Skip to content
Tenzro
Reference design · PhysiClaw

Accountable physical AI on Tenzro Network 1.

A reference design for robots, drones and connected devices that take on paid work in the physical world, prove what they did, and get paid on completion.
Overview

Machines that hold their own identity and earn their own keep.

PhysiClaw is an illustrative design, not a deployed product. Each device has a machine identity derived from the key in its TPM 2.0 or Secure Enclave. It takes jobs under a scope its owner or customer sets, runs perception and planning models on board or on the network, signs its sensor evidence with its device key, and is paid from escrow when the work is confirmed.
Architecture

Network 1 primitives PhysiClaw uses.

  • Machine identities

    Each robot or drone has a did:tenzro:machine identity derived from its device key. It holds its own account, bond and reputation, under a controller it names.
  • Signed sensor evidence

    Sensor readings and action logs are signed with the device's hardware-rooted key, so a customer can check which machine produced them.
  • Attested remote compute

    Heavy perception or planning runs on network operators inside Intel TDX, AMD SEV-SNP, AWS Nitro or NVIDIA confidential GPUs, with attestation verified per vendor.
  • Multimodal inference

    Vision, segmentation, detection and speech models through OpenAI-compatible APIs and Tenzro extensions, on board or routed to network operators.
  • Bonds and policies

    Operators post an agent bond and publish a signed policy for the work they accept. Slashing applies only to provable breaches of that policy.
  • Settlement on completion

    Escrow is released when the work is confirmed, or metered per use for continuous services, in TNZO or stablecoins.
Flow

How it works, end to end.

  1. 01

    Provision the device

    The owner registers the device's machine identity from its TPM 2.0 or Secure Enclave, posts a bond and publishes a signed operating policy.

  2. 02

    Customer books a job

    A customer or their agent books a task (deliver, inspect, monitor) and delegates a scope to the device, with payment held in escrow.

  3. 03

    Device does the work

    Sensors capture; perception models run on board or in an attested enclave; the planner acts within the delegated scope.

  4. 04

    Evidence is signed

    The device returns a receipt with signed sensor evidence and, for remote inference, the attestation of the enclave that ran it.

  5. 05

    Payment settles

    Escrow is released to the device's account on confirmation. Network fees are paid in TNZO; the customer can pay in stablecoins.

  6. 06

    Reputation builds

    Completed jobs feed ERC-8004 reputation and trust credentials that customers use to choose devices for the next job.