A laboratory benchmarking methodology, aimed at the Benchmarking Methodology Working Group, for measuring whether an AI agent's memory subsystem can detect tampering with its stored memory - alteration, deletion, reordering, replay, or forgery at the storage layer - and whether it refuses to use, or alerts on, that memory before serving it. The method specifies eight storage-level edits, three verdict categories, a read-time vs. audit-time detection distinction, two control scenarios, and a scoring approach, in the reproducible tradition of RFC 2544 and RFC 8239. It is written as the test method for a proposed "Protection of Memory Data Integrity" metric.
Defines a YANG data model for the management of Quality of Service (QoS) in IP networks, giving operators a standard, vendor-neutral schema for QoS configuration and management.
Describes GAAP (Group Address Allocation Protocol, "gap"), a lightweight, decentralized protocol for allocating multicast group addresses with no centralized service, though it depends on ASM-capable multicast routing being available. It runs among group participants that need unique multicast addresses, works for both IPv4 and IPv6, and offers a simpler alternative to extending existing protocols. GAAP is specified as an Experimental protocol, with rationale and experiment-conclusion criteria set out in the document.
Specifies Hybrid Public Key Encryption (HPKE), a scheme for public-key encryption of arbitrary-sized plaintexts to a recipient public key, including a variant that authenticates possession of a pre-shared key. HPKE works with any combination of a Key Encapsulation Mechanism (KEM), key derivation function (KDF), and AEAD, with practical instantiations over ECDH, HKDF, and SHA-2. This revision supersedes RFC 9180.
Defines the Action Evidence Boundary (AEB), an executor-side processing model for consequential agent actions that cross multiple systems. AEB mandates native artifact verification, exact-action binding, authorization decisions, durable atomic consumption or reservation of one-time authority, and authenticated reconciliation. A grant is uniquely identified through a relying-party-pinned authority namespace and native authorization identifier so rewrapped grants cannot be reused, and a durable same-action fence blocks duplicate in-flight attempts even when fresh authority is presented. It introduces no new token, receipt, or policy language: OAuth artifacts, AuthZEN decisions, workload credentials, and payment mandates keep their native semantics.
Defines a new BGP Edge Metadata Path Attribute and Sub-TLVs so egress routers can advertise metadata about attached edge services. Ingress routers in 5G Local Data Networks can then select paths based on both routing cost and the running environment of the edge services, improving latency and performance. Among other things, it lets a specific edge-service location (behind a shared anycast IP) be preferred to receive flows from particular sources such as specific User Equipment.
An informational memo arguing that TCP/IP standardized interoperability and end-to-end transport, and the Web standardized publishing and retrieval, but neither by itself specifies the operational properties needed for utility-grade Internet service at scale. It establishes terminology distinguishing interoperability standards from operational utility, then outlines requirements for "infrastructure activation" - provisioned transport, interconnection strategy, routing controls, redundancy, locality, monitoring, incident response, and service accountability. No protocol modifications are proposed.
Addresses delegation of agent tasks across organizational boundaries. Building on existing work that identifies, discovers, and describes agents and states cross-domain isolation and authorization requirements, it targets the identified gap of expressing capability policy. It defines four policy attributes for inter-domain agent delegation, the declarations each attribute carries, and a validity condition on delegation chains that no single party can establish by observing the whole chain.
A tongue-in-cheek memo investigating why global transport-layer encryption remains incomplete despite decades of IETF work. It identifies the primary obstacle as a class of legacy printing devices - often located in building basements - repeatedly cited to justify continued plaintext transmission. The document provides a taxonomy of such devices, analyzes the rhetorical structure of printer-based encryption-exemption claims, and proposes a framework for evaluating their validity.
Presents technical details of multiple CVEs and GitHub Security Advisories (GHSAs) arguing that "early attestation" fails in practice, even without physical access to the target machine, and that since continuous attestation is generally required, early attestation adds unnecessary complexity. Results are backed by ProVerif models and Apache-2.0 artifacts, covering two CVSS-9.1 CVEs, one CVSS-7.5 CVE, and several high-severity GHSAs across ecosystem layers. It names Edgeless Systems Contrast and Meta's AI implementations as remaining vulnerable. (This document has been posted in a rapid sequence of revisions.)
Defines AAuth, an authorization protocol for agent-to-resource authorization and identity-claim retrieval. It supports five resource access modes - agent identity, resource-managed (two-party), person identity, PS authorization (three-party), and federated authorization (four-party) - with agent governance as an orthogonal layer. It builds on the HTTP Signature Keys specification for HTTP Message Signatures and key discovery.
Notes that several numbered NFSv4 protocol elements - operations, callback operations, status codes, file attributes, and ACCESS/OPEN flags - lack IANA registry assignments, creating collision risk when concurrent extensions assign the same values to different elements. It requests IANA registries for each element type, populates them from published RFCs, and requires future elements to obtain values through these registries. Updates RFC 8178.
Extends the Zero Trust Fabric Layer (ZTFL), which handled single-agent authorization but not what happens when an agent delegates its authority to a second or third agent. It adds a chained authorization model using travel metaphors: a Passport establishes identity across the chain; a Ticket, issued once at task initiation, binds every hop as an ephemeral credential; per-hop Boarding Passes derive from and trace back to the Ticket; and a Visa gives explicit authorization when crossing tenant boundaries. The model provides chain-wide traceability to a single origin and containment at the boundary, formalized mathematically and validated against Cedar policy.
In confidential computing, device assignment lets devices such as network adapters or GPUs be assigned to Trusted Virtual Machines (TVMs). For a TVM to trust an assigned device, the device must supply attestation evidence of its identity, firmware state, and configuration. Because that evidence may be processed by external entities such as verifiers, this document standardizes how device-assignment information is represented, defining an attestation-evidence format for device assignment as an EAT (Entity Attestation Token) profile.
Describes a manufacturer-assisted mechanism for distributing operational CA certificates to devices using EST or EST-over-secure-CoAP, aimed at deployments where a device is manufactured before the operational PKI and EST trust anchors are known. The device receives a manufacturer trust anchor during production; later, a manufacturer-signed operational CA-certificate bundle is delivered through a manufacturer-specific EST alias, and the device validates it against its manufacturer anchor before installing the certificates as operational trust anchors. The mechanism is confined to CA bootstrap and does not alter EST enrollment semantics, proof-of-possession, or CA policy.
Defines two email-header mechanisms for verifying properties of automated senders using the Agent Identity Registry System (AIRS). Mode 1 uses a detached CMS signature from a message-signing proof key to establish manufacturer-backed hardware provenance, Registrar-authenticated AIRS identity binding, or both. Mode 2 carries a per-message SD-JWT letting a Registrar assert selected properties while optionally withholding the sender's canonical AIRS identifier. It relies on companion AIRS documents for the underlying identity model and applies those concepts to email message binding and verification.
Presents the Agent Identity Registry System (AIRS), a federated architecture giving an autonomous entity's durable identity a permanent canonical identifier, an authoritative record, proof-of-control bound to enrolled anchors, and verifiable credentials. Canonical identifiers use URNs in the "aid" namespace, and trust is organized into five tiers by anchor strength - sovereign (TPM 2.0), portable (PIV tokens), enclave, virtual, and declared (software-only). Higher tiers give stronger anti-Sybil properties; lower tiers allow software-only participation with clearly labeled reduced assurance. It separates governance, registry operations, and competing registrars, using OAuth 2.0 JWT tokens and following a DNS-like decentralized model with a single production uniqueness index.
Describes the read-side operations of the Agent Identity Registry System (AIRS): how relying parties discover the resolution service, retrieve public records, resolve handles to canonical "aid" identifiers, and verify registrar-issued credentials. Discovery uses DNS-based URN Dynamic Delegation Discovery System (DDDS), lookups use the Registration Data Access Protocol (RDAP), and credential verification reuses AIRS's OAuth 2.0 JWT access-token and sender-constraint profiles, introducing no new credential formats or generic device-proof protocols.
Defines an EPP (Extensible Provisioning Protocol) mapping for provisioning agent-identity and handle objects in the AIRS repository. It specifies two objects: a permanent, non-expiring Agent Identity object with a server-allocated identifier, and a renewable Handle object providing human-readable aliases. Key features include cross-Registrar enforcement of enrolled-anchor identifier uniqueness and transfer authorization via actor-signed proofs from operational proof keys rather than passwords.
Defines the Agent Identity Authority (AIA), the governance body that the AIRS specifications describe but deliberately do not constitute. It specifies the Authority's name, legal form, mission, and relationship to the protocol specs; its membership categories and Board composition; binding geographic-diversity rules and non-binding advisory recommendations; and the accreditation, dispute-resolution, hardware-trust-store, transparency, and funding frameworks it operates, plus the bootstrap process by which it forms. The AIA governs infrastructure - the "aid" namespace, hardware roots of trust, accreditation, and Registry Operator succession - not agent behavior, and is chartered so no single nation, region, or company can capture it.
An informational framing and vocabulary document for the AIRS family of specifications. It argues that autonomous software agents and robots now operate at machine scale with legal, economic, safety, and security consequences, and that any credential, authorization, or liability tied to such an entity needs reliable identification over time. It establishes precise terminology separating "identity" from identifiers, credentials, and reputation - introducing "identity0" for durable identity in the strict sense - and presents a layered reference model showing where existing agent-identity efforts fit and which foundational identity layer they presuppose but do not provide.
Establishes clear terminology for expressions like "IPv6-Only" and "IPv6-Mostly" to prevent confusion across IETF and related documents. Its key goal is to ensure that "IPv6-Only" describes functionality actually being used within a specific scope, rather than merely the protocol support that happens to be installed.
A tutorial ("layman's guide") introducing a practical subset of ASN.1, the Basic Encoding Rules (BER), and the Distinguished Encoding Rules (DER). It provides enough background to understand and implement standards that make use of ASN.1. The memo is explicitly not an IETF standard and has not been shown to have community consensus; it offers tutorial information only.
Specifies the Secure Asset Transfer Protocol (SATP), which operates between two gateways to transfer a digital asset from one gateway to another, each representing its corresponding digital-asset network. It establishes secure communication channels between the endpoints and uses a two-phase commit mechanism to guarantee atomicity, consistency, isolation, and durability in asset transfers.
By its name, this individual draft probably specifies an audit-trail mechanism for AI agents - likely a structured, verifiable record of agent actions for accountability and traceability. The official Abstract could not be retrieved this run (the fast source returned a 404), so this description is approximate and will be grounded on the next run.
Specifies a QUIC extension that lets a server advertise a prioritized set of alternative addresses, so a client can migrate the connection as the availability of, or preference among, server addresses changes.
Updates RFC 7518 to deprecate the JWS algorithm "none" and the JWE algorithm "RSA1_5", both of which have known security weaknesses. It also updates the Review Instructions for Designated Experts to set baseline security requirements that future algorithm registrations are expected to meet.
Introduces an optional link-state database synchronization packet, the Aggregated SNP Hash (ASH), which compresses traditional SNP exchanges into a dynamic Merkle-tree-like structure to speed up synchronization of large databases and adjacencies while reducing the load of regular CSNP exchanges during normal operation. Like traditional SNP variants, ASH comes in Complete (CASH) and Partial (PASH) forms.
Specifies Cuback, an ACK-driven reformulation of CUBIC congestion control. It replaces CUBIC's mutable time- and ACK-driven state with pure functions over immutable per-epoch parameters (for which test vectors are provided), and grows the congestion window with the same ACK-driven mechanism as Reno, removing several sources of implementation error. When entering a high-capacity path, a newcomer converges on its share sooner than under CUBIC, so short flows complete earlier.
Defines a DNS-based mechanism for discovering Model Context Protocol (MCP) servers and their operators' identities using three TXT records: _mcp.<domain> advertises the server endpoint, protocol family, transport binding, cryptographic identity, and capabilities; _org-alter.<domain> publishes the operator's organizational identity including legal entity and regulatory frameworks; and _alter.<domain> publishes an Ed25519-signed envelope binding a handle to a public key, an IdentityLog root reference, and a revocation commitment. It mandates DNSSEC validation for envelope records and DANE TLSA pins on MCP endpoints, complements HTTPS-based discovery, follows DKIM/SPF/DMARC/MTA-STS precedents, and requests provisional registration of an "alter:" URI scheme.
Describes a protocol by which on-path network elements can communicate their view of the maximum sustainable throughput for QUIC flows to the endpoints. This throughput advice suggests an upper bound on long-term average throughput, independent of and complementary to real-time congestion-control signals.
An extension for MoQ Transport that lets an endpoint declare that advertisements to it must be solicited first. Endpoints that declare nothing keep receiving unsolicited PUBLISH_NAMESPACE messages (the default), while those implementing this extension can request solicited-only advertisements during setup to avoid unwanted messages. Because sending the option identifies compliant endpoints, the requirement is enforceable between two such endpoints rather than merely advisory.
Specifies moq-e2ee, a versioned profile for end-to-end encryption of MoQ application payloads. Authorized publishers and subscribers share a 32-byte broadcast secret out of band; each publisher instance mints an epoch and publishes under an opaque broadcast path ending in it. HKDF-SHA-256 derives opaque physical track names and per-track AES-128-GCM keys from the secret and epoch, with separate key domains for grouped frames and datagrams. Media frames and datagrams carry only ciphertext plus a 16-byte tag, and object identity is bound through derivation and the nonce rather than an on-wire header.
Defines the "mpegts" catalog section for MoQ, recording what demultiplexing an MPEG-2 Transport Stream into a MoQ broadcast would otherwise lose: each track's PID and PMT descriptors, the program identity, the service-information tables, and a carriage record for every elementary stream the publisher did not decode. It is a root member of either the hang catalog or the MSF catalog, so a subscriber that ignores it still plays the broadcast while one that reads it can rebuild the source multiplex.
Defines Hang, a real-time conferencing protocol built on top of moq-lite. A room consists of multiple participants who publish media tracks, and all updates - such as a change in participants or in their media tracks - are delivered live.
Describes moq-lite, a transport designed to fan out live content 1-to-N across the Internet. It leverages QUIC to prioritize important content and avoid head-of-line blocking while respecting encoding dependencies. The protocol is payload-agnostic, so relays and CDNs can proxy it without knowing codecs, containers, or encryption keys, making it suitable for media delivery yet broadly applicable.
Specifies how a MoQ Transport track carries DEFLATE-compressed payloads. Each subgroup is a single raw DEFLATE stream, sync-flushed at every object boundary, so each object stays self-delimited while later objects compress against earlier ones in the same subgroup. Small repetitive payloads compress several times better than in isolation, and a dropped group costs nothing beyond itself because the compression window never spans more than one. Nothing is added to the wire: the application declares the track compressed and a relay forwards it unchanged.
Guidance for operators moving toward IPv6-only data centers to simplify addressing, restore end-to-end connectivity, and meet operator and government timelines. Unlike much published IPv6 guidance aimed at network engineers, this document targets Site Reliability Engineers (SREs) and Software Engineers (SWEs) who deploy, operate, and debug services in operator-owned data centers. It is organized into migration strategies, building the data center, tools and best practices, and pitfalls, with IPv6 fundamentals in an appendix, and it documents common software/infrastructure gaps aligned with the v6ops charter.
Defines a standard mechanism to signal that a DNS zone cut exists without specifying authoritative nameservers for the delegated child zone. This "zone cut to nowhere" is especially useful in split-horizon environments, letting a parent zone explicitly signal that a child zone exists but is only resolvable within a private namespace.
Describes a mechanism for disclosing that a Negative Trust Anchor (NTA) was in effect at the time a DNS response was generated, conveyed using an Extended DNS Error (EDE).
Extends the MOQT Streaming Format catalog by defining the "mpeg2ts" packaging value for carrying MPEG-2 Transport Stream and M2TS source packets over MOQT. It specifies catalog-extension fields describing transport-stream tracks and outlines subscriber behavior for joining, switching, and validating packetized streams.
Describes how to securely exchange structured business data over HTTP - XML, EDI (ANSI X12 or UN/EDIFACT), or other structured formats - packaged using standard MIME structures. Authentication and confidentiality use Cryptographic Message Syntax with S/MIME security body parts, and authenticated acknowledgements use multipart/signed Message Disposition Notification responses. This applicability statement, informally "AS2", succeeds "AS1" (RFC 3335), obsoletes RFC 4130, and updates related IANA registries originally created by RFC 3335 and RFC 4130.
Presents technical details of multiple CVEs and GitHub Security Advisories (GHSAs) arguing that "early attestation" fails in practice, even without physical access to the target machine, and that since continuous attestation is generally required, early attestation adds unnecessary complexity. Results are backed by ProVerif models and Apache-2.0 artifacts, covering two CVSS-9.1 CVEs, one CVSS-7.5 CVE, and several high-severity GHSAs across ecosystem layers. It names Edgeless Systems Contrast and Meta's AI implementations as remaining vulnerable. (This document has been posted in a rapid sequence of revisions.)
Addresses problems that arise when tunneling technologies (GRE, MPLS, SR-MPLS, SRv6) decouple BGP's control-plane view of next-hops from the actual data-plane forwarding endpoints - including suboptimal path selection, incorrect resolvability tracking, traffic loss, and misrouting. It describes how BGP can obtain resolvability, preference, metric, and tracking information from forwarding-path resolution and then apply those values in BGP best-path selection.
Motivates IP-in-space work by describing deep-space communications, where one-way delays are long (for example 4-24 minutes Earth-to-Mars) and connectivity is intermittent, mainly due to orbital dynamics. Standard Internet protocols assume the short delays and continuous connectivity that do not hold there. The document outlines the essential characteristics, applications, and technical requirements for IP-based networking in deep-space contexts.
Defines RTP payload formats for Video-based Dynamic Mesh Coding (V-DMC), which comprises a base mesh, AC-based displacements, 2D attribute representations, and an atlas. This document focuses on the base-mesh and displacement components (atlas and attributes are handled elsewhere), specifying RTP payload-header formats for packetizing base-mesh or displacement NAL units and for fragmenting NAL units across multiple RTP packets.
Explores the recurring problem of using an IGP to carry arbitrary information - captured by the phrase "the IGP is not a dump truck". It describes the kinds of information typically carried in an IGP and proposes an approach to changing the system so that inappropriate information is not loaded into it.
Defines a mechanism for temporal anchoring of digital artifacts by committing cryptographic hashes to the Bitcoin blockchain via the OpenTimestamps protocol. The resulting proof is independently verifiable by anyone with access to independently validated Bitcoin chain data, without contacting the anchoring service. The SCITT architecture is used as the primary integration example, and no changes to SCITT are required.
Provides guidance to authors and reviewers on the operational and management aspects that should be addressed when specifying new protocols or protocol extensions in the IETF Stream, on the premise that retrofitting operations and management is suboptimal. It obsoletes and completely replaces RFC 5706 with updated techniques, updates RFC 2360 to remove mandatory MIB creation, and introduces a requirement to include an "Operational Considerations" section in new IETF-Stream RFCs (with an escape clause when no new considerations are identified).
Describes an Extensible Provisioning Protocol (EPP) mapping for retrieving a client's account balance and other financial information from a registry.
Describes a method to mitigate Denial-of-Service attacks using a well-known BGP community named "DOWNGRADE" as a signal for neighboring networks to treat traffic toward DOWNGRADE-tagged prefixes with low precedence. This "downgrade" strategy is offered as an appealing alternative to Remotely Triggered Blackhole (RTBH) filtering, which effectively completes the DoS attack and hampers the defender's ability to see whether the attack is still ongoing.
Defines PCEP extensions to configure where Entropy Label Indicator/Entropy Label (ELI/EL) pairs should be positioned within SR-MPLS label stacks - the Entropy Label Positions (ELP). Entropy labels improve load-balancing in the SR-MPLS data plane, and multiple ELI/EL pairs may be inserted per RFC 8662; this work lets a Path Computation Element control their placement.
Describes the security features of the NFSv4 protocol family across all minor versions, focusing on per-connection RPC security while noting that ACL authorization details are covered in a separate document. It aims to support working-group discussion of existing NFSv4 security issues and to establish a framework for addressing them; when eventually published as RFCs, it and its companions would supersede the security descriptions in existing minor-version specifications such as RFC 7530 and RFC 8881.
Explains how Optical Transport Networks (OTN) can support Computation-Aware Traffic Steering (CATS). CATS selects computation service sites based on computing capability and load together with network state along the paths, while OTN provides guaranteed traffic separation and reserved hardware resources with bandwidth and QoS guarantees. The document shows how OTN can help CATS meet the stringent performance targets required by demanding service environments.
Specifies two companion URI schemes - "rttp" and "iqa" - whose addresses are derived by computation rather than by a lookup service. "rttp" names intent claims directed at identified subjects; "iqa" names attestation standing as reported by designated organs, carrying no proof or credentials. Both share a "no lookup" model (no DNS, registry queries, or fetches), derive deterministically from authority components, represent claims rather than proofs, and use fail-closed parsing. The document sets mandatory client requirements to prevent open redirects, restrict protocol-handler scope, and require explicit user consent, and stresses that parsing an "iqa" URI must never be presented as attestation evidence.
Describes a syntax for the Connect-Info attribute used with the RADIUS protocol, letting RADIUS clients provide the server with information about a user's connection to an IEEE 802.11 wireless network.
Describes a mechanism for generating interface-based prefix allowlists for intra-domain Source Address Validation (SAV) on external interfaces facing directly connected hosts or non-BGP customer networks. It derives source prefixes from routing data and combines them with operator-provisioned prefixes; routers then use the combined set to generate their SAV allowlists.
Specifies a CBOR encoding of X.509 certificates, called C509, supporting a large subset of RFC 5280 and common certificate profiles while remaining extensible. It defines two types: an invertible CBOR re-encoding of DER-encoded X.509 certificates (signature copied from the DER encoding), and one that computes the signature over the CBOR encoding, avoiding ASN.1 entirely. Both preserve X.509 semantics with comparable size reductions. It also specifies CBOR-encoded certification requests and templates, new COSE headers, a TLS certificate type, and a C509 file format, and updates RFC 6698 to extend the TLSA selectors registry to C509.
Defines PQ/T (post-quantum/traditional) composite schemes for OpenPGP based on ML-KEM and ML-DSA combined with ECDH and ECDSA using the NIST and Brainpool domain parameters, extending RFC 9980.
Defines a YANG data model for network-incident lifecycle management, providing a standard way to report, diagnose, and help reduce troubleshooting tickets and to resolve network incidents - supporting network-service health and probable root-cause analysis.
By its name, this RADEXT working-group draft (referred to as EPCS) probably defines a RADIUS extension - likely additional attributes or procedures for a specific access scenario. The official Abstract could not be retrieved this run (the fast source returned a 404), so this description is approximate and will be grounded on the next run.
Presents the Zero-Trust Data Sanitization (ZTDS) protocol, a framework for stripping personally identifiable information (PII), protected health information (PHI), payment-card data, and corporate credentials from text before it is sent to remote language models. It enforces processing strictly in volatile RAM, uses ephemeral surrogate tokens, keeps tab-isolated session maps, and guarantees zero network transmission of raw identifying data. Reversible mapping happens only at the client boundary, aiming to prevent cloud-proxy interception, prompt-injection attacks, and vector-database poisoning.
Specifies AER-1, a small vocabulary for recording a single AI-agent tool call as a portable, independently checkable execution receipt. A receipt identifies the execution, records when it happened, preserves the canonical bytes used for the output commitment, names the tool and caller scope, carries a provenance class, and resolves at a stable public URL. The format separates what the system observed from claims about the outside world, and separates provenance (who ran or reported the action) from the record itself; a reference implementation produces receipts that are publicly verifiable without an account or token.
Specifies AINS (AInternet Name Service), a protocol for discovering and identifying autonomous agents across heterogeneous networks. It provides a transport-independent namespace for agent identifiers and structured metadata combining identity, capabilities, route information, and cryptographic evidence references, resolved over HTTPS into rich metadata objects. A federation model based on signed append-only logs supports multi-registry deployment without a central authority. Unlike DNS, which maps names to IP addresses, AINS maps agent identifiers to metadata objects enabling local evaluation of agent interactions, and it complements companion specs (JIS, TIBET, UPIP, RVP).
Defines UPIP (Universal Process Integrity Protocol), a five-layer protocol for capturing, verifying, and reproducing computational processes across machines, actors, and trust domains. It builds a cryptographic hash chain over five layers - STATE (input), DEPS (dependencies), PROCESS (execution), RESULT (output), and VERIFY (cross-machine proof) - so any modification is detectable. It also defines continuation artifacts: Task Capsules carry bounded process blueprints and evidence; Work Corridors name bounded continuation windows; and Fork Tokens freeze the stack and transfer it to other actors with a cryptographic chain of custody. It is transport-agnostic with JSON as the baseline serialization and integrates with TIBET, JIS, AINS, and RVP.
Defines a YANG data model for the management of Computing-Aware Traffic Steering (CATS) systems.
Argues that delegation-chain specifications describe the shape of conveyed authority but leave the verifier's half of the exchange underdetermined, so two verifiers can both report success on the same chain yet enforce different policy. It establishes what verifiers must do - specifying evaluation inputs and four rules that prevent fail-open outcomes - derived from the Grant & Autonomy Lifecycle (GAL) and Provenance & Trust Context (PTC) specifications plus a public reference implementation.
Specifies the verification.* constraint family, a pre-action, fail-closed gate primitive for AI-agent decisions. A verification.* receipt is a JWS-signed artifact carrying canonical input, a derived binary act/halt output, and a versioned mapping identifier. It replaces the prior draft's raw verdict domain with four states - verified, contradicted, indeterminate, and not_evaluated - plus reason codes distinguishing substantive findings from verifier-instrument failures, and adds evidence pinning so receipts carry content-addressed sources and verdicts can be recomputed offline. It targets decision explainability and traceability aligned with EU AI Act Article 12 record-keeping and Zero-Trust-for-AI-Agents frameworks, and receipts remain verifiable under their mapping after newer mappings ship.
Extends the Zero Trust Fabric Layer (ZTFL), which handled single-agent authorization but not what happens when an agent delegates its authority to a second or third agent. It adds a chained authorization model using travel metaphors: a Passport establishes identity across the chain; a Ticket, issued once at task initiation, binds every hop as an ephemeral credential; per-hop Boarding Passes derive from and trace back to the Ticket; and a Visa gives explicit authorization when crossing tenant boundaries. The model provides chain-wide traceability to a single origin and containment at the boundary, formalized mathematically and validated against Cedar policy.