why · names

The most numerous agents
on earth are anonymous

Count the agents that actually exist. Not the demo bots, not the enterprise pilots: the personal agents. They outnumber every other kind by orders of magnitude, and almost none of them have a name you can hand to another person.

the audience nobody serves

Built for the other agents

Claude Code and Codex sessions in terminals. OpenClaw and Hermes assistants on gateways. The agent that reads your mail, the one that watches your builds. Every existing directory was built for the hosted, corporate, capability-marketed kind of agent. Personal agents were left out, because their owners have an email address and nothing else: no domain, no PKI, no ops team. PAN starts from exactly that.

Your agent gets a name you can put in an email signature, say in a meeting, or paste into another agent's config.

the dns question

Where's the IP address?

DNS maps a name to an IP because servers sit at stable, reachable locations. Your agent doesn't: it lives on a laptop that sleeps, moves between networks, and sits behind a router whose address your ISP rotates and which accepts no incoming connections. An IP names the router of wherever your agent happens to be, not the agent.

So a PAN record points at an identity instead of a location: the agent's key. The agent keeps an outbound connection open, and delivery finds it wherever it is, the same way your phone gets messages without having a public IP. PAN is DNS-shaped naming for things that don't have, and shouldn't want, a stable address. Your console still shows where each agent last connected from, the way your email shows last account activity: recognition, not routing.

who owns it

The name outlives the registrar

A registrar is a custodian, not an owner. It witnessed your claim and it keeps the record, and that is the whole of its standing. It has no power to keep a name whose owner has moved on.

So a handle can move. Point it at a different registrar and the name does not change: the old registrar starts answering with a referral to the new one, and it is not allowed to hand your name to anybody else afterwards. Nobody has to be told, because the name they already have keeps working.

No registrar can take a name either. Before a registrar accepts a handle moving in, it has to hear from the one letting go, and confirm the name was released to it specifically. A registrar that simply asserts a name it was never given is refused. That is the difference between this and the certificate world, where any authority can vouch for any name and the system is only as strong as its weakest one.

And if you own the domain in your address, you outrank every registrar: serve the record yourself and your answer is the one that counts.

Through all of it the agent's key never changes, so none of this is an identity event. A new key would be a new agent. A new custodian is paperwork.

the scope

Names, and nothing more

PAN does one job for this audience: it turns a string you pick into an address other agents can reach. It does not run discovery, does not grade agents, and does not carry messages. Presence may ride along on a resolved card where a source happens to observe it, but that is a bonus, not the point. The name and its address come first.