[Agentproto] Re: Suggested charter amendments (follow-up on my GitHub issue)

Leonard Gebauer <leonard.gebauer.ha@gmail.com> Tue, 01 September 2026 09:08 UTC

Return-Path: <leonard.gebauer.ha@gmail.com>
X-Original-To: agentproto@mail2.ietf.org
Delivered-To: agentproto@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A18C2132E90A8 for <agentproto@mail2.ietf.org>; Tue, 1 Sep 2026 02:08:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788253729; bh=GCK8L/ACu1m+xQ8Jzbbo9mY/J9esJ/xlVivOwi5YXds=; h=References:In-Reply-To:From:Date:Subject:To; b=TRkDIlJeTGK8pLv1iTGh8Rfmg2ucMsa5yLl501Os1Ij81hGhhbepbq9hjCK1fHvM8 HBYpK7KYtdlguDMfcamWERnhGMs31jx7u/u63gIq3gPaxM37slFngm3Hem/al9BS1D nAzziRVmNna9ssxZA36fR0p8uRw6qEpK+yA0/maY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xEoFZyAu4Ue1 for <agentproto@mail2.ietf.org>; Tue, 1 Sep 2026 02:08:48 -0700 (PDT)
Received: from mail-pg1-x531.google.com (mail-pg1-x531.google.com [IPv6:2607:f8b0:4864:20::531]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2EC91132E9079 for <agentproto@ietf.org>; Tue, 1 Sep 2026 02:08:48 -0700 (PDT)
Received: by mail-pg1-x531.google.com with SMTP id 41be03b00d2f7-cc1cc97b84bso4006622a12.1 for <agentproto@ietf.org>; Tue, 01 Sep 2026 02:08:48 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788253727; cv=none; d=google.com; s=arc-20260327; b=Cis5e1hUod4ZKxzPTcFqPqZ73wYJuu+AxJbGGuzsv71aSwOS0Oo1aMYlmmWgXXrH5Z 8K32YHDK177/P5r/zSmloxZLNlQ+Wk0jushnm4CLhseu2vlKp4ePwAqGBcme+3d60K3T Giv5eFF79ym3HUl1aqtRKY/lyPxjZASuHbgyKoUBW9aFeLAW/9NR4CjvPqMYT7dmCX2L HBlfSxdKB8Gecg4+Ao9eGqAckOfqrnYKR9jQmR+LALPWar3QUjYsJdHaAt3gSj6Gu+oD mgpQ9tsgSpTD1dmCL/YDCaCKcDor2tiW9DXWxai1wsGYe2RiM810JlGIfw4E2VdXI4wu zO2g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=5MDzIt6rozK1hbaBzM2Rg3sgALTTfYOTgiYCjkxd870=; fh=fau/IBtoccbGQ2vNVmo7YHgnsFVFzJwdw4C0dKHE/KU=; b=VGXcNpZpF4FwRVQ9dde9tRFIZuCDH+TI23BWMJgtjuO8Ge1IeLx/nbXjMeHGcn0tZG MNXZwc3p8dnZgzs8Z+hnJ0hMH7JADMBIUghQDpnxQu0eyz1CEQFfAs8x3XWBPiEf7Xiy 8UxLeP2ORTSN6uW0BJR9lm/TEVFcBpZx5frM/tLaOhwDy/qMe7WKGJGxQd5wzijHFmVk Mf03PjUxVpapIQGR5v1TPfPgq+WpddvXEm0zT0DMYnpIwOvQCB/6KSeufPpojFeM4ycy lDDMx+9VE57hVU/8YNYxxdwcGReO4MdA6Jym6QGtQgFeUdOEEzJPb3sA47qT2N3iHx1O etxw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788253727; x=1788858527; darn=ietf.org; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=5MDzIt6rozK1hbaBzM2Rg3sgALTTfYOTgiYCjkxd870=; b=MJTZEUhfRlZXCE95Xoa5aym7Keik5Z0XiOmjkoTx0251fOTbf7u2y9rsDlB0lk22so 4f649Dk5rkRJyRmDOU+rCYkP14Uqslaje9iA/8tjCSHOyBhakWZOlcbfi4F5qtdQ1mbh b360rpXP2H6dX9GCMkXFgMyBOpJ7Obxz+7XoRg/exNZUYdqKmWOCMUV7NldjldQVoFaP yQi1dvp4ulG14Pod0LP1BI3p+FDVmqcPdfVq5nRXuEo7d7817jYZp10sL/sv2+tLmUmO 3KHyiBx3OPPHOxZU3KOYMOrGcN05KrNcqaLVx9nyL8uAI4fAnCS7Wr2X8uJdbhI0P/hy LAiw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788253727; x=1788858527; h=content-type:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5MDzIt6rozK1hbaBzM2Rg3sgALTTfYOTgiYCjkxd870=; b=klEOIQ3YpkcPa7GmN/2VLI62ah4QxTVQkflkCtgsFv7bvSrQecTnFfDVmId5CAyBrz tu3Yfl0wzkTqmWDCRroQAH7R4fqEzse0DdldldUtAE94yYuu0X8NqMrHjRA4Y8SJr++r Ph24BMOEMrlLHFB4wpxQImm2CunG0ETsj6dKCbilBw4hzQhj0+aVE5r0op9wHBXI7cag SjlOlHq5mCKU2qs/BOdoFKbmhmHeAkPOTvAzvZEvOT5GUhgvinSuwsoPMR5n8DCVeBIl qb+JZz79PiQjoifwvBh0NRDMOVdEWKIOhqx5TYBcDUmJjqlERjw2rzYSQ62nCB/vIrBX bOyQ==
X-Forwarded-Encrypted: i=1; AKwUvBxdwXem5eVBvBCloW+9zyexaKtbEi31Jzn67X2fR+gqcpYiJgOHLh7ueo4iaZk8X2DPWK2TlpBH6rFd@ietf.org
X-Gm-Message-State: AFuF++mFp1dLJT7rrvQkBdVEpZihs7DuTwoSLN1zJ8SedK5/qiboeicB 13gVGDYvuLu3a3vD33ujGTDPgbU8xuxV/4vE6MDvzCDCht4FzQX1GGMFhKdAV7YgFo6R7x0sDBI y0azXThDOVrm4ME+q7WhsAudh2lOAAQ8NtlLl
X-Gm-Gg: AYBFou0/GwjxwKkA9hiaR79bMDHcs+DhhTAVsU4HFNLFUTR1NP+0tDLZV/YUOfPH+pD aqqLdlWMDRYmXeOLu605zjfpfDtX0pfZYefJ6+3jxLaRYExyAFeIZrupY8aHmns6KoVkPSOBuLu dENP9JA8KdL7vRpCfvkFS57PiOk0Yx+7zcQcEjx6CvBLs9GF9+itHc//S5Mp557qN6kKBHh+5z8 qkyClM6WD06lT802Uj+xEpOr02UfsxoZgph7Gx2FqJwxXpk2iTusarWi7cxOpXnhS6nqZZWDc+D dVVXo1YIyqzwtcni+C/WWIENcOiKvd2s3ohETBrR9qLZt8yc01rv+mWhvNmiIhljnUYwcFT4GCg =
X-Received: by 2002:a17:90b:224d:b0:36d:9e0b:3801 with SMTP id 98e67ed59e1d1-39907b17a40mr9061730a91.8.1788253726677; Tue, 01 Sep 2026 02:08:46 -0700 (PDT)
MIME-Version: 1.0
References: <CABTQ9f5CRx30pF8OAL-Q3S+1TK_BJqS94xr8P6JcYBMvJx2xrw@mail.gmail.com> <3EFA5552-EA12-42D1-8970-F178929F4DC9@thinkingcat.com> <CABTQ9f4eYOvFLS2=nbWgq4cR0+hArA=5TjkRBkcuHaxMTtQcfw@mail.gmail.com> <CABTQ9f7_1d81gAjGpdzrZ4sVYYiYDD_mRtvRugcaZjv8xVhDLw@mail.gmail.com>
In-Reply-To: <CABTQ9f7_1d81gAjGpdzrZ4sVYYiYDD_mRtvRugcaZjv8xVhDLw@mail.gmail.com>
From: Leonard Gebauer <leonard.gebauer.ha@gmail.com>
Date: Tue, 01 Sep 2026 10:08:35 +0100
X-Gm-Features: AcwNN1Vg76vkTN5VVqcqRKGAmQCw-HrlLYS3LQMGFGy6SwQQOek3JYsrIU5HpLo
Message-ID: <CABTQ9f4Qk0vB1MdGh50Njy=ugLb3rLQ3662m=WSFAR-VnPgeuA@mail.gmail.com>
To: "Leslie Daigle (ThinkingCat)" <ldaigle@thinkingcat.com>, agentproto@ietf.org
Content-Type: multipart/alternative; boundary="000000000000259ebc065a6844e1"
Message-ID-Hash: DJ4Y4HPWDA6YMT37CGYQNJPQ3MPXFX6B
X-Message-ID-Hash: DJ4Y4HPWDA6YMT37CGYQNJPQ3MPXFX6B
X-MailFrom: leonard.gebauer.ha@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Agentproto] Re: Suggested charter amendments (follow-up on my GitHub issue)
List-Id: Agent Communication Protocols <agentproto.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/agentproto/WNJpHiiwkykz1UnwOFdevgGeDLk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/agentproto>
List-Help: <mailto:agentproto-request@ietf.org?subject=help>
List-Owner: <mailto:agentproto-owner@ietf.org>
List-Post: <mailto:agentproto@ietf.org>
List-Subscribe: <mailto:agentproto-join@ietf.org>
List-Unsubscribe: <mailto:agentproto-leave@ietf.org>

Hi Leslie,

I just want to do a quick follow up because maybe you missed or didn't
receive my rationale (or i didn't receive your answer).

Here is the email again (hope the link works):
https://mailarchive.ietf.org/arch/msg/agentproto/RaO3d-ysmPouixg84twjp8qiNXw/#

If you didn't answer because my email didn't meet the new requirements or
was unclear/not useful for you or I just missed your answer, please let me
know.

Thank you!

Best,
Leonard Gebauer

On Thu, Aug 27, 2026 at 12:12 PM Leonard Gebauer <
leonard.gebauer.ha@gmail.com> wrote:

> And i just noticed that i didn't use STE, i'm sorry for that. I'll
> definitely use it in future.
>
> Leonard Gebauer <leonard.gebauer.ha@gmail.com> schrieb am Do., 27. Aug.
> 2026, 13:06:
>
>> Hi Leslie,
>>
>> thank you for the feedback and for clarifying the expectations around
>> rationale.
>>
>> I understand that the current charter text reflects prior discussion and
>> rough consensus on inclusion and exclusion. My proposals are intended as
>> targeted refinements that I believe strengthen the document in the
>> direction the chairs have recently emphasized, concrete interoperability
>> problems and the minimum necessary primitives, rather than expanding the
>> scope.
>>
>> Here is the rationale for each proposal, tied to the current text:
>>
>> 1.) Human-agent communication
>>
>> The charter currently places “protocol-level mechanisms for establishing
>> sessions, negotiating modalities, and exchanging multimodal data between a
>> human user and an AI Agent” in scope, while the Out-of-Scope section
>> already excludes “the design of human to agent user interfaces, client
>> application UX, or the rendering of agent outputs on end-user devices.” The
>> proposed replacement closes the remaining gap: it keeps shared session and
>> transport mechanisms (usable by both agent-to-agent and human-agent
>> interactions) in scope, but explicitly places human-specific interaction
>> patterns such as barge-in handling or modality negotiation for end-user UIs
>> out of scope. This reduces the risk of the group being drawn into
>> application-layer UI concerns while preserving the foundational session
>> work.
>>
>> 2.) Discovery and capability advertisement
>>
>> I remain less certain about this item. Discovery is already acknowledged
>> under Coordination (INT and OPS areas) and in the Key Considerations around
>> selecting agents and tools. Adding an explicit requirements-and-integration
>> bullet to the Framework deliverable would make that coordination more
>> visible and help ensure the session protocol remains usable across trust
>> domains. However, I recognize this could be seen as moving beyond the
>> current minimal-primitives focus. I am happy to drop or defer it based on
>> the group’s and your view.
>>
>> 3.) Definition of “AI agent”
>>
>> The current definition (“an autonomous, adaptive intelligent software
>> system that uses AI models to complete a specific task”) is narrower than
>> the description that immediately follows it in the charter. The proposed
>> wording aligns the definition more closely with the systems that actually
>> require inter-domain interoperability, entities that pursue goals, make
>> decisions, and interact with other agents or tools, without materially
>> expanding the scope of the work.
>>
>> 4.) Success criteria
>>
>> The current charter does not contain explicit success or readiness
>> criteria. Adding clear, pragmatic criteria (stable architectural building
>> blocks for the Framework document; adoption of the Session Protocol by at
>> least two independent agent frameworks) provides the group with measurable
>> exit ramps and reinforces the focus on usable, interoperable results.
>>
>> 5.) Behavioral security boundary
>>
>> The existing Out-of-Scope text already places pure model-level behavioral
>> security out of scope while keeping protocol-level user confirmation in
>> scope. The proposed wording makes that boundary more precise by also
>> excluding mechanisms whose primary purpose is to mitigate model-level
>> failures (e.g., prompt injection) beyond confirmation and authorization
>> hooks. This further protects the group from scope creep into
>> model-alignment territory while preserving the confirmation mechanisms that
>> are already agreed to be in scope.
>>
>> In short, proposals 1, 3, 4 and 5 are intended to clarify and tighten the
>> existing consensus direction. Proposal 2 is the one I am least attached to
>> and where I would particularly value your and the group’s feedback.
>>
>> I am happy to withdraw any item that does not help us reach a clearer
>> consensus-ready charter, or discuss the points individually.
>>
>> Best regards,
>> Leonard
>>
>> [NOTE: The text was translated from German to English by an AI, which
>> also reworked it to be more readable. Edited by the Author.]
>>
>> Leslie Daigle (ThinkingCat) <ldaigle@thinkingcat.com> schrieb am Mi.,
>> 26. Aug. 2026, 00:21:
>>
>>> Hi,
>>>
>>> Thanks for the suggestions. As we are working on developing a text that
>>> has consensus support, and with the understanding that all the text that is
>>> in the current version of the charter is the result of several minds
>>> agreeing on both what to put in and what to leave out: could you identify
>>> why you propose those updates as an improvement in our effort to make a
>>> consensus-based charter for an IETF working group?
>>>
>>> This mailing list is for the discussion of creating a charter for an
>>> AGENTPROTO IETF working group, and carrying out  the work the group is then
>>> chartered to do.   General discussion of (AI) agents is not in scope.
>>> Discussion of specific implementations is not relevant, except where it
>>> supports a written statement proposing an update to existing charter text.
>>> The AGENTPROTO charter proposal is available here (
>>> https://github.com/ietf-artarea/charters/blob/main/agentproto/charter.md)
>>> If you have issues with any of the text, or suggestions for additional or
>>> different content in the charter, please provide your rationale.
>>>
>>> Thanks,
>>> Leslie.
>>>
>>> On 24 Aug 2026, at 17:17, Leonard Gebauer wrote:
>>>
>>> Hi all,
>>>
>>> I have opened an issue on the charter repository with five proposed
>>> changes
>>> to the current draft. I’d like to briefly present them here for
>>> discussion,
>>> because i think the discussion about proposals will take place here.
>>>
>>> I understand that the chairs have recently refocused the discussion on
>>> concrete interoperability problems and the minimum necessary primitives.
>>> Still, i want to introduce my proposal, as I believe proposals 1, 3, and
>>> 5
>>> help clarify and sharpen the scope along those lines. Proposal 4 adds
>>> success criteria that align well with this pragmatic focus.
>>>
>>> However, I'm less certain about proposal 2 (discovery and capability
>>> advertisement). I realize this might be a more contentious topic and
>>> potentially out of step with the current priority on minimal primitives.
>>> I
>>> would appreciate the group's feedback on whether this belongs in the
>>> charter at this stage.
>>>
>>> Here is the exact copy of the issue, as posted by me on Github:
>>>
>>> --- BEGIN ISSUE TEXT ---
>>>
>>> Hi all! Here are some ideas i have for the charter:
>>>
>>> 1.)
>>>
>>> Replace: „Human-agent communication protocols — specifically the
>>> protocol-level mechanisms for establishing sessions, negotiating
>>> modalities, and exchanging multimodal data between a human user and an AI
>>> Agent — are also in scope.“
>>>
>>> With: „Human-agent communication mechanisms that are specific to human
>>> interaction patterns (e.g., barge-in handling or modality negotiation for
>>> end-user UIs) are out of scope. Shared session and transport mechanisms
>>> that can be used by both agent-to-agent and human-agent interactions
>>> remain
>>> in scope.“
>>>
>>> 2.)
>>>
>>> New bullet point in Framework-Deliverable:
>>>
>>> „• Identify requirements and integration approaches for agent and tool
>>> discovery, including capability advertisement and trust-domain discovery,
>>> and coordinate with relevant existing mechanisms.“
>>>
>>> 3.)
>>>
>>> Replace: „An AI agent is an autonomous, adaptive intelligent software
>>> system that uses AI models to complete a specific task.“
>>>
>>> With: „An AI agent is an autonomous software entity that uses one or more
>>> AI models to complete tasks, pursue goals, make decisions, and interact
>>> with other agents or tools.“
>>>
>>> 4,)
>>>
>>> Add as Success Criteria: „The working group will consider the Framework
>>> document ready for Working Group Last Call once the core architectural
>>> building blocks and their relationships are stable. The Session Protocol
>>> work is considered successful when it provides a usable, interoperable
>>> session layer that can be adopted by at least two independent agent
>>> frameworks.“
>>>
>>> 5.)
>>>
>>> Replace: „• AI agent behavioral security (e.g., preventing the AI model
>>> itself from hallucinating, though mitigating the impact of hallucinations
>>> via protocol-level user confirmation is in scope).“
>>>
>>> With: „• AI agent behavioral security (e.g., preventing the AI model
>>> itself
>>> from hallucinating). Protocol mechanisms whose primary purpose is to
>>> mitigate model-level failures (e.g., prompt injection) beyond providing
>>> confirmation and authorization hooks are also out of scope. Mitigating
>>> the
>>> impact of hallucinations via protocol-level user confirmation remains in
>>> scope.“
>>>
>>> [NOTE: Original Text was in German, it was translated via AI which ALSO
>>> helped to make it more readable. From my perspective it seemed fine,
>>> however i am sorry if there is something incorrect in my proposal due to
>>> this procedure.]
>>>
>>> --- END ISSUE TEXT ---
>>>
>>> Looking forward to your thoughts!
>>>
>>> Best regards,
>>> Leonard Gebauer
>>>
>>> [NOTE: This email was translated from german into english and edited to
>>> be
>>> more readable by an AI.]
>>> ------------------------------
>>>
>>> Agentproto mailing list -- agentproto@ietf.org
>>> To unsubscribe send an email to agentproto-leave@ietf.org
>>>
>>> --
>>> ------------------------------
>>> Leslie Daigle
>>> Principal, ThinkingCat Enterprises
>>> ldaigle@thinkingcat.com
>>>
>>