Draw up a capital request.
State what your business needs. In the next article you will set, precisely, what an agent may do about it — and compose a portable draft of that authority. Drafts stay on this device until you explicitly save them to an account. Nothing is transmitted on page load, while drafting, or at review — and never to any third party.
The Request
The Authority
The mandate is the instrument that says, provably, what an agent acting for you may do. Grant narrowly. Everything below is revocable at will.
Permitted acts — granted by you
Never delegable — locked in v1
Only you can pledge yourself. An agent cannot.
Refused by default, everywhere, categorically.
Ceremonies belong to humans. The agent orchestrates; you execute.
Bounds
The Instrument
Read it as a lender's counsel would. Then compose it — your device computes the draft's SHA-256 digest and prints you a receipt for those bytes, all of it here, none of it sent. That digest is the fingerprint anyone holding a copy can recompute to see the copy is unaltered. Minting is the separate, account-bearing passkey ceremony below.
Capital Authority Mandate
It's the key to your saved drafts — no password to steal, nothing to remember. Your device holds the key; we hold the drafts you save, and a record that you saved them.
Stored with surrounding spaces trimmed; leave it blank and your account simply carries no name.
The form has moved past this saved draft — save again to mint the new terms.
This device is not holding this draft's original bytes, so there is no file to hand you here — the digest above is what any copy of it must still match.
Optional. We grade them and record that you answered — it is how we check the instrument reads the way it was written.
Under this mandate, may your agent submit applications without your per-application review?
What all-in cost ceiling did you set?
What this is — and is not (v1)
- On your device by default. No draft leaves this page until you save, mint, or sign in — no analytics, no beacons, no autosave, no cookies until you create an account. Anonymous, the page talks to no one: every asset it loads — typefaces included — comes from capital.new, it calls no APIs, and nothing you type is transmitted at all. Signed in, opening it reads your session and lists your saved drafts, and nothing more.
- Saving is explicit. An account stores your drafts so you can resume, mint, and revoke — nothing is sent until you act. A save sends the draft you see and how long the ceremony took; both are appended to a hash chain, each entry hashed over the one before it.
- Tamper-evident, which is not tamper-proof. We re-derive the whole chain from its stored fields on a schedule, so a row edited out of band — by a privileged operator, a restored backup, a migration run by hand — surfaces as a broken link instead of a quiet change. What we cannot yet claim is independence: the chain is ours and the re-derivation is ours, so until its head is published somewhere outside our control, the check rests on us running it honestly. Removing entries from the end leaves the remaining links intact and moves only the count, which is why the count is published for you or anyone else to watermark. An external anchor is later work, and is named as owed rather than implied to exist.
- Minted here means platform-witnessed. A mint is your passkey ceremony, with user verification, recorded in a tamper-evident ledger; portable signed credentials come later, and nothing here pretends otherwise.
- Not credit advice, not an offer, not an application. A statement of authority, drafted.
Evidence trail
These entries live in one global ledger, so each is hashed over the entry before it in that chain — not over the one above it here. What your device re-derives, entry by entry, is that hash, the bytes it was taken over, and the draft digest it names.
Your drafts
Held in your account under your passkey. Open a draft and you land back in the ceremony with every field as you left it — nothing here is a dashboard.
Verify a draft
Paste a mandate draft. Your device recomputes its digest and compares it to the one embedded in the file — the same replay any counterparty would run. Nothing is uploaded. What a match establishes is that the file is whole: unaltered since its own digest was taken. It is not evidence of a mint, because both the bytes and the digest being compared come from the file in front of you.