0Summary
Humanity is between two paradigms. One is late-stage extractive capitalism, which we call the Molochian shit show. The other is the heliogenic, life-serving civilisation. The first missing piece of infrastructure for the second is the heliogenic material stack: grown materials, provided as a global commons, that free people from material scarcity. Building that stack needs money, but money is not the binding constraint. Policy sits upstream of money, and coordination sits upstream of policy. GUANXI is a proposal for the coordination layer: the infrastructure for what Heliogenesis calls its second vector, Community Coordination, which replaces the extractive owner the way Material Independence replaces the extracted input.
The core idea is simple to state. Every person, organisation, solution and offering is represented by a software agent that knows what its principal needs, what it can give, and under which ethical, geographic and practical constraints. These agents meet in an open, distributed network. Where two agents alone cannot find a fair exchange, the network finds the third, fourth and fifth party who close the loop, exactly as a guanxi network in China resolves obligations across many people and many years without anyone keeping a monetary account, and as ayni in the Andes, utu among Māori, or the potlatch of the Pacific Northwest have done for as long as anyone can remember. The humans are shown who to give what to and from whom they receive, and they decide. Private data never leaves the principal's control. Agreements are signed by humans and recorded in witnessed, tamper-evident logs so that everyone can rely on their performance.
The research behind this paper changes three things about how the idea should be built.
- Language models read intent well and compute exchanges badly. Every empirical study since 2024 says the same thing: LLM agents infer preferences accurately, report them truthfully inside a mechanism, and explain outcomes well, but they anchor on opening offers, concede on rigid schedules, miscalculate, hallucinate commitments and are exploitable by emotional framing. GUANXI therefore uses LLMs for intent modelling, negotiation of disclosure and explanation, and a deterministic clearing solver for finding the exchange, as kidney-exchange programmes and national invoice set-off systems already do.
- Every component you do not run is an attack surface you do not have. The design uses only open-source software and open standards, runs on hardware the principals and their communities own, and depends on no cloud provider, no proprietary model, no chip vendor's trusted-execution promise, no public blockchain and no smart contract in its core. Where the earlier draft reached for a data-marketplace protocol and confidential cloud compute, this version reaches for a smaller specification, a memory-safe reference node, capability-scoped sandboxes, and trust placed in people one knows rather than in vendors one does not.
- "No money" is achievable; "no accounting" is not. Real obligation graphs are sparse. Pure cycle netting clears 10 to 25 percent of a B2B obligation graph; adding a tolerated imbalance in a unit of account, mutual credit, roughly doubles that to about 50 percent. GUANXI embeds no currency, but it does embed a ledger of who has given and received, and permits communities to extend credit lines, so that chains, not just closed cycles, can clear. Balances fade in both directions, as gifts do.
The paper draws on two bodies of thought beyond the engineering. Relational economics (Wieland; Bruni and Zamagni's civil economy) treats the transaction as a relational event and value as something created between parties over time, not extracted from one by the other. Indigenous economies worked this out long ago: Kimmerer's honourable harvest, Yunkaporta's kinship-mind, Māori whanaungatanga and utu, Andean ayni and minka, Ubuntu, the Haudenosaunee seventh-generation principle, the Balinese subak. GUANXI does not claim to implement any of them. It takes from them the design rules that a network of agents can honour: relation before transaction, the gift keeps moving, take only what you need, and decisions belong to those who live with them.
The technical architecture has seven layers: identity, vault, representative agent, discovery, negotiation, clearing, and commitment log, with a governance layer wrapping all of them. Each layer reuses an existing open standard where one exists (W3C DIDs and Verifiable Credentials, Solid, MCP, A2A, transparency logs, Semaphore) and specifies only what is missing: the intent profile, the multilateral clearing protocol, the bounded human mandate, and the governance of the commons.
Cost: a lean spec-and-pilot year costs roughly €1.2 million; a standard three-year programme that reaches a federated network with a few hundred thousand participants costs roughly €10 million; the marginal cost per participant at scale is a few cents to a few tens of cents per month, dominated by inference on community-owned hardware, and zero where agents run on the principal's own device. These figures sit inside the envelope of comparable protocol projects: Mastodon runs on under €1 million a year, the Matrix Foundation on about $1.2 million, and Bluesky needed about $36 million before its 2025 growth round.
1Background: between two paradigms
1.1 The diagnosis
The Molochian shit show is late-stage extractive capitalism and neocolonialism. It is not a moral failing of individuals but a coordination failure: a system in which each actor is compelled to extract because everyone else does, and in which two design flaws, debt-based money that compels growth and unlimited accumulation, lock the path in. It moves roughly 100 billion tonnes of material a year on 19 terawatts of energy and leaves 50 billion tonnes of waste, while the biosphere moves 150 billion tonnes on sunlight with none.
The heliogenic civilisation rests on a different premise: that three hundred thousand years of being human are stronger in each of us than the last three hundred years of extraction. People who spend a weekend in a forest, a ritual, a community kitchen or a good conversation remember what it means to be a human being, to be part of life, to live as nature rather than from nature. The remembering usually lasts until Monday, when the bills are due and the shit show resumes.
If the majority of humanity remembered this at the same time and coordinated along and across that memory, the paradigm would change today. The problem is not knowledge, and it is not even will. It is coordination.
1.2 Three constraints, in order
The first missing piece of infrastructure we identified is the heliogenic material stack: materials grown by biological processes, substituting for anything we currently mine or synthesise, provided as a global commons. Heliogenesis (heliogenesis.io), the full-stack institute for material independence that carries this work, puts it in one sentence: "We start at the molecule and we finish at the city." Bacteria-made cement replaces kiln-fired Portland, fungal panels replace acoustic foam, brewed protein fibre replaces polyester, and living materials stay alive after they leave the factory. The stack carries energy, water, materials, food and shelter together, nothing leaves the loop as waste, and its catalogue already counts 176 projects, 104 of them at commercial scale. Provided to everyone, under the institute's Exit-to-Planet rule that the whole record goes into the commons, the stack liberates people from material and economic scarcity at once.
Building it needs money. But money turns out not to be the real constraint. Policy is further upstream: if you are not allowed to grow those materials, if building codes, seed laws, biosafety regimes or trade rules stand in the way, no amount of money solves it. And policy is downstream of coordination: it is coordination between people that gives influence on policy, that makes funding easier to reach, and that lets the memory of being part of life travel from one person to the next.
So the project we are embarking on here is an exploration into a new modality of coordination. This paper is that exploration.
1.3 Where GUANXI sits in the heliogenic civilisation
Heliogenesis works along three vectors. Material Independence replaces the extracted input with grown alternatives. Community Coordination replaces the extractive owner with cooperative structures, and points to what already works at scale: Mondragon with seventy thousand worker-owners, the cooperative district of Emilia-Romagna, the Preston procurement model, the Sardex mutual credit circuit, the WIR bank trading since 1934. Human Flourishing replaces extraction as the goal, and points to states that already treat inner development as public infrastructure.
GUANXI is infrastructure for the second vector, built to serve the first and the third. It follows the same design rule the institute applies to itself: a transition that depends on one owner staying benevolent for forty years is not a transition, it is a bet. So the protocol, the reference implementation and the matching heuristics are released into the commons, Exit-to-Planet, and no party can own the network, the data or the matching logic.
Two general principles from the commons literature shape the geometry. First, separate by what scales: the binding, everything that decides about scarce goods, stays in the near, in communities whose members can know one another; the non-rival, knowledge, designs, standards, protocols, code, circulates in the distant as a planetary commons. Second, protocols instead of commands, the discipline of the Internet Engineering Task Force: rough consensus and running code, intelligence at the ends and a dumb network in between.
GUANXI is a protocol that belongs in the planetary commons and a practice that lives in the near. Every actual exchange is a binding decision about a scarce good, and it happens between humans who, through their agents, have come to know enough about each other to decide. The network never commits anyone. It introduces.
1.4 Relationship to the Agentic Commons proposal
"The Agentic Commons" (September 2026) described representative agents that hold a living model of a principal's needs and offerings, discover each other over a peer-to-peer network, negotiate disclosure, and hand over to humans when a bilateral match looks likely. It established the non-negotiables: in the commons, distributed, open and agnostic, and agents never commit their principals.
GUANXI keeps all of that and adds four things the earlier proposal deliberately left out:
| Agentic Commons (Sept 2026) | GUANXI adds |
|---|---|
| Bilateral matching: my need meets your offer | Multilateral clearing: A gives to B, B to C, C to A, and longer chains, found by a solver |
| Disclosure policy on a self-hosted agent | A private-data vault with consent-mediated access and sandboxed, algorithm-to-the-data queries on hardware the principal or their community owns |
| Exchange medium left to the parties | A unit of account without a currency: a ledger of given and received, community credit lines, and explicit rules for tolerated imbalance |
| Trust via peer attestation | A commitment log: human-signed multilateral agreements in cross-witnessed transparency logs, with threshold-key escrow where deliverables are digital and attestation where they are not |
The reason for the extension is the central problem of markets, stated next.
2Why the market, and why it fails
2.1 The market is older than humanity
The market is often called one of humanity's central inventions. This paper takes the view that it is not an invention at all. It is embedded in nature. A forest is a market: mycorrhizal fungi trade phosphorus for sugar with trees, bacteria trade fixed nitrogen for root exudates with legumes, birds trade seed dispersal for fruit. Life itself can be seen as a vast, continuous exchange in which no party keeps an account, no party is paid in a common medium, and yet the whole clears, over time, across many species, with astonishing reliability.
What humans invented is not exchange but the bookkeeping of exchange, and then the pathologies that follow from one particular way of keeping books.
2.2 The central problem: exchange is rarely reciprocal
Any two parties rarely want exactly what the other has, in the same quantity, at the same time. Economists call this the double coincidence of wants. Money solves it by splitting every exchange in two: I give a service to A and receive money, so that I can buy a product from B. The genius of money is that it makes exchange bilateral and instantaneous even when the underlying wants are multilateral and spread over time.
The cost of that genius is the diagnosis behind heliogenesis. Once exchange runs through a medium, the medium can be hoarded, lent at interest, created as debt, and enclosed. The intermediary who issues or controls it extracts from every flow. And an economy that must service debt denominated in the medium must grow, whether or not the biosphere can carry it.
2.3 What guanxi and the gift economies actually do
Anthropology has documented, for a century, exchange systems that solve the coincidence problem without splitting it through money.
Guanxi (关系) literally means "relation", not "connection". Assistance inside a guanxi network is given when one party has need and another has capacity. Direct repayment is neither required nor appropriate. The helped party is expected to be among those who help later, if and only if they have the resources. Obligations run not just between two people but between nested groups: a marriage that links village A to village B lets any member of A draw on any member of B through compounded ties. The network, through face (mianzi), human feeling (renqing) and the moral grammar of return (bao), keeps a distributed, non-monetary, slowly decaying account of who has given and received. It is, in engineering terms, a multilateral, time-extended clearing system without a unit of account.
Mauss (The Gift, 1925) showed that the obligation to give, receive and reciprocate, with the return delayed and inexact, is precisely what keeps relationships alive. A prompt, exact repayment ends the relation. Sahlins (Stone Age Economics, 1972) laid out a spectrum from generalised reciprocity (kin, no accounting), through balanced reciprocity (community, roughly equivalent return within a customary period) to negative reciprocity (strangers, haggling and barter), keyed to social distance. Polanyi distinguished reciprocity, redistribution and market exchange, and showed that the self-regulating market is a late, politically constructed institution. Graeber (Debt, 2011) showed that everyday credit long preceded coinage, that barter between neighbours is largely a myth, and that what he calls baseline communism, from each according to abilities, to each according to needs, is the default inside every functioning human group.
The lesson for GUANXI is not romantic. Guanxi works because it moves strangers inward along Sahlins' spectrum: it turns negative reciprocity into balanced reciprocity by making the network, rather than the individual, the counterparty. What it cannot do is scale beyond the number of relationships a human can hold, roughly Dunbar's 150, or resolve obligations that span networks whose members have never met. That is the gap the agents fill.
2.4 Multilateral clearing is already engineered
Three operating systems prove that the guanxi function can be run at scale by a machine:
- Kidney exchange. Roth, Sönmez and Ünver formalised paired kidney donation as cycles and chains in 2004. Today the US National Kidney Registry has performed over 10,000 transplants across more than 100 centres; more than three quarters of transplants at one alliance came through chains rather than closed cycles. A deterministic integer-programming solver, not the participants, finds the exchange. Short cycles capture most of the value; chains need someone who accepts counterparty risk, the bridge donor.
- Slovenian multilateral set-off. Since 1991 Slovenia has run compulsory monthly multilateral netting of overdue business obligations through its AJPES agency, clearing between 1 and 7.5 percent of GDP per year without any money changing hands.
- Cycles Protocol (Informal Systems, 2024 to 2026). Participants submit bilateral obligations; a min-cost-max-flow algorithm finds cycles and chains; parties receive legally meaningful set-off notices. No custody, no central counterparty, no new currency.
The measured numbers matter for design. On Sardex's 2019 data (138,000 invoices, 3,199 firms), pure cycles reduced net internal debt by about 25 percent; with mutual credit, about 50 percent. On a 2021 Italian invoice corpus (€19.67 billion), cycle-restricted netting cleared 21 percent, and path-enabled three-party compensation 54 percent. On 1.28 million Italian invoices, about 10 percent of debt lay in closed cycles.
Rule of thumb: pure cycle netting clears 10 to 25 percent of a real obligation graph; adding a tolerated imbalance in a unit of account roughly doubles that. A money-free network can be real, but it needs a unit of account and a way to carry balances forward. Guanxi carries them in face and memory. GUANXI carries them in a ledger.
2.5 What changes when the representative is an agent
Platforms are already emerging in which humans are represented by LLM agents that interact and, when there is a meaningful connection, introduce their principals: LinkedIn on steroids, the ultimate dating app. GUANXI extends the notion to literally everything the market exchanges, and then removes the platform.
An agent can hold a model of its principal's needs, offerings and constraints far richer than any listing. It can talk to thousands of other agents a month at a cost of cents. It can negotiate disclosure progressively, so that a principal's full situation is revealed only to a counterpart who has revealed theirs. It can explain, in plain language, why a five-party chain across three countries makes sense for each party. And, crucially, it can feed a structured, bounded statement of intent into a solver that finds exchanges no human, and no bilateral conversation, could see.
What it must not do is decide. Section 4 explains why, from the evidence.
2.6 Relational economics and indigenous ways of being in the world
Anthropology describes what gift economies do. Two other bodies of thought say why they work and how to build for them.
Relational economics. Josef Wieland's Relational Economics (2020) and the civil-economy tradition of Luigino Bruni and Stefano Zamagni start from a simple inversion: the transaction is not the unit of the economy, the relation is. Value is created between parties, across time, through cooperation that neither could have produced alone, and the surplus of a good relation, the relational rent, is lost the moment either party treats the other as a means. Bruni and Zamagni add reciprocity as a third organising principle alongside contract and redistribution, and name the relational goods, trust, recognition, belonging, that a market with money cannot price and therefore systematically destroys. For GUANXI this is not decoration. It says the solver's objective should not be one-shot surplus but the continuity and deepening of relationships; that an agent represents a person in relation, not an isolated utility maximiser; and that the introduction, the moment two humans meet through their agents, is the product, not a cost of doing business.
Indigenous economies. Long before the word "economy" existed, peoples on every continent ran multilateral, time-extended reciprocity at scale, and many still do. We name a few because each contributes a design rule, and we name them with care: these are living practices of living peoples, not templates to be extracted, and the honourable thing is to learn and to credit.
- The honourable harvest (Robin Wall Kimmerer, Potawatomi, Braiding Sweetgrass, 2013): ask permission, take only what you need, never take the first or the last, use everything you take, share, give thanks, reciprocate the gift, sustain the ones who sustain you. In The Serviceberry (2024) Kimmerer adds the gift economy's central rule: the gift keeps moving; wealth is what flows through you, not what stops with you. GUANXI's intent profile carries constraints of exactly this shape, and its ledger lets balances fade in both directions so that nothing stops.
- Kinship-mind (Tyson Yunkaporta, Apalech clan, Sand Talk, 2019): knowledge and obligation live in relationships between people, places and things; systems that are healthy grow by deepening rather than by scaling; and any technology should be tested against whether it increases or destroys relatedness. That test is written into GUANXI's metrics.
- Whanaungatanga, manaakitanga, utu, kaitiakitanga (Māori): relationship as kinship, care as obligation, reciprocity as the restoration of balance rather than the settlement of a debt, and guardianship rather than ownership of what sustains us. The Whanganui River has held legal personhood since 2017, a reminder that relation, not property, can be the legal form.
- Ayni and minka (Quechua and Aymara, Andes): reciprocal labour exchanged between households over seasons and years, and communal work for shared benefit, inside the ayllu. Ayni is a clearing system denominated in labour; it is the closest living ancestor of a time-based unit of account. Sumak kawsay, living well together, has stood in Ecuador's constitution since 2008.
- Ubuntu (southern Africa): umuntu ngumuntu ngabantu, a person is a person through other persons. Identity is relational; so should an agent's representation of its principal be.
- The seventh-generation principle (Haudenosaunee): decide with the seventh generation to come in the room. GUANXI's governance layer gives every clearing house a rule for the time horizon of its credit and its sanctions.
- The potlatch (Kwakwaka'wakw, Haida, Tlingit and others, Pacific Northwest): standing comes from giving, surplus is redistributed rather than accumulated, and the practice was banned by Canada from 1885 to 1951 precisely because it made accumulation impossible. Decaying positive balances are the potlatch written into a ledger.
- The subak (Bali): water temples coordinating irrigation across whole watersheds for a thousand years without a central authority, through nested ritual and negotiation among farmers who know one another. Stephen Lansing showed in the 1990s that the temple network outperformed the state's engineers. It is Ostrom's nested enterprises, and GUANXI's nested clearing houses, in the flesh.
The Lakota phrase mitákuye oyás'iŋ, all my relations, says in three words what this paper says in ten thousand. A market that remembers it is a different kind of market.
3The idea in one picture
3.1 The flow
principal ──talks/points──▶ VAULT (private, local-first)
│ consent-gated
▼
REPRESENTATIVE AGENT
needs · offers · constraints · disclosure policy
│ signed summaries
▼
DISCOVERY (P2P index, federated registries)
│ candidate counterparts
▼
NEGOTIATION (agent ↔ agent, progressive disclosure)
│ structured, bounded intents
▼
CLEARING (deterministic solver: cycles, chains, credit)
│ proposed exchange + plain-language brief
▼
HUMANS (read brief, talk, sign mandate)
│ signed multilateral agreement
▼
COMMITMENT LOG (signed, witnessed, timestamped, attestations)
3.2 A worked example
Ana runs a small mycelium-panel workshop in Porto. Her agent knows she has spare kiln time on Fridays, needs a structural engineer to sign off a load calculation for a community hall, and will not exchange with arms manufacturers or anyone more than one day's train away.
Jonas is a retired structural engineer in Freiburg. His agent knows he wants to be useful for a few hours a week, remotely, without liability exposure, ideally with projects that build in wood or bio-based materials. He needs nothing from Porto. He does need someone to teach his granddaughter Portuguese before her exchange year.
Marta teaches Portuguese online in Lisbon. Her agent knows she has evening capacity, wants to move her cooperative's website off a US platform, and needs 40 square metres of acoustic panelling for a new classroom.
No two of these three have anything to exchange bilaterally. The clearing solver finds the cycle: Ana's panels go to Marta, Marta's lessons go to Jonas's granddaughter, Jonas's sign-off goes to Ana's community hall. Each agent produces a brief for its principal: who the others are, why the loop makes sense, what has been disclosed and what has not, and how confident the agent is. The three humans talk. Two of the legs have a value gap the solver flags; Marta's cooperative agrees to carry a small positive balance in the Lisbon clearing house's ledger, which it will draw down later. All three sign. The agreement is recorded. When the panels arrive and the lessons happen, each party attests. Nobody was paid.
Multiply this by a few hundred thousand participants, and the network is doing continuously what guanxi does inside a village, and what no market with money has ever done: clearing everything that can be cleared, and only then asking what remains.
4What the evidence says
This section compresses the three research appendices into the findings that shaped the architecture.
4.1 Large language models as negotiators and matchers
The record from 2022 to 2026 is consistent enough to design against.
| LLM agents do well | LLM agents do badly |
|---|---|
| Reading unstructured intent from an email thread, a voice note or a website and turning it into a structured, updatable profile | Converting inferred preferences into strategy: they identify the counterpart's priorities early and still fail to trade low-value for high-value items |
| Reporting preferences truthfully inside a mechanism, at higher rates than humans (matching-market experiments, 2026) | Solving the mechanism themselves: on stable-matching instances they cannot hold feasibility, stability and optimality at once, and iterative prompting degrades |
| Handling flexible, natural-language constraints: geography, ethics, timing | Arithmetic and price consistency: selling below cost, hallucinating a payment account (Project Vend, 2025) |
| Explaining a deal to a human: the Habermas Machine's group statements were preferred to human mediators' by 56 percent of participants | Anchoring: opening-to-final price correlation of 0.72 across frontier models; concession schedules that ignore leverage; negotiation skill does not improve with model size |
| Completing deals: deal rate saturates across frontier models | Being exploited: a counterpart "pretending to be desperate" raised its payoff by about 20 percent; sycophancy toward the counterpart over the principal |
| Sustained operation when procedures are imposed: a supervising agent plus mandatory lookup procedures cut unwarranted discounts by 80 percent (Project Vend phase 2) | Long-horizon coherence without scaffolding; "meltdown loops"; failures uncorrelated with context length |
| Tacit collusion when agents are symmetric (22 percent above competitive prices), broken by heterogeneity | |
| Strategic dominance: some models systematically extract more surplus, so the outcome depends on which model a party can afford |
Cicero, the strongest existing negotiation system, is instructive precisely because of its architecture: a language model generates dialogue conditioned on plans from a separate strategic planner. Language handles language; a solver handles strategy.
Design consequences. LLMs produce structured, bounded intents and explain results. A deterministic solver finds exchanges and divides surplus by rule (equal split or Nash bargaining), which also removes the exploit surface. Humans sign commitments. Agents in a match run the same commons-provided model, or the solver neutralises model differences. Procedures and sanity gates, not prompts, enforce constraints. Episodes are short, event-driven and stateless, with state held in the vault.
4.2 Multilateral clearing
Summarised in section 2.4. The clearing problem with bounded cycle length three or more is NP-hard, but real instances at national scale solve in seconds to minutes with integer programming or min-cost flow. Short cycles capture most value; chains capture the rest but require a party willing to carry a balance. This is the hard, honest constraint: GUANXI needs a unit of account and a rule for tolerated imbalance. It does not need a currency, interest, or convertibility.
4.3 Privacy layer
The question for the privacy layer is where raw personal and organisational data may be processed, and by whom. The evidence narrows the answer to one honest option and several that should be declined.
Local-first is the strongest option and the cheapest. A 7 to 30 billion parameter open-weight model runs on a laptop, and a 2 to 4 billion parameter model on a single-board computer, at electricity cost of fractions of a cent per episode. Data that never leaves the device has no network attack surface at all. Apple's on-device foundation models and Stanford's OpenJarvis show the pattern is mainstream in 2026.
Personal data stores with consent control exist as open standards. The Solid protocol, stewarded since 2024 by the Open Data Institute, gives a self-hostable pod with fine-grained access control and an open-source server (Community Solid Server, MIT licence). It is the only standards-track personal data store with an institutional steward and agent tooling.
Confidential cloud compute should be declined for the core. Trusted execution environments (Intel TDX, AMD SEV-SNP, NVIDIA confidential GPUs) are generally available at little or no price premium, and they do reduce what a cloud operator can see. But they move trust from a cloud operator to a chip vendor, they have a history of side-channel breaks, they cannot be audited by the community that relies on them, and they require the data to leave the principal's hardware in the first place. Fully homomorphic encryption is not viable for LLM inference in 2026. Container isolation on somebody else's server is not confidentiality at all.
Bring the algorithm to the data, inside a capability-scoped sandbox. The one pattern worth keeping from data-marketplace designs is that the computation travels to the data rather than the reverse. In GUANXI a query from another agent that needs more than a summary is executed on the principal's own node, or on a community node run by people the principal knows, inside a WebAssembly sandbox with no network and no filesystem beyond what the vault explicitly grants. Trust in the near replaces trust in the vendor.
Design consequence. Local-first vault, Solid-style consent layer exposed over MCP, computation in capability-scoped sandboxes on principal or community hardware, no cloud dependency in the core, and TEEs permitted only as an extension a community may choose for itself. Appendix 1 documents a data-marketplace protocol that was evaluated for this layer and set aside.
4.4 Agent protocols
The 2026 landscape supplies transports and payment rails but no governance:
- A2A (Linux Foundation, Apache 2.0, v1.0 in 2026, 150+ organisations): agent discovery via signed Agent Cards and task delegation over JSON-RPC. The natural transport for agent-to-agent negotiation.
- MCP (Agentic AI Foundation under the Linux Foundation): how an agent reaches its principal's calendar, inventory and documents. Not for inter-agent bargaining.
- AP2 (Google, Apache 2.0): Intent, Cart and Payment "mandates" as W3C Verifiable Credentials signed by the human's wallet. The mandate structure, a human signs bounds and the agent acts inside them, is directly reusable for non-monetary commitments. A 2026 security analysis found 48 threats, the core one being prompt injection before authorisation.
- x402 (Coinbase, now an LF foundation with Stripe, Cloudflare, Visa, Mastercard among 22 supporters): HTTP-native micropayments. Useful only as an optional residual-settlement leg.
- ERC-8004 "Trustless Agents" (draft; mainnet January 2026): identity, reputation and validation registries. A June 2026 study found only 3 to 15 percent of registered identities expose working endpoints and 59 to 91 percent of reviewers show Sybil traits. The registry "cannot function as a trust signal" as deployed.
- NANDA (MIT): a federated "quilt of registries" with verifiable AgentFacts. The closest architectural match for non-platform discovery, still at research stage.
- Olas, Fetch.ai, Virtuals: token-dependent registries; Virtuals' evaluator-agent-plus-escrow phase is a reusable pattern for verifying delivery.
A June 2026 gap analysis of MCP, A2A, ACP, ANP and ERC-8004 found voting, dissent preservation, deliberation, human escalation and audit absent or weak in all five: "governance constitutes a missing architectural layer". GUANXI must build it.
4.5 Identity
W3C Verifiable Credentials 2.0 became a Recommendation in May 2025. DID 1.1 is at Candidate Recommendation. OpenID4VP and OpenID4VCI are final, with conformance certification since February 2026. Every EU member state must offer a certified EU Digital Identity Wallet by 24 December 2026, and obligated private relying parties must accept it from late 2027. The wallet presupposes a human subject; agents cannot operate it. The workable pattern is a delegation credential, issued from a person's or organisation's wallet, that scopes and time-limits what an agent may claim. Organisations verify through domain control at the low end and GLEIF's verifiable LEI (eight qualified issuers) at the high end.
4.6 Ledgers and logs
The ledger's job is modest: make agreements non-repudiable, timestamped and tamper-evident, and make attestations portable. It does not need a currency, a consensus network or programmable money.
Public blockchains are cheap and unnecessary for the core. A simple transaction costs $0.10 to $0.25 on Ethereum mainnet in 2026 and a few cents or less on rollups. But every rollup in wide use runs a single company's sequencer, every smart contract is an attack surface with a long record of nine-figure losses, and the on-chain reputation registry designed for agents (ERC-8004) turned out, in a June 2026 study, to have 59 to 91 percent Sybil reviewers and only 3 to 15 percent working endpoints.
Transparency logs do the job with less. Certificate Transparency (RFC 6962) has protected the web's certificate system since 2013 with append-only Merkle logs, open-source implementations (Trillian, Sigstore Rekor, Sigsum) and independent witnesses that co-sign log checkpoints so that no single log operator can rewrite history. The pattern is battle-tested, has no token, no gas and no contract, and a log node runs on a €5 a month server.
External timestamps are free. OpenTimestamps aggregates hashes and anchors them in Bitcoin at no cost to the user; anchoring a daily checkpoint to Ethereum mainnet costs about $0.25. Either gives a third-party timestamp no clearing house can forge, without depending on either chain for anything else.
Attestations belong in the vault, not on a chain. W3C Verifiable Credentials 2.0 are the portable, signed, revocable format. Semaphore-style zero-knowledge group proofs, production-grade and open source, let an agent prove "my principal holds at least N positive attestations from members of set S" without revealing which.
Design consequence. Signed, content-addressed agreement documents held by their parties; per-clearing-house transparency logs cross-witnessed by peer clearing houses; free external timestamping; attestations as verifiable credentials; group proofs for private reputation; no blockchain and no smart contract in the core; an optional extension for communities that want on-chain escrow of digital deliverables.
4.7 Inference cost
At list prices, a bilateral ten-round negotiation episode (about 30,000 input and 3,000 output tokens, before caching) costs roughly $0.004 on a small cloud model and $0.05 to $0.25 on frontier cloud models. On a 27-billion-parameter open-weight model on a consumer GPU it costs about €0.002 in electricity, and on a community-owned inference node shared by a few hundred participants, a few tenths of a cent including hardware amortisation. Cloud frontier models are excluded from GUANXI's core anyway, because every token sent to them is data leaving the principal's control. Cost is not the constraint. Human attention is.
5Design principles
The Agentic Commons' non-negotiables stand, and they are Heliogenesis' Exit-to-Planet rule applied to a protocol: in the commons (free to use, study, modify and redistribute; no charge for access; a stewarding body that maintains the specification, not the infrastructure), distributed (no node whose failure or capture stops or controls the network), open and agnostic (interfaces and message formats, not implementations; any model, any host, any interface). GUANXI adds nine.
- Relation before transaction. The unit of the system is the relationship between principals, not the exchange. The solver prefers matches that renew and deepen existing relations over one-off surplus; the introduction is the product.
- LLM for intent, solver for clearing, humans for commitment. The language model produces and explains; it never computes the exchange and never signs.
- Every component you do not run is an attack surface you do not have. Only open-source software under permissive or copyleft licences; only open standards; reference node in a memory-safe language; reproducible, signed builds; no proprietary model, no cloud service, no chip-vendor trust root, no blockchain and no smart contract in the core. Extensions may add any of these; the core never depends on them.
- Privacy by architecture, not by policy. Raw data stays where the principal keeps it. The network sees signed summaries at the disclosure level the principal set. Computation over private data happens on the principal's hardware or on hardware run by people the principal knows, inside capability-scoped sandboxes.
- Separate by what scales. The specification, the solver code, the schemas and the heuristics are planetary commons. Every exchange, every credit line, every sanction is decided in the near, inside a clearing house run by a community whose members can know one another.
- Nested, not flat. Clearing houses nest: community inside federation inside planetary commons, and obligations clear at the lowest level that can close them, as guanxi compounds ties between groups and as the subak coordinates a watershed. This is Ostrom's eighth principle and the reason the system can scale without a global pool.
- A unit of account, no currency, and the gift keeps moving. The ledger records given and received in a community-chosen unit (hours, as in ayni; a reference basket; a local index). There is no issuance, no interest, no convertibility, and no obligation to settle balances in anything but further exchange. Balances decay in both directions: negative ones so that obligation fades as it does between people, positive ones so that nobody hoards standing, as the potlatch and Gesell's demurrage both understood.
- Neutralise strategic dominance. Within a match, all agents run a commons-provided open-weight model, or the solver divides surplus by rule. Nobody buys a better deal by buying a better model.
- Assume adversaries, and test for relatedness. Sybil identities, tacit collusion, prompt injection before authorisation, probing of profiles piecemeal, supply-chain compromise and capture by a dominant implementation are design inputs. And every feature is tested, as Yunkaporta asks, against whether it deepens or destroys relatedness between the people it connects.
6Technical architecture
GUANXI is specified as seven layers plus a governance layer. Each layer names the open standard it reuses, what GUANXI specifies itself, and the reference implementation choice. Every named component is open source under a permissive or copyleft licence and can be run by a community on its own hardware. The specification is deliberately small; everything not listed under "GUANXI specifies" is left to implementers.
6.1 Layer 0: Identity
Reuses. W3C DID 1.1 and Verifiable Credentials 2.0; OpenID4VC for wallet interoperability; did:key for agents and offline principals; did:webvh (verifiable history, Decentralized Identity Foundation) for organisations; the EU Digital Identity Wallet, whose reference implementation is Apache-2.0, as an optional root of assurance for European persons from 2027; GLEIF's verifiable LEI or national registers for legal entities.
GUANXI specifies.
- Principal identity: a DID whose keys the person or organisation holds, on their own device or in an open-source wallet.
- Agent identity: a separate DID per agent, with a delegation credential issued by the principal's DID stating scope (which categories of need and offer the agent may represent), limits (maximum value, geography, counterpart classes), expiry, and the model and execution environment the agent runs in.
- Relational identity: a principal's membership credentials name the communities they belong to; an agent introduces its principal as a person in relation, never as a bare key.
- Claiming: proof of control over a source (domain, verified email, social handle, company-register entry, wallet presentation) transfers a crawler-created provisional agent to its principal, as in the Agentic Commons.
- Key rotation and recovery: social recovery through a threshold of the principal's clearing-house peers (FROST threshold signatures, open source), never through a network operator.
Reference implementation. did:key on day one, did:webvh for organisations, OpenID4VP presentation from any conformant open-source wallet (the EUDI reference wallet or walt.id), delegation credentials as VC 2.0 with Data Integrity proofs.
6.2 Layer 1: Vault
The vault holds the principal's raw material: emails, calendars, inventories, project notes, ERP exports, voice notes. It is the only place raw data is ever processed.
Reuses. Solid protocol and Community Solid Server (MIT) for storage, access control and consent; MCP for exposing vault resources to the agent as capability-scoped tools; WebAssembly with WASI (Wasmtime, Apache-2.0) as the sandbox for any algorithm brought to the data.
GUANXI specifies.
- Local-first default: the vault runs on the principal's device, or on a server the principal or their community controls. Encrypted at rest with keys the principal holds. A small local model handles routine profile extraction.
- Consent-mediated access: every read by the agent is an access-controlled request, logged and revocable; the principal remains the editor of record and approves profile changes.
- Algorithm to the data: when another agent's query needs more than a published summary, the query travels as a signed WebAssembly module and runs inside the vault's sandbox with no network, no clock beyond what is granted, and read access only to the fields the disclosure policy permits at that tier. Only the module's output leaves, and the principal's policy may require it to be reviewed first.
- Trusted-algorithm allow-list: the vault runs only modules whose hashes the principal or their clearing house has approved and whose source is published.
- Community compute: a principal whose device cannot run a needed model may delegate inference to a node run by their clearing house, under the same sandbox rules. Trust here rests on Ostrom's first principle, known membership, not on hardware attestation. Confidential-computing hardware is permitted as a community-level extension and is not part of the core.
Reference implementation. Community Solid Server as the pod; an MCP server over the pod issuing per-capability tokens; llama.cpp (MIT) or vLLM (Apache-2.0) serving a permissively licensed open-weight model locally; Wasmtime for sandboxed queries.
6.3 Layer 2: Representative agent
Reuses. Any open-weight LLM; MCP for tools; A2A Agent Card for self-description.
GUANXI specifies. The intent profile schema and its lifecycle:
- Needs: what, why, by when, under what constraints, how urgently, and a value band in the community's unit of account.
- Offerings: what, capacity, conditions, availability, geography, value band.
- Disposition: counterpart classes and exchange forms the principal is open or closed to, including ethical exclusions (no arms, no fossil extraction, no entities on a community's exclusion list), geographic bounds, and harvest rules in Kimmerer's sense: how much of a capacity may be given before the principal is asked, what must always be kept back, whom to sustain first.
- Disclosure policy: which fields are visible at which stage of negotiation to which counterpart classes.
- Mandate envelope: the bounds within which the agent may propose without asking, and the threshold above which the human must be consulted before the agent even signals interest.
Profiles are updated intentionally (the principal tells the agent) and ambiently (the agent proposes changes from consented sources), as in the Agentic Commons. Agents run as short, event-driven episodes triggered by discovery or by the solver; persistent state lives in the vault, never in a conversation.
Reference implementation. A model-agnostic agent runtime that ships with a commons-selected open-weight model under a permissive licence as default (a 27 to 30 billion parameter class model runs on a laptop; a 2 to 4 billion parameter class model runs on a single-board computer for profile maintenance). Model choice is the principal's; the network records which model an agent runs, because it affects trust. Proprietary model APIs are not part of the core, because every token sent to them is data leaving the principal's control.
6.4 Layer 3: Discovery
Reuses. libp2p or Iroh (Rust, open source) for gossip, content-addressed blobs and NAT traversal; A2A Agent Cards; a NANDA-style quilt of federated registries for cross-community lookup.
GUANXI specifies.
- Summaries: signed, content-addressed summaries of shareable needs and offerings, coarse enough to signal relevance and not enough to reveal the principal's situation.
- Topic and region indexes: agents subscribe to categories and geographies; matching heuristics run locally on each agent and may differ between implementations.
- Registry federation: every clearing house runs a registry of its members' summaries; registries peer with one another; no global directory, no central index anyone can capture or subpoena.
Reference implementation. Iroh for transport and blobs; an open-source search index (Meilisearch, MIT, or Typesense, GPL) per clearing house.
6.5 Layer 4: Negotiation
Negotiation in GUANXI is not haggling over price. It is the progressive, mutual disclosure of enough detail to produce a structured, bounded intent that the solver can use.
Reuses. A2A for the message sequence; Messaging Layer Security (RFC 9420, OpenMLS) for end-to-end encrypted channels between agents and for group channels in a multilateral match; AP2's mandate structure for the bounded intent.
GUANXI specifies.
- Message sequence: open channel, exchange disclosure tier 1, evaluate, exchange tier 2, evaluate, withdraw or emit intent. Either side may withdraw at any point.
- Bounded intent: a signed statement, "I would give X under conditions C for value in band [a, b]" or "I need Y under conditions C, worth to me in band [a, b]", with an expiry. This is the only artefact that leaves negotiation. It is produced by the agent and, above the principal's threshold, confirmed by the human before emission.
- No LLM pricing: value bands are set by the principal (with the agent's help from reference data), and surplus within a match is divided by the solver's rule, not by bargaining. This removes the anchoring, rigid-concession and exploitation failure modes documented in section 4.1.
- Same-model rule: for a given match, participating agents either run the commons default model or accept that the solver, not their agent, determines terms.
6.6 Layer 5: Clearing
The clearing house is a deterministic service that takes bounded intents, builds an obligation graph and finds exchanges.
Reuses. Integer programming with cycle and chain variables (kidney exchange, Anderson et al. 2015); min-cost max-flow for divisible quantities (Cycles Protocol's MTCS, Circles pathfinder); Trade Reduction for budget-balanced surplus division; open-source solvers HiGHS (MIT) and OR-Tools or SCIP (Apache-2.0).
GUANXI specifies.
- Clearing protocol: how a clearing house ingests intents, what it may compute, how it produces a proposed exchange, and what it must publish (aggregate statistics, never individual intents).
- Objective: maximise cleared value weighted by relationship continuity, so that a match which renews an existing relation outranks a marginally larger one-off, in line with relational economics.
- Cycle and chain packing: cycles of length 2 to 4 preferred; chains permitted when a party or the community's credit line carries the residual.
- Credit lines and decay: each member has a tolerated imbalance in the community's unit of account, set by the community's rules. Both negative and positive balances decay over time at rates the community sets; obligations fade, and so does hoarded standing.
- Surplus rule: equal split or Nash bargaining across the match, published in the community's rules.
- Nesting: an intent that does not clear inside a community after N rounds is forwarded, at the principal's disclosure level for the next tier, to the federation clearing house; then to the planetary commons. Most exchange clears near.
- Explanation: the solver returns, for each participant, the structure of the proposed exchange and the reason each leg was chosen; the agent turns this into a plain-language brief with an honest confidence statement.
Reference implementation. An open-source solver in Rust or Python over HiGHS; a clearing-house node runs on a €5 to 10 a month server or a single-board computer for a community of a few thousand; federation-scale instances of a few hundred thousand nodes solve in minutes on a single machine. The solver is the most reusable piece of GUANXI and should be released early and separately. Whether the solver should itself run inside the principals' sandboxes, so that a clearing house never sees intents in clear, is an open question in section 9.
6.7 Layer 6: Commitment log
Reuses. Content-addressed storage (Iroh) for agreement documents; the transparency-log pattern of Certificate Transparency (RFC 6962) with open-source implementations (Trillian, Sigstore Rekor, Sigsum); witness co-signing between logs; OpenTimestamps for free external timestamps; Verifiable Credentials 2.0 for attestations; Semaphore (MIT) for private group proofs; FROST threshold signatures for escrow release.
GUANXI specifies.
- Multilateral agreement: a document listing every leg (giver, receiver, what, conditions, value band, due date), signed by every principal's DID via their wallet. Humans sign; agents cannot. Each party keeps a copy in their vault.
- Logging: each clearing house appends the hash of every agreement to its own append-only Merkle log and publishes signed checkpoints. Peer clearing houses in the federation act as witnesses and co-sign each other's checkpoints, so that no single log can rewrite history without detection. A daily checkpoint is timestamped externally via OpenTimestamps, at no cost, or optionally to Ethereum mainnet for about $0.25.
- Performance: on completion of a leg, receiver issues a verifiable credential to giver; it is stored in both vaults, revocable, and its hash may be logged. Disputes go to the clearing house's conflict process (section 6.8).
- Escrow without contracts: where a leg is digital (a design file, a dataset, a licence), the giver encrypts the deliverable and splits the key among the clearing house's arbiters with a threshold scheme; the key is released on the receiver's attestation or an arbiter decision. No smart contract, no chain. Where a leg is physical or a service, there is no escrow; reputation and graduated sanctions carry it, as they do in every mutual-credit system that has lasted.
- Reputation: portable, attested, decaying. An agent may prove "my principal holds at least N positive attestations from members of clearing house S" with a Semaphore proof without revealing which. Any on-chain reputation is advisory only, given the measured Sybil rates on ERC-8004.
- Optional extensions: a community may choose to anchor its log to a public chain, to use smart-contract escrow, or to settle residual balances in a complementary currency or money via x402. The protocol permits these and neither requires nor privileges them.
6.8 Governance layer
The gap analysis in section 4.4 is explicit: no agent protocol supplies governance. GUANXI does, by mapping Ostrom's eight principles onto the stack, with the indigenous design rules of section 2.6 alongside:
| Ostrom principle | GUANXI mechanism |
|---|---|
| 1. Clear boundaries | Membership of a clearing house is a verifiable credential; provisional (crawler-created) agents participate at reduced trust and hold no credit |
| 2. Rules fit local conditions | Unit of account, tolerated imbalance, decay rates, surplus rule, harvest rules and exclusion lists are set per clearing house |
| 3. Collective choice | Members change their clearing house's rules through a published process; the protocol only requires that the process be published and the rules machine-readable |
| 4. Monitoring | Attestations, aggregate clearing statistics, cross-witnessed logs, and principal-side alerts on unusual query patterns against their profile |
| 5. Graduated sanctions | Reduced disclosure tier, lowered credit line, slower decay of negative attestations, suspension, exclusion, in that order; restoration of balance (utu) is the aim, not punishment |
| 6. Conflict resolution | Each clearing house names arbiters (human, optionally agent-assisted); decisions are attested; appeal runs to the federation |
| 7. Right to self-organise | The stewarding body has no privileged position on the network; a legal wrapper (association or foundation) holds the specification and trademark only |
| 8. Nested enterprises | Community, federation, planetary commons; clearing and sanctions at the lowest level that can close them, as in the subak |
| Time horizon | Each clearing house states the horizon its credit, decay and sanction rules are designed for; the seventh generation is the reference, not the quarter |
The specification itself is governed IETF-style: proposals as public requests for comments, rough consensus, running code, a small stewarding body with a public charter and a funding plan that does not depend on any single implementer.
6.9 Minimising the attack surface
The architecture is built so that the list of things an attacker can target is short, and every item on it is something the community itself runs and can inspect.
What is not there.
- No central server, directory, index or matching service. Discovery is peer-to-peer; registries are per clearing house and federated.
- No cloud dependency. Every component runs on a laptop, a single-board computer or a community server.
- No proprietary software or model in the core. Every line of the reference implementation and every weight of the default model is inspectable.
- No proprietary model API. No token of a principal's data leaves for a vendor.
- No chip-vendor trust root. Confidentiality comes from data not moving, not from attestation.
- No blockchain, token or smart contract in the core. Logs are append-only Merkle trees witnessed by peers; timestamps are free.
- No global identity provider. DIDs are self-held; recovery is social.
- No telemetry.
What is there, and how it is hardened.
- Reference node in a memory-safe language (Rust), eliminating the class of bugs behind most remote-code-execution exploits.
- Reproducible builds (Nix or Guix) with signed releases (Sigstore) and a software bill of materials, so that any community can verify that the binary it runs matches the published source.
- Minimal dependencies, pinned and audited; the specification is small on purpose.
- Capability-based access everywhere: the agent reaches the vault only through MCP tools scoped to single capabilities; foreign queries run in WebAssembly sandboxes with no ambient authority.
- End-to-end encryption between agents and within a match (MLS); transport over QUIC with TLS 1.3 or Noise.
- Human signature as the only commitment; hardware-backed keys where the principal has them.
- Cross-witnessed logs, so that compromising one clearing house's log is detectable by every peer.
- Rate limits and anomaly alerts at the vault, owned by the principal, not by the network.
- Implementation diversity funded by the steward, so that a single bug does not take down the network.
The principle behind the list is the one guanxi has always used: trust the people you know, and make everyone else prove it.
6.10 Threat model
| Threat | Mitigation |
|---|---|
| Sybil identities inflating reputation or draining credit lines | Verified-human or verified-organisation credentials for full membership; provisional agents cannot hold credit; group proofs bound to membership sets |
| Prompt injection before authorisation (the core AP2 finding) | Agents never sign; bounded intents above threshold require human confirmation; mandates carry scope and expiry; vault inputs are treated as data |
| Profile probing by many agents | Disclosure tiers gated on the counterpart's attestations; rate limits per counterpart class; principal-side anomaly alerts |
| Tacit collusion between agents | Solver-determined terms; model diversity across communities; audit of clearing-house statistics |
| Strategic dominance by better models | Same-model rule within a match or solver-determined terms |
| Hallucinated commitments | Only human-signed agreements exist; agent output is never a commitment |
| Supply-chain compromise of the software | Reproducible builds, signed releases, SBOMs, pinned dependencies, multiple independent implementations |
| Malicious query module exfiltrating vault data | WebAssembly sandbox with no network; allow-listed, source-published modules; output review policy |
| Compromised clearing-house log | Cross-witnessed checkpoints; external timestamps; parties hold their own signed copies |
| Community node operator reading delegated data | Known membership under Ostrom's first principle; sandboxing; the principal's right to keep everything local |
| Capture by a dominant implementation or model provider | Implementation diversity cultivated by the steward; commons default model; switching cost kept low by the specification |
| Clearing house misbehaviour | Published aggregate statistics; members can fork a clearing house with their credentials, attestations and log history intact |
6.11 What the protocol specifies, in one list
- Identity and delegation (6.1)
- Intent profile schema, harvest rules and disclosure tiers (6.3)
- Publication and discovery messages (6.4)
- Negotiation sequence and bounded intent format (6.5)
- Clearing protocol, credit-line and decay semantics, surplus and continuity rules, nesting (6.6)
- Multilateral agreement, attestation, log and witness formats (6.7)
- Clearing-house rule schema and governance minimums, including time horizon (6.8)
Everything else, matching heuristics, interfaces, connectors, models, hosting, is left to implementers. That is the whole point.
7Roadmap
The roadmap follows the Agentic Commons' logic, specification plus a minimal copyable implementation, and adds the clearing and log layers in the order the evidence supports: the solver first, because it is the most reusable and least risky piece; the log last, because it only matters once there are agreements to record.
Phase 0: Specification and solver (months 0 to 6)
- Publish GUANXI RFC 0001 to 0007 (the seven items in section 6.11) as public drafts under an open licence.
- Release the clearing solver as a standalone open-source library with the Sardex, Italian and kidney-exchange benchmark datasets, so that researchers and existing mutual-credit networks can use it before any agent exists.
- Convene a small advisory circle: mechanism design, relational economics, anthropology of reciprocity, indigenous knowledge holders who choose to engage on their own terms, mutual-credit practitioners (Sardex, Grassroots Economics, Cycles), privacy and supply-chain security engineers.
- Establish the legal wrapper (association or foundation) that holds the specification and trademark and nothing else.
- Warning, not a work package: community credit lines may touch e-money or payment law, and non-monetary exchange may be taxable at market value in some jurisdictions. Pilots should know this before they start. This paper does not go further.
Phase 1: Reference implementation and pilots (months 6 to 18)
- Ship the reference implementation: vault, agent runtime with a commons default open-weight model, discovery, negotiation, one clearing house. Reproducible build, signed release. Installable on a single-board computer or a community server in under an hour; one-click path for everyone else.
- Seed with crawler-created provisional agents for public organisations in the pilot regions, as the Agentic Commons proposes, so that early adopters find something on day one.
- Run two or three pilots with communities that already coordinate and already lack money: candidates from delodi's own portfolio are the MOTHERLAND farmer groups in Siaya County (low-bandwidth, post-harvest surplus, material needs), the IRM and New Wohlstand network in Germany, and the Heliogenesis community with its catalogue projects, which already have grown materials to offer and inputs to need; outside it, a repair and maker cooperative network in Lisbon and Porto, and GITA's municipal partners.
- Target: 5,000 participants, at least one clearing house with published rules, first measured clearing rate and first measured relatedness score.
Phase 2: Federation and log (months 18 to 36)
- Second and third clearing houses, then federation between them; nesting live; cross-witnessing of logs.
- Commitment log: agreement format, attestation credentials, per-clearing-house transparency logs, free external timestamping; threshold-key escrow for digital legs.
- EUDI delegation credentials, once member-state wallets are live (deadline 24 December 2026) and relying-party registers exist.
- Community compute nodes: hardware grants so that clearing houses can run inference for members whose devices cannot.
- Independent security audit of the reference node and the sandbox; first alternative implementation funded.
- Charter the stewarding body with a public funding plan; move the RFCs to it.
- Target: 10 or more clearing houses, roughly 300,000 participants, measured clearing rates by cycle length and credit-line use.
Phase 3: Scale and policy (year 4 onward)
- Hand over: the steward maintains the specification; implementations multiply; delodi becomes one implementer among several.
- Use the network for what it was built for: the coordination substrate that gives the heliogenic material stack its policy leverage and its funding paths.
What to measure
| Metric | Why it matters |
|---|---|
| Clearing rate: share of emitted intents cleared within N rounds, by cycle length | The core promise; the benchmark is 10 to 25 percent for pure cycles, about 50 percent with credit lines |
| Share cleared in the near layer | Tests the nesting principle |
| Relationship continuity: share of matches that renew an existing relation; median number of exchanges per pair over a year | Yunkaporta's test and relational economics' claim, made measurable |
| Human minutes per completed exchange | Human attention is the scarce resource |
| False-positive introductions | Match quality, and the fastest way to lose participants |
| Credit-line utilisation and decay | Whether "no money" is holding |
| Share of participants running fully local | The privacy promise, made measurable |
| Sybil, probing and supply-chain incidents detected | Whether the threat model is real |
8Likely cost of implementation
All figures are 2026 euros, fully loaded (salary plus employer costs), for a team based in Berlin and Lisbon with some remote contributors. Salary benchmarks and hosting prices come from research/03; inference prices from research/02. Ranges are honest: this is a concept, not a budget.
8.1 Three scenarios
| Lean | Standard | Ambitious | |
|---|---|---|---|
| What it buys | Specification, solver, one reference implementation, one pilot | Full seven-layer stack, three pilots, federation, log, community compute grants, security audits, steward chartered | Standard plus multi-region deployment, a second independent implementation, and a policy programme in several jurisdictions |
| Team at peak | 6 FTE | 20 FTE | 35 to 40 FTE |
| Year 1 | €1.1 to 1.3M | €2.3M | €4 to 5M |
| Year 2 | €1.2 to 1.5M | €3.3M | €7 to 8M |
| Year 3 | €1.3 to 1.6M | €4.4M | €9 to 11M |
| Three-year total | €3.6 to 4.4M | €10M | €20 to 24M |
| Comparable | Mastodon gGmbH (2024 costs €0.77M), Matrix Foundation (2024 costs $1.2M) | Wikimedia Foundation years 4 to 6 ($2M to $5.6M), Signal's early years | Bluesky ($36M raised before its $100M round; team under 30) |
8.2 Standard scenario, year 1, in detail
Personnel (12.5 FTE, fully loaded)
| Role | FTE | Cost per FTE | Total |
|---|---|---|---|
| Protocol lead and architect | 1 | €130k | €130k |
| Distributed-systems engineers (vault, discovery, log; Rust) | 3 | €110k | €330k |
| Agent and ML engineers (runtime, intent modelling, evaluation) | 2 | €115k | €230k |
| Cryptography, identity and supply-chain security engineer | 1 | €130k | €130k |
| Operations-research engineer (clearing solver) | 1 | €110k | €110k |
| Product designer (agent interface, briefs, onboarding) | 1 | €85k | €85k |
| Community and pilot leads | 2 | €70k | €140k |
| Governance, legal and standards lead | 1 | €100k | €100k |
| Operations and finance | 0.5 | €70k | €35k |
| Personnel subtotal | 12.5 | €1,290k |
Non-personnel
| Item | Total |
|---|---|
| Infrastructure: clearing nodes, registries, log witnesses, build farm, monitoring (all on rented or community servers) | €30k |
| Inference for 5,000 pilot participants, on community GPU nodes | €25k |
| Community node hardware for pilots (single-board computers, one GPU node per pilot) | €15k |
| Security audits: protocol, reference node, sandbox | €120k |
| Legal: entity, licences, data protection | €80k |
| Pilot costs: community stipends, onboarding, events, travel | €120k |
| Research partnerships: matching theory, relational economics, evaluation, indigenous knowledge collaborations on their own terms | €60k |
| Non-personnel subtotal | €450k |
Overhead at 20 percent of personnel (offices, equipment, administration, insurance): €258k Contingency at 15 percent: €300k Year 1 total: approximately €2.3M
Years 2 and 3 grow personnel to 16 and 20 FTE, add €250k to 400k a year for community and pilot programmes, €150k to 250k a year for community compute hardware grants, and €100k a year for a second independent implementation. Audits and legal stay roughly flat. Because inference runs on principals' and communities' hardware, the programme's own inference bill stays small.
8.3 Marginal cost per participant
This is the number that decides whether GUANXI can be a commons rather than a subscription. At 300,000 participants:
| Component | Per participant per month | Basis |
|---|---|---|
| Vault and agent runtime on own device | €0 | local-first default |
| Share of a community-hosted vault node (200 agents per €8 server) | €0.04 | Hetzner-class or cooperative server |
| Inference, local open model on own device | €0.01 to 0.05 | electricity for about 20 episodes a month on a 27B model |
| Inference, community GPU node shared by a few hundred members | €0.15 to 0.30 | electricity plus hardware amortisation of a consumer or L40S-class GPU |
| Clearing-house share (thousands of members per €10 node) | under €0.01 | |
| Transparency log and witnessing | under €0.01 | one €5 server per clearing house |
| External timestamping | €0 | OpenTimestamps |
| Registry and content storage | about €0.01 | |
| Total, fully local participant | about €0.05 | |
| Total, community-compute participant | about €0.20 to 0.40 |
At 300,000 participants with 40 percent using community compute, inference costs the communities collectively about €300k to 400k a year in electricity and hardware, which is why hardware grants sit in the programme budget and why the default model is small, open and local.
8.4 What the money does not buy
- Adoption. The cold-start problem is solved by seeding and by pilots with communities that already coordinate, not by spend.
- Legitimacy. Communities will only put their credit lines and their reputation into a clearing house whose rules they set. That is a governance outcome, not a budget line.
- Relationship. The system can introduce people; it cannot make them kin. Every indigenous economy named in section 2.6 rests on ceremony, presence and time that no protocol supplies.
- Policy change. GUANXI is the substrate for coordination that influences policy; the influence itself is the work of the people it connects.
9Risks and open questions
Clearing rates may disappoint. The benchmark numbers come from B2B invoice graphs, which are denser than early-stage need-and-offer graphs. The first pilots may clear far less than 10 percent. Mitigation: seed densely within a domain and region, allow credit lines from day one, and treat the first year's clearing rate as a measurement, not a promise.
Warning: regulatory and tax classification. Depending on jurisdiction and on whether balances are redeemable, community credit lines may fall under e-money, payment-services or consumer-credit rules, and non-monetary exchange may be taxable at market value. Sardex shows one way through, euro-equivalent units and ordinary invoices. Flagged here so nobody is surprised; not treated further in this paper.
Local-first has a capability ceiling. Refusing cloud frontier models and confidential cloud compute means agents run smaller models, and some principals' devices will not run them at all. Community compute nodes close most of the gap, but they reintroduce a party who can, in principle, see delegated data. The design accepts this trade, trusting known people over unknown vendors, and measures how many participants stay fully local.
Privacy under adversarial conditions. Progressive disclosure protects against casual leakage, not against a patient adversary running many agents. Rate limits, attestation-gated tiers and anomaly alerts are ongoing commitments, not a fix.
Model dependency. Even with a commons default model, agents inherit the biases and failure modes of whatever they run. The same-model rule trades diversity for fairness inside a match; across communities, diversity should be encouraged.
Capture by the back door. A dominant implementation, host or model provider becomes a de facto centre. The steward must actively fund alternatives; the standard budget does from year two.
Extraction dressed as respect. Drawing on indigenous economies carries the risk of taking their vocabulary without their relationships. Mitigation: collaborations on the knowledge holders' own terms, funded and credited, and a willingness to be told that a mapping is wrong and to remove it.
Governance load. Commons fail when stewardship is under-resourced. The standard scenario funds a governance lead from year one and charters the steward in year three; if that slips, so does everything else.
The honesty question. GUANXI cannot promise "no accounting". It promises no currency, no interest, no convertibility, and balances that fade. Whether communities experience that as liberation or as a new ledger to be anxious about is an empirical question the pilots must answer.
Open technical questions. Optimal cycle-length limits for sparse social graphs; decay functions for credit and reputation that match how human obligation actually fades; how to weight relationship continuity against cleared value in the solver's objective; how to price legs whose value bands do not overlap; whether the solver can run as a multi-party computation or inside the principals' sandboxes so that a clearing house never sees intents in clear; how provisional agents earn trust.
10Key sources
Full source lists with URLs and verification flags are in the three research appendices. The most load-bearing:
Anthropology, relational economics and indigenous thought. Duran Bell, "Guanxi: A Nesting of Groups", Current Anthropology 41(1), 2000. Mayfair Yang, Gifts, Favors, and Banquets, 1994. Marcel Mauss, The Gift, 1925. Marshall Sahlins, Stone Age Economics, 1972. Karl Polanyi, The Great Transformation, 1944. David Graeber, Debt: The First 5,000 Years, 2011. Elinor Ostrom, Governing the Commons, 1990. Josef Wieland, Relational Economics: A Political Economy, 2020. Luigino Bruni and Stefano Zamagni, Civil Economy, 2016. Robin Wall Kimmerer, Braiding Sweetgrass, 2013, and The Serviceberry, 2024. Tyson Yunkaporta, Sand Talk, 2019. Stephen Lansing, Priests and Programmers, 1991. Te Awa Tupua (Whanganui River Claims Settlement) Act, 2017. Constitution of Ecuador, 2008 (sumak kawsay). Heliogenesis, heliogenesis.io (Model, Catalogue, Plan). WELTAUFGANG, Act 3 (Coordination), for the rival/non-rival separation.
Multilateral clearing. Roth, Sönmez, Ünver, kidney exchange (QJE 2004; AER 2007). Anderson, Ashlagi, Gamarnik, Roth, "Finding long chains in kidney exchange", PNAS 2015. Fleischman, Dini, Littera, Sardex netting study, JRFM 2020. Cycles Protocol whitepaper, arXiv 2507.22309. de la Rosa and Madugula, Italian invoice netting, arXiv 2606.26126. Slovenia AJPES multilateral set-off.
LLM agents. Meta, Cicero, Science 2022. Bianchi et al., NegotiationArena, ICML 2024. "The Illusion of Rationality", arXiv 2512.09254. "LLM Rationalis?", arXiv 2512.13063. "Counterparty Modeling is Not Strategy", arXiv 2605.16575. TERMS-Bench, arXiv 2605.13909. "Do Matching Mechanisms Work with LLM Agents?", arXiv 2606.03030. Andon Labs, Vending-Bench, arXiv 2502.15840. Anthropic, Project Vend phases 1 and 2. Fish, Gonczarowski, Shorrer, algorithmic collusion by LLMs, EC 2026. AP2 security analysis, arXiv 2608.23858. Governance gap analysis of agent protocols, arXiv 2606.31498. ERC-8004 empirical study, arXiv 2606.26028.
Protocols and infrastructure. A2A (Linux Foundation). MCP (Agentic AI Foundation). AP2 (Google). NANDA, arXiv 2507.14263. Solid protocol (Open Data Institute) and Community Solid Server. W3C VC 2.0 Recommendations, May 2025; DID 1.1 CR, March 2026; did:webvh (DIF). EU Regulation 2024/1183 and Implementing Regulation 2025/848; EUDI reference wallet. RFC 6962 Certificate Transparency; Trillian; Sigstore Rekor; Sigsum; OpenTimestamps. RFC 9420 Messaging Layer Security; OpenMLS. FROST threshold signatures. Semaphore. WebAssembly System Interface and Wasmtime. Iroh 1.0. HiGHS; OR-Tools; SCIP. llama.cpp; vLLM.
Costs. Glassdoor and Ravio salary data, Berlin and Lisbon, 2026. Hetzner, DigitalOcean, getdeploying GPU price indexes, September 2026. Local inference cost measurements, Towards Data Science, July 2026. Mastodon gGmbH Annual Report 2024. Matrix.org Foundation annual report, March 2026. Signal Technology Foundation Form 990, 2024. Bluesky funding announcements 2023 to 2026. Wikimedia fundraising statistics.
GUANXI is a placeholder name. It names what the system does, resolving obligation across a network of relationships over time, and pays respect to a tradition that has done so for millennia without a coin. All my relations.