[OAUTH-WG] New I-D: Problem statement on verifiable human mandates for autonomous agent actions

Blake Morrison <blake@truealter.com> Thu, 13 August 2026 11:01 UTC

Return-Path: <blake@truealter.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 3891112915D2B for <oauth@mail2.ietf.org>; Thu, 13 Aug 2026 04:01:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786618869; bh=2ro/WRFsjK4l3CZH9y08a5MnXsckUqp4yQPbfxvl83k=; h=Date:To:From:Cc:Subject:In-Reply-To:References; b=gOAVDa6GKJXgLcQmaqGw/8MwAswbEWFx4subxBLMUcQPh1kxb+7ye7/GTzlXhLArD 7zrZcQ2FNqtm7fsJfduAWRuVTEw4J/OKp6EIZD1Oziq+xe5ap4zZFC6pE8JmU+RFeK xwClih483xnsEkj5WmmXLjwJNOA0BZCkqSlGy+lE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=truealter.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g2cp8MHbxIVI for <oauth@mail2.ietf.org>; Thu, 13 Aug 2026 04:01:08 -0700 (PDT)
Received: from mail-24422.protonmail.ch (mail-24422.protonmail.ch [109.224.244.22]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A0FE812915D26 for <oauth@ietf.org>; Thu, 13 Aug 2026 04:01:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=truealter.com; s=protonmail; t=1786618860; x=1786878060; bh=KQrCLQtrCLiPs2rQqbBssJkwHdGdol9W+TmMQ0Bomns=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=MlP37ZNEYa1EsWZzRoxNXeToNjNCAZXXOuGdWLtmlIU2N/gLa6tWr820Wt0Jq3qvn NQn/gaAB2kvuhgXve0pfHdGrbo5OTNtx5enNcunGlZ+0sJIlWWjThdiBFq83gQrFEK SrmD0RBIW2+0gEVx7FnfIvqL1fnDmqFzMltNvy0m9PaELF9sNZHQlC7IM+kkESiFo6 ASREU+z+dooDrny9Ed5BM6xExrt0eVUeXF8LBjD7UoPrYmH7qpDTrs9SdeCa3Fa/s2 KOvxjPKpQ6KbytgSnbFCNWE/7piYQBuEMpSWe+z3eZhSFjmqT3zsxDRwPwBvSC6pi/ pZSM3t/MnGvqQ==
Date: Thu, 13 Aug 2026 11:00:54 +0000
To: oauth@ietf.org
From: Blake Morrison <blake@truealter.com>
Message-ID: <kiD5GqNkywLXWyhXTw76cpJ3fS1zaynfR4-_RaUmdloFLNBrdp6Y6rSX505QoDdJVfv67h-BueZvk-0OIGI7m57OAkpqJxZR2oLsUBbBrnA=@truealter.com>
In-Reply-To: <9241DDB3-78D5-44F1-AF5B-992113226235@yuthent.com>
References: <9241DDB3-78D5-44F1-AF5B-992113226235@yuthent.com>
Feedback-ID: 187617253:user:proton
X-Pm-Message-ID: 86b715491bc759c07843abfab03ff3dacb33e228
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: 53C7CKOMSYT6JHVOM6RI7TCUFUSKZ3V3
X-Message-ID-Hash: 53C7CKOMSYT6JHVOM6RI7TCUFUSKZ3V3
X-MailFrom: blake@truealter.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Mohamad Khalil Yossif <mohamad@yuthent.com>, "drew@truealter.com" <drew@truealter.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] New I-D: Problem statement on verifiable human mandates for autonomous agent actions
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/sAwOPQeSFk_4uwK723q2psxrJLU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Hi Mohamad,

Property, not count. Your wording is better than mine and "wider than
two" should go.

On who declares it - the two you have drawn are not the only options.
If the escalating side declares the space, the requirement is met by
an agent that never offers amend, and the amend outcome exists to
report that agent's own error. So the party that declares the response
space cannot be the party whose error the amendment reports. That
rules out agent-declared without putting you in the position of
requiring anyone to accept an unanticipated response and it says what
must be true rather than how to build it.

Third one, separate, for your reason. Whether 500 instead of 5000 is
inside what was authorised is a question about the constraint set and
it is asked the same way whether the value arrived by amendment or in
the original request. Folding it into Section 6 makes the escalation
requirement carry a check that is not about escalation.

So your landing holds with one addition. Neither acceptance nor
refusal, declared rather than implied, and not declared by the party
being corrected.

Best,
Blake


On Thursday, 13 August 2026 at 5:57 PM, Mohamad Khalil Yossif <mohamad@yuthent.com> wrote:

> 
> 
> > Blake,
> > 
> > You're right about the axis. My tiers grade how hard the challenge is
> > before signing. You're asking what can come back after it. Those are
> > different questions and mine doesn't touch yours - CONFIRM and STEP_UP
> > both still end in accept or refuse, so I made the question harder
> > without making the answer wider.
> > 
> > The amend case is the one with nowhere to land, and I agree it's the
> > one worth keeping. "Right question, wrong amount" is the human telling
> > you the agent got something wrong. Collapsing that into a refusal
> > keeps the outcome and throws away the reason, and the reason is the
> > more useful half.
> > 
> > Before I write it into -01 I want to get the requirement right rather
> > than the mechanism, and three things are unclear to me. This is a
> > problem statement, so anything I put in Section 6 has to say what must
> > be true without saying how to build it.
> > 
> > First, "wider than two" counts options, and counting is already a
> > design choice. What I think you're actually pointing at is a property:
> > the return must be able to carry a response that is neither acceptance
> > nor refusal. That states the failure without prescribing a shape. Is
> > that the requirement you mean, or do you mean something stronger that
> > a count captures and a property doesn't?
> > 
> > Second, and this is the one I keep going back and forth on - who
> > declares the response space?
> > 
> > If the escalating side declares it, the space is closed and the agent
> > still controls it. An agent that never offers amend leaves the human
> > exactly where they were, and the requirement is satisfied on paper
> > while the gap survives.
> > 
> > If the human can return an amendment whether or not it was offered,
> > the space is open, but then the requirement lands on the party that
> > has to accept an unanticipated response, which is a much larger claim
> > for a problem statement to make.
> > 
> > I don't think Section 6 can be written without choosing, and I don't
> > want to choose by accident.
> > 
> > Third, an amendment carries a value the original didn't. Something has
> > to decide whether that value is within what was originally authorized
> > - 500 instead of 5000 is fine, 50000 instead of 5000 is not. Is that
> > inside the escalation requirement, or a separate one about the
> > constraint set the amendment is checked against? My instinct is
> > separate, because otherwise Section 6 quietly becomes a negotiation
> > protocol.
> > 
> > Where I've landed provisionally, and tell me if it's wrong: the
> > requirement is that the escalation return be able to carry a response
> > that is neither acceptance nor refusal, and that whatever the response
> > space is, it be declared rather than implied. What that space contains,
> > and who is bound by it, sits outside a problem statement.
> > 
> > Mohamad
> 
> 
>