Skip to main content
← Back to glossary
Compliance & consent

Delegate certificate (ATIS-1000092)

Qu'est-ce que Delegate certificate (ATIS-1000092)?

Cette entrée n'est actuellement disponible qu'en anglais.

A delegate certificate is the credential your service provider issues under the ATIS-1000092 delegated-attestation standard to authorize specific caller IDs — typically bring-your-own-number (BYON) numbers you legitimately control but do not own through your platform. Registering the certificate with Orbit lifts the numbers it covers from C (gateway) attestation to B (partial) and never to A (full); it is a tenant-controlled authorisation artifact, validated for lifecycle only, with B locked as its deliberate ceiling.

More detail

The artifact records a friendly name, SPC, fingerprint, PEM, plus a covered-number and covered-range list — the list is free-form input, not bound to the certificate's real TNAuthList, and the chain itself is not cryptographically validated by the platform. That is precisely why B (customer authenticated, number authorization not provider-verified) is the ceiling.

The resolver runs the certificate lifecycle live: a certificate that is not yet valid, past its validity window, or revoked stops covering its numbers, and they fall back to their ownership-based level on the next call. A self-registered artifact must never be able to spoof full attestation for arbitrary numbers — so B is a deliberate ceiling, not an accident.

Resolution fails open to C: if the certificate lookup or the ownership checks fail at dial time, the call still places — signalled at C rather than blocked. You can list, register, and revoke certificates over `/compliance/attestation/delegate-certs`; the listing endpoint also reports the org's `max_certificates` ceiling.

Questions fréquentes

Does registering a delegate certificate raise my BYON numbers to full (A) attestation?
No — the deliberate ceiling is B (partial). The certificate is a tenant-supplied artifact; its chain is not cryptographically validated and its covered list is not bound to the certificate's TNAuthList, so it will never sign at full attestation. Signing at full (A) requires the caller ID to resolve to a number your organization owns through Orbit, purchased or ported in and billed to you.
What happens to covered numbers when the certificate expires or is revoked?
They fall back to their ownership-based level — C for a typical BYON number — on the next call. The delegate-cert section of the attestation policy lists each one with its effective status (active, pending, expired, or revoked) so you can see which numbers have stopped rising before the next dial.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.