[SCITT] Re: New I-D: Evidence Requirements for Agent Control Delivery and Outcome Reconciliation (draft-abak-agent-control-delivery-evidence-00)

Walter Hawkins <wdhawkins46@gmail.com> Sat, 05 September 2026 05:13 UTC

Return-Path: <wdhawkins46@gmail.com>
X-Original-To: scitt@mail2.ietf.org
Delivered-To: scitt@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id CF60A135DF68B for <scitt@mail2.ietf.org>; Fri, 4 Sep 2026 22:13:14 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788585194; bh=EzfV1PhrqWMu9U0a3JckrHGUonT/gBcsMSRRgP0CFiQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=NMtoTQxanbtDXYxH6jlKXcJ7I3oK0vooqi7vlDY22aoPcCigWjm+765tIc3w5t2Cv yJIMMOr+ZPzUXLds16vygh1Dt8oAs81dZ33aQNHxdxtM1I4mGLhVM5ynuehxtRTodR QbgmXUA7bbPZvhfOeBLi7plJubfrCBwl/Vj831ZY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.848
X-Spam-Level:
X-Spam-Status: No, score=-0.848 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QnzBdcbCqxPQ for <scitt@mail2.ietf.org>; Fri, 4 Sep 2026 22:13:14 -0700 (PDT)
Received: from mail-lj1-x22d.google.com (mail-lj1-x22d.google.com [IPv6:2a00:1450:4864:20::22d]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 04C4E135DF686 for <scitt@ietf.org>; Fri, 4 Sep 2026 22:13:14 -0700 (PDT)
Received: by mail-lj1-x22d.google.com with SMTP id 38308e7fff4ca-39c8ee87f7eso15484361fa.3 for <scitt@ietf.org>; Fri, 04 Sep 2026 22:13:13 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788585186; cv=none; d=google.com; s=arc-20260327; b=hy1Pk0xggNJHWhcpgvI2SYD3MYg0qbR3FUn4xgLhL4fXVGkB8yg34YsgcThFtJw8X8 GXEexw7mdem0StZbflBvpBkfyadZiEWIQgtQijX2ztGFlXRLTjJbjFwucZvYCpanF9qS JtRVpbHLDgIBFWuV+ti83R040OJGavH03vEoe30NpYHgxtjQadK01UX5cqPLFLJFWvfU /jX4DX8oiD29X1Ejx2aBj60dKnBnDuyvQcE5mYzQaJ5VJYzGx9Ur1nkxPNmCUs4+QJco KxcOBmOV/8Y0WJaDtC0VyulXqUP1i9fRJeHeFCCncal8vBj1/hfPGVrSqqwcUnJAFv9m bbwQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=4fKafPxkfWjuLDRzWDmyVI6gVd6M7PFxiK2vOIcqPMs=; fh=dwgQ+A7BvGeFCIbP31pfueaottrPj50W5GZ7+P6FdgU=; b=be7CrAfM38R8O/5BrqEW/P5wIkCAMNKJP8qqly4wQf7/7UczAVvos+QFFVvikdePaU GQSemJPtdL3sFQYqYsx4Xf/UEEyVsdc0TAdAkdIKDeO1GB2k9Ptt1IOMGzTNAbqJGw8M R6uoFd/abW6aMyE6tSHHpqujKUu9xuDGxJEbxhmI6PAlNcWY+ZRQla3+jKPZupX07MvD CSoS21lxhUtd2EijkuPQeYBxA7obJNwe+YB0a9sUWf4tA4FVhxRvocfdlhcqLUjEAxCD SxbFfzg20Pb9LXXo52BcgYV1Z3O8p8d9MTmEGzfA9k2u4gwqZBjSeeYvzGddAZedDUqk Bzfg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788585186; x=1789189986; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=4fKafPxkfWjuLDRzWDmyVI6gVd6M7PFxiK2vOIcqPMs=; b=dR3WtokA4HEmsuc2o3Q1ags0khM/Q8Etr+Xt/XKz2Ge+zx0dk70EFVggaR6XhbJOaG Z1xAMItjqbf88g0FidsGZyUoBUBrguixZ1IYHzz5aTyAdFaNFfwQWw6AlWqMNNUs56L6 jwLcZ9NsDivHSmor3UCrQHppNrjFT4fgv2cqZlwphABFFVmOHvCaxgqCVfNdrDGmlTOG vbsZ9geMtstqkWfhw9FRc/PGymF4KvxBHnC3IcfA7TLv32R07J4kHJsXrOy2K4mn7svd npM9MVwQiei/2JCFKRRetvupwAZbwfCif6w1RqFlFgu5V3HNIdn/BEtb5wQ7sslgwc2U gCRA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788585186; x=1789189986; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=4fKafPxkfWjuLDRzWDmyVI6gVd6M7PFxiK2vOIcqPMs=; b=V4Ahe2fgoVgIXg6emFdiydBYxk5SHiQQ7oWL113GllmuojsTNIOK0tbMeM/cze6IGu 3lKkokmg2uNampHv3c+zrjPF8DqbKRS0e57LtSnoYdAgxaBIJL0ShKP1a6BqtHEIIjeM t0O8N5sUv4r/KUrSn3F6c0IQ7pLNIUf+xD5bbBtlkDqh+9rxhmVmQFYdBP34l4m/SebP WePcHdg356LcJOD3UZYnht9B/pKr/WgksPmkHn4effwhTWJkseb20zMC2bro4Hufadee KPCqI6itsGb0MtwR7OmCArU30RrD5Ne6LJ7qJNX0ctRsKJ0lSe0lqmZzkSNLfE2cv6f2 QRnQ==
X-Forwarded-Encrypted: i=1; AKwUvBynqjDmBzvP4fNZFu49dYQCDb6IjoQVmaE4g84VmtuktoIYjg4VfLXhv5fLJYpvLF3HaF1FwA==@ietf.org
X-Gm-Message-State: AFuF++npTEXJ/ZznnH0y4nCeIZVPgsRZtuo3kw2JmAMooX8LnMFWEWfs b/lcG9Bcbt7t8LrvB0neN30/McT+qr1w659vXVfhrnV1qVjB62E5NgX4nqyKi+qpr8wy4Uj0yvc tD8enrfjreBCFXTV2hLOMfsbcRKSh2yuxrMrp
X-Gm-Gg: AYBFou1raJ10gUYvgH/TEPBJlAlf/hXv1O02pkk9V1KHK1h8scBAU5IUI7HAH43dQBb BngNmUUV3ilAzIoZgle9ozIu9M7GLO8OAl/ts+1hUh2vMdTDoOWs91RnZq+pXNMw8RbizvBfS+r cWg7p5xXDeb/CwXqB6NOBfAaZ7N+biEnaJevK5E3gRZRa+11ssgBaAFw7EQ2RC5yDkMjgJzh+jA 3hFThFqkFV9To2iLF/t7S6ZXSvWxLd0UxChEU52WSmIvexzxuJN0isOZb8q9aovB8l79uRZO5HG dqA2uD9srrqRmYNZTvDff2gh42paRUplrRbjjD3X3wuiMLZLdhnUng==
X-Received: by 2002:a2e:be29:0:b0:3a3:7680:67f7 with SMTP id 38308e7fff4ca-3a3768069ddmr7072981fa.22.1788585186169; Fri, 04 Sep 2026 22:13:06 -0700 (PDT)
MIME-Version: 1.0
References: <1a059195afd.4565299a1665355.5803749020539612109@phionyx.ai> <CAOfgHgozu3Zkfa_8xLL-_819UXa9+AHWyzmgJqECrJrdHAMqrg@mail.gmail.com> <1a059647c95.52b5c00d1669474.5350363334433611579@phionyx.ai> <CAOfgHgqo59hP2=ETw4_tZ+7V+_NofFA0CzDx+VPmkasNaQuPmA@mail.gmail.com> <1a05b083a92.194b8edc1680092.2192186531592395387@phionyx.ai> <CAOfgHgpoPMzgjph+8iiu1GCbCbCSQrU0CLXCSwPfNRdRoeeseg@mail.gmail.com> <1a068aa9c84.628acde8302609.9037848624334984897@phionyx.ai> <CAOfgHgp=SPxXRjgZpDWtBL1d-CoV4+UMyiEDJbMUjqkZd+PGHw@mail.gmail.com> <1a06920a8e5.48543f44307536.277778572727460648@phionyx.ai> <1a0693c482f.8787537f308350.3610854305484865878@phionyx.ai> <1788476568800716144.1788476568@conarium.dev> <1a06a611813.c6c0a25312932.5215504566405879891@phionyx.ai> <1788531190678629118.1788531190@conarium.dev>
In-Reply-To: <1788531190678629118.1788531190@conarium.dev>
From: Walter Hawkins <wdhawkins46@gmail.com>
Date: Sat, 05 Sep 2026 00:12:54 -0500
X-Gm-Features: AcwNN1WqQDtlBQ_8FrHet5ACw2_N-xs-aQYOV6-sOCt5hgyxA0HkjXEkWO2baJs
Message-ID: <CALc05oFS9S3NFZ6AMo67as1o4o43XCSJxARSNhwR1ohKC-Vz+Q@mail.gmail.com>
To: Emek Can Dogru <e.dogru@conarium.dev>
Content-Type: multipart/alternative; boundary="000000000000ac160d065ab57081"
Message-ID-Hash: 5BEQSKBIO5TJGGRABAAUFV63J54AD6OR
X-Message-ID-Hash: 5BEQSKBIO5TJGGRABAAUFV63J54AD6OR
X-MailFrom: wdhawkins46@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: founder@phionyx.ai, team@emiliaprotocol.ai, scitt@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [SCITT] Re: New I-D: Evidence Requirements for Agent Control Delivery and Outcome Reconciliation (draft-abak-agent-control-delivery-evidence-00)
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/CiAlVgCWAuLQJjyEWExLl-ZrysU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Emek,

Congratulations on publishing draft-dogru-cedulon-decision-profile-00.

Naming `effect-against-refusal` as a first-class reconciliation failure
mode is an important contribution. Existing payment and spend profiles
almost universally assume non-execution under denial; formalizing rogue
execution against an authoritative refusal fills a genuine gap in the audit
model.

Regarding your IANA registration question: your reasoning is sound and
consistent with SCITT/COSE architectural practice.

If the Effect Extract is delivered as an application-level detached JSON
payload rather than an encapsulated COSE structure whose MIME type is
parsed and validated inside an authenticated protected header parameter
(e.g., `content type` / label 3), registering a standalone media type adds
registry noise without cryptographic or protocol enforcement. Limiting the
formal media type registration strictly to the COSE_Sign1 Decision Record
keeps the IANA parameter footprint clean and avoids encouraging fragile
MIME-sniffing downstream.

We will run the conformance suite against commit da7bf9b and review the
interaction with receipt-invariant checks.

Best regards,
Walter

On Fri, Sep 4, 2026 at 9:14 AM Emek Can Dogru <e.dogru@conarium.dev> wrote:

> Ali, Iman, all,
>
> Following this thread, I wrote the decision side out as a profile on the
> Cedulon reconciler and posted it today:
>
>   draft-dogru-cedulon-decision-profile-00
>   https://datatracker.ietf.org/doc/draft-dogru-cedulon-decision-profile/
>
> The population is the one this thread has been circling. A Decision
> Record is a COSE_Sign1 signed by the party that decided whether an agent
> may act (allow, deny or defer, with the request hash, the policy hash
> and, for an allow, the reference and the content hash of the effect it
> allowed). An Effect Extract is an authenticated list of what actually
> occurred on a channel. An allow must be matched by exactly one effect
> carrying the content hash it named; a refusal must be matched by none.
> The finding the profile exists for has its own name,
> effect-against-refusal: an effect under a reference a refusal names.
> The spend vocabulary had no word for that case.
>
> What is measured and what is not, in the document's own terms: the
> profile runs on the same reconciler that runs spend, and the spend
> behaviour is held byte for byte by a fifteen-case golden file; eighteen
> conformance cases and four offline fixtures for a direct-message reply
> log; the live log's field names were not read, and no independent
> implementation has run it. Before posting, the draft was read by an
> outside model barred from editing, and the code behind it by two; what
> those readings found is in the companion's review log, the code defects
> each with the test that was red before the fix.
>
> Pinned commit: dogrucanemek-alt/cedulon@da7bf9b. `npm ci && npm run
> test:pre-release`; the cases are tests/decision-profile.test.ts, the
> fixtures interop/mizan-ig/. Same terms as before: run it, try to break
> it, say what you found.
>
> One registration question for anyone who has been through it. The
> profile registers one media type, for the Decision Record, and none for
> the Effect Extract, which is a JSON body with a detached signature; the
> reasoning is that the core registers names only for objects whose
> content type is checked inside a protected header. If that reasoning is
> wrong I would rather hear it before the six-type request is answered.
>
> Emek
>
> On Fri, Sep 4, 2026 at 6:05 AM Ali Toygar Abak <founder@phionyx.ai> wrote:
> > Hi Emek,
> >
> > Thank you. That closes the focused review on my side as well.
> >
> > I also have the pinned reproduction file and exact invocation now. I’ll
> run the 0.8.0 and 0.12.0 cases independently from clean directories and
> record the result separately, without changing or repinning the historical
> 1 September probe.
> >
> > I’ll keep the distinction explicit between your reported measurements
> and my independent reproduction until that run is complete.
> >
> >
> >
> > Best,
> >
> > Ali Toygar Abak
> >
> >
> >
> > Phionyx
> >
> > https://phionyx.ai
>
> --
> SCITT mailing list -- scitt@ietf.org
> To unsubscribe send an email to scitt-leave@ietf.org
>