Internet-Draft draft-sato-soos-gar-05.txt is now available.
Title: The Governance Audit Record (GAR) for Agentic AI Systems
Author: Tom Sato
Name: draft-sato-soos-gar-05.txt
Pages: 52
Dates: 2026-08-17
Abstract:
This document specifies the Governance Audit Record (GAR), the audit
architecture for agentic AI systems. GAR defines five audit types,
the Session Audit Record (SAR), the Audit Alert system, auditor
principal categories, and the Audit Package for external regulatory
inspection. GAR provides verifiable evidence that AI agent sessions
were governed in accordance with the Intent Declaration Primitive
[I-D.sato-soos-idp] and the Human Escalation Mechanism
[I-D.sato-soos-hem]. GAR answers the governance question: can any
of this be proven to a regulator? GAR is a domain-specific
application of the SCITT (Supply Chain Integrity, Transparency and
Trust) architecture [I-D.ietf-scitt-architecture] extended with
causal ordering semantics for agentic governance events. GAR defines
the Authority Lifecycle Event (ALE) category: a normative set of
causally-ordered event types covering the complete agent session
revocation and recovery lifecycle, including single-agent revocation,
authority suspension, partial state recording, recovery initiation,
credential restoration, and multi-agent delegation tree events.
Version -03 adds the SOOS Governance Semantic Convention: the
normative soos.governance.* OpenTelemetry attribute namespace for
governance observability (Section 13), the SOOS GAR Processor
specification for OTel-to-SAR pipeline construction with Session
Block Merkle integrity (Section 14), four new Authority Lifecycle
Events, three mandatory provenance fields on Cedar evaluation
records, and the XPID mirror field on ACD session ALEs.
Version -04 made the Session Block construction rules of Section
14.3 more explicit, closing three ambiguities found during
independent interop verification at the IETF 126 Hackathon.
Version -05 supersedes -04's Section 14.3 text with a corrected
construction: the Merkle leaf and internal-node hashes are now
domain-separated (RFC 6962 S2.1's MTH, with 0x00/0x01 prefix
octets) and odd-length levels use RFC 6962's k-split recursive
tree shape rather than duplicate-node padding, closing a
malleability class structurally equivalent to CVE-2012-2459 that
was present in -04's construction (Section 15 S.15.e). This
revision is fully self-contained: unlike -03 and -04, it does not
carry forward unreproduced text from an earlier version. Version
-05 also adds a subject_digest field to Cedar-evaluation GAR
records (Section 8.6), the same construction used by the Agent
Accountability Composition [I-D.mih-sato-agent-accountability-
composition] as its cross-slot join key, positioning GAR as a
conforming AEP instance under the RATS-bound composition of
[I-D.sokolov-rats-aep-composition]; the field is normatively
scoped to prohibit independent re-serialization where an
upstream party has already established the action's canonical
serialization, per the failure mode documented in
[I-D.hillier-scitt-arp] Appendix D.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-sato-soos-gar/
There is also an HTMLized version available at:
https://datatracker.ietf.org/doc/html/draft-sato-soos-gar-05
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-sato-soos-gar-05
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
_______________________________________________
I-D-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.