I-D Action: draft-noa-scitt-ai-agent-receipt-01.txt

[email protected]
Newsgroups gmane.ietf.announce
Message-ID <178675643883.117568.1404007446620024588@dt-datatracker-7c6ddbc678-86d5j>
Internet-Draft draft-noa-scitt-ai-agent-receipt-01.txt is now available.

   Title:   A SCITT Profile for AI-Agent Action Receipts
   Author:  Tora Toraman
   Name:    draft-noa-scitt-ai-agent-receipt-01.txt
   Pages:   97
   Dates:   2026-08-14

Abstract:

   This document profiles the IETF SCITT (Supply Chain Integrity,
   Transparency, and Trust) architecture for AI-agent action receipts:
   tamper-evident, signed, offline-verifiable records of what an
   autonomous agent was recorded as doing at the governed boundary,
   under which recorded principal class, with what recorded verdict, and
   -- where the issuer records one -- under which policy identity.  Each
   receipt is a signed record over a canonical JSON payload, hash-
   chained so that each record commits to its predecessor, and presented
   either bare -- the payload with its own native signature -- or
   enveloped in a COSE_Sign1.  This revision specifies how such a
   receipt is carried as a SCITT Signed Statement, with the protected
   claims a Transparency Service requires, so that a receipt can be
   registered.  Registration obtains a Transparency Service's signed
   proof that the statement was registered in its log -- a property a
   self-signed chain cannot provide alone.  It does not, by itself, give
   an offline holder non-equivocation: that requires consistency proofs
   and monitoring of the log, which this profile does not specify.  The
   profile makes a deliberately narrow, checkable claim: this is an
   issuer-authenticated, signature-verifiable, tamper-evident record of
   the action, the recorded principal class, the recorded verdict, and
   any policy identity the receipt carries.  It explicitly does not
   claim that the agent was correct, safe, or wise, that the recorded
   inputs were true or complete, that a named approver authorized this
   exact action before it ran, that a downstream controller succeeded,
   or that any physical effect occurred.  This revision separates those
   last three as distinct claims with independent failure behaviour,
   states the boundary of a shared action digest, and keeps a
   deterministic offline policy-replay capability out of scope.

The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-noa-scitt-ai-agent-receipt/

There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-noa-scitt-ai-agent-receipt-01.html

A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-noa-scitt-ai-agent-receipt-01

Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts


_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.