driven workflow OS. Approvals are permission grants, so separation of duties is enforced by architecture, not convention.
  6. U-DEV — the developer platform: app registry, serverless runtime, and AI-agent deployment with declared capability bounds. Revenue settles automatically from the ledger.
  7. U-SECTOR — pre-wired industry bundles (finance, healthcare, education, government, commerce, logistics, AI economy) that collapse adoption cost for entire verticals.

The composition argument, compressed: layers 1–4 are control (whoever defines the primitives defines the game), layer 5 is lock-in (you can export data, but not operations), layer 6 is scale (two-sided network effects), layer 7 is sector capture.

The closest thing that already works

I'm not claiming this is unprecedented. India's digital public infrastructure is the existence proof: Aadhaar for identity, UPI for real-time payments, DigiLocker for documents, ONDC for open commerce, and the Account Aggregator framework for consent-based data sharing — which is a direct ancestor of U-PERM's consent engine. U-STACK can be read as DPI generalized: the same layered, protocol-first philosophy, extended to all data, all permissions, workflows, and developers — with AI agents as first-class citizens, which no DPI stack yet provides.

Why agents change everything

There's a reason this architecture puts AI agents at the center. Right now, an agent that books your flights or manages your calendar does it by holding your passwords — a security model that collapses the moment agents become capable enough to matter. U-STACK gives every agent its own identity with a declared principal, its own wallet with spending bounds, and permissions scoped to exactly what it needs. When the agent acts, the audit log shows which agent, whose authority, and what grant — not a shared login.

The honest part

This is a specification, not an implementation. No layer has running code. No wire formats, no security proofs, no performance measurements. The paper says this explicitly in a section I call the honesty ledger, because a target architecture should never be mistaken for shipped software.

What I am confident about: the layering is right, the invariants are the right ones (default-deny, attenuation-only delegation, auditability by construction), and the direction — users owning primitives, apps as guests, agents as citizens — is where the puck is going.

Shivam Kumar is an AI researcher and founder of VisionQuantech. U-STACK is working paper #2 in the VisionQuantech architecture series.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.