TEPP · Trust Extended Permissions Protocol
A home, not a prison.
TEPP lets guardians — parents, in the motivating case — bound a person's world on Nostr: the people, places and things that may reach them, and those they may act on. The person's own software enforces it, explains every decision, and changes who governs only with their own signature.
In one minute
How TEPP works
Policy is ordinary Nostr events
Each guardian publishes policy carriers — open, or sealed: encrypted to the subject. No TEPP server, no special relay.
The subject consents to who governs
The subject's own signed association names its guardians. A guardian can only offer a new guardian set; the subject ratifies it with a signature, or ignores it.
Trust extends
A grant's members can double as sources: adopt what a school or a helpline directory publishes, inherit what a friend is permitted — one hop, each harvested grant held to both sides' rules.
Two questions, two temperaments
May this reach the subject? One permitted person, place or thing is enough. May the subject sign this? Everyone and everything it names must be covered.
Private is analysed, not exempted
For encrypted messages the engine recovers who they involve — never keeping what they say. Sending one needs exactly what a public mention needs; receiving one needs an interact grant on its sender.
Denies win; losses are reported
A guardian's deny over-rules every grant, wherever the engine meets it. Every verdict names what decided it, and whatever cannot be loaded is reported.
The big picture
TEPP at a glance
Guardians and third parties publish to ordinary relays; the subject's own engine fetches, verifies and assembles one construct, and answers two questions with it.
Reading is not acting
Two questions
May this arriving event reach the subject?
- Is it genuine?
- Does the subject-wide gate allow it now?
- Does anything on it hit a deny?
- One hit admits: a permitted place, person or thing — or the subject's own.
Beneath an admitted event, referenced events are only deny-checked: a stranger seen in a trusted thread is not a stranger reached.
May the subject sign this event?
- Does the subject-wide gate allow it now?
- Is anything it references denied — down the chain?
- Is everyone and everything it names covered — by an interact grant, or as the subject's own event?
- Are its destinations allowed?
A tag in a signed event is an act — clients notify everyone tagged — so the subject answers for every element under its signature.
Two levels
Pick your depth
The big picture
What TEPP is for, who is who, how consent works, the two questions, trust extension, private messages, and the honest limits. No prior knowledge of the specification needed.
How it works
The six event kinds, the ceremony, policy documents, restriction regimes and profiles, assembly, input and output evaluation, the sealed channel and its oracles, loci, lifecycle and the trace.
For parents and newcomers: TEPP – Permission that scales explains what TEPP does for a family, in plain words, without the mechanics.
Said out loud
Honest limits
Where the guardian is the threat, TEPP is not the remedy. It cannot open a channel the guardians have not permitted.
The boundary is key custody and device control. Enforcement binds a cooperating subject and produces evidence about a defecting one.
A permitted private channel is private — guardians included. What the household keeps is who, never what.
No release ceremony. A regime ends outside the protocol: by deleting the association or signing a newer one — both signed, public acts — or by no longer running TEPP software.