TEPP · Trust Extended Permissions Protocol

A home, not a prison.

TEPP lets guardians — parents, in the motivating case — bound a person's world on Nostr: the people, places and things that may reach them, and those they may act on. The person's own software enforces it, explains every decision, and changes who governs only with their own signature.

Peoplenpubs — who may reach the subject, and whom the subject may address
Placesrelays — where events may come from, and where the subject's own may go
Thingsevents — one particular post, by its id

In one minute

How TEPP works

1

Policy is ordinary Nostr events

Each guardian publishes policy carriers — open, or sealed: encrypted to the subject. No TEPP server, no special relay.

2

The subject consents to who governs

The subject's own signed association names its guardians. A guardian can only offer a new guardian set; the subject ratifies it with a signature, or ignores it.

3

Trust extends

A grant's members can double as sources: adopt what a school or a helpline directory publishes, inherit what a friend is permitted — one hop, each harvested grant held to both sides' rules.

4

Two questions, two temperaments

May this reach the subject? One permitted person, place or thing is enough. May the subject sign this? Everyone and everything it names must be covered.

5

Private is analysed, not exempted

For encrypted messages the engine recovers who they involve — never keeping what they say. Sending one needs exactly what a public mention needs; receiving one needs an interact grant on its sender.

6

Denies win; losses are reported

A guardian's deny over-rules every grant, wherever the engine meets it. Every verdict names what decided it, and whatever cannot be loaded is reported.

The big picture

TEPP at a glance

Guardians and third parties publish to ordinary relays; the subject's own engine fetches, verifies and assembles one construct, and answers two questions with it.

Reading is not acting

Two questions

May this arriving event reach the subject?

  1. Is it genuine?
  2. Does the subject-wide gate allow it now?
  3. Does anything on it hit a deny?
  4. One hit admits: a permitted place, person or thing — or the subject's own.

Beneath an admitted event, referenced events are only deny-checked: a stranger seen in a trusted thread is not a stranger reached.

May the subject sign this event?

  1. Does the subject-wide gate allow it now?
  2. Is anything it references denied — down the chain?
  3. Is everyone and everything it names covered — by an interact grant, or as the subject's own event?
  4. Are its destinations allowed?

A tag in a signed event is an act — clients notify everyone tagged — so the subject answers for every element under its signature.

Two levels

Pick your depth

high-level

The big picture

What TEPP is for, who is who, how consent works, the two questions, trust extension, private messages, and the honest limits. No prior knowledge of the specification needed.

mid-technical

How it works

The six event kinds, the ceremony, policy documents, restriction regimes and profiles, assembly, input and output evaluation, the sealed channel and its oracles, loci, lifecycle and the trace.

For parents and newcomers: TEPP – Permission that scales explains what TEPP does for a family, in plain words, without the mechanics.

Said out loud

Honest limits

Where the guardian is the threat, TEPP is not the remedy. It cannot open a channel the guardians have not permitted.

The boundary is key custody and device control. Enforcement binds a cooperating subject and produces evidence about a defecting one.

A permitted private channel is private — guardians included. What the household keeps is who, never what.

No release ceremony. A regime ends outside the protocol: by deleting the association or signing a newer one — both signed, public acts — or by no longer running TEPP software.