[SCITT] Escalation and hold-window semantics — a companion layer for draft-munoz-scitt-permit-profile

"David S. Rose" <primacy@davidsrose.com> Fri, 04 September 2026 04:26 UTC

Return-Path: <david@gust.com>
X-Original-To: scitt@mail2.ietf.org
Delivered-To: scitt@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 594981353BBC7 for <scitt@mail2.ietf.org>; Thu, 3 Sep 2026 21:26:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1788495995; bh=LzL+3gP1hPvu1izeSAW93V96Yn/VwwiFpzI0zIyth7w=; h=From:Subject:Date:Cc:To; b=F3fzMH3KHN8XzRhF8kAB3RRIU7sIrw+pdSz1KGhRdpmTvGWq39vFyrLIcB17r+Jwq wopIFy4SfF4Tw/EI+hzX7Xxu4rhw0AR5aNLzXAhXOlW7vogdar7yrdH9gYRvpNcGAy 86uPptlMZLBkSVkGB39GwbbGKgKiJCov65QDUiYY=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aaPTzi9DqexN for <scitt@mail2.ietf.org>; Thu, 3 Sep 2026 21:26:34 -0700 (PDT)
Received: from mail-qk1-f174.google.com (mail-qk1-f174.google.com [209.85.222.174]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 499241353BBC0 for <scitt@ietf.org>; Thu, 3 Sep 2026 21:26:34 -0700 (PDT)
Received: by mail-qk1-f174.google.com with SMTP id af79cd13be357-93959320373so49507785a.1 for <scitt@ietf.org>; Thu, 03 Sep 2026 21:26:34 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788495987; x=1789100787; h=to:cc:date:message-id:subject:mime-version:content-type:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=NBrWgpvyUYC/C5Bx9pr2E+ft7W9VihXgrTZaZixYGVI=; b=SILzxIk5rITBH3dhD+arCq8Bk/Dl79JWOWe4OlfnOV4vYUC0du/hV18p7+0Ie6xqxZ f10MoELBhE2bWGFWgqJ/vd0EYeJtHwgl/PxUxRv0nOzZsIhCpQUxXUzXM/SrXFWlWboE qi6iOagYf5+ls6VVBV479uOfVaiAQMOi1meNZeu5yoau6e4tfJXUvamNNjr/XSRzjMMJ CWHZhAmHVukMZuUWEc98udAMQ8AjKBtmzTuT+gkxNOX6v9gXynAv1wo3SxTrI195vEqB ETFQ+Z7hOCZToVYxfIEB/QjEQTtoUbyolzVOqL94rk62vBJcjkRdtKwluVY2IKnAuC/R hImQ==
X-Gm-Message-State: AFuF++n4kPZ/k2NTw41+knAI2Yzh/rG75KEZxsTb2WJYavaNG+f5TT/S /K3OcZLe9KgCrgD4CXez9eIh8+Gahmc8eoRiMNttlRn41EENixu712mlkBbZcaHKNncGjuPqXB7 8WFzFB10=
X-Gm-Gg: AYBFou1qSdxFz340DW4yRZNaWwToGHET2LdOyvYfcaWPo8I9QE2NRcr1M9YPQjiTXqj EKWPgurP6yjGsnKUSAeS1t0YvgQoRjEtR7DCWQjTZQAaF8Ydck7nTNi6r0hyT3H9dRz5zYiBDQ+ kHyn8fg0o2A4cL6QCK3K7qwDD2IwCRM7e1XRp9UNPZa7B3F4m5ahJYmi/Yn+VweCPb8hpdHgfuU YTpNSyS/3VqVC7riWuka5A/c42a5Cox1w2++zjn2C1wazC/1DpcMvS39WG7h7q/5oKSoQttFb08 7ZGzHfwH4bbkg28jUpivQh/Z3ncEITVeptJMAV+dZ/rsErZwxMcFcbDKvHN12ct2oXi0346Bx3S c6UbcOnEmB8d0kzP5eh8916X/5Kj4SLsWhZZoOpd6G4fjv+zkUNDw0lx6twrqbWCacoOXT0MLOU XUvDgbIWNIbMR3wefJjbhCFsv2aop9hyb9zdMy8CMbCuSQMvcRP06u0qYk1ja35xo9mrj1yrafW 8I64jzDwVyekKTMMMjXy3ralAKFOl1Z1+7tXxnL6AKNpxz1Y34fJpg8MBQBbdHHVTnRV763pB/N eN30qRIOYgQG+y4NKtNWWK2GPGUtDruD8mH/McLP4c3/heyrRkKkTP23rrQyCSVFah/twJJhQW+ vKol99BiSHgCIK+MgEljHlc3tzS0FrESbxk7a8yi7xrckW7K35mHdo2fk/Ak+B0s=
X-Received: by 2002:a05:620a:8804:b0:92e:e1d1:49dd with SMTP id af79cd13be357-9398034904amr389683085a.21.1788495987543; Thu, 03 Sep 2026 21:26:27 -0700 (PDT)
Received: from smtpclient.apple (pool-98-116-246-178.nycmny.fios.verizon.net. [98.116.246.178]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9397fb380f8sm125913185a.23.2026.09.03.21.26.26 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 03 Sep 2026 21:26:26 -0700 (PDT)
From: "David S. Rose" <primacy@davidsrose.com>
Content-Type: multipart/mixed; boundary="Apple-Mail=_152842C2-14D1-422D-8A44-D3B5BC3B20FC"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.700.51.1.1\))
Message-Id: <A4003FB6-3069-4038-9125-A86F61D5BFD8@davidsrose.com>
Date: Fri, 04 Sep 2026 00:26:16 -0400
To: scitt@ietf.org
X-Mailer: Apple Mail (2.3864.700.51.1.1)
Message-ID-Hash: KFLDU4U6YLPKJBY2DDKTTTLJM2D4LG7E
X-Message-ID-Hash: KFLDU4U6YLPKJBY2DDKTTTLJM2D4LG7E
X-MailFrom: david@gust.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: christian@keelapi.com
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [SCITT] Escalation and hold-window semantics — a companion layer for draft-munoz-scitt-permit-profile
List-Id: "Supply Chain Integrity, Transparency, and Trust" <scitt.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/scitt/JR_MeZOSR-boq1D-wigUYWkuBRQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/scitt>
List-Help: <mailto:scitt-request@ietf.org?subject=help>
List-Owner: <mailto:scitt-owner@ietf.org>
List-Post: <mailto:scitt@ietf.org>
List-Subscribe: <mailto:scitt-join@ietf.org>
List-Unsubscribe: <mailto:scitt-leave@ietf.org>

Hi all,

I'm David S. Rose. I build and operate a governed personal-AI-agent
deployment, and I've been following the agent-drafts discussion here
with interest.

The permit profile (draft-munoz-scitt-permit-profile-01) scopes itself
to the pre-execution decision record, and — as far as I can see —
escalation workflows, hold windows, and monitor constructs appear
nowhere in it: "challenge" is a decision value whose downstream
semantics the document leaves open. The CHAP discussion in August
was circling the same ground from the human-authority side.

I have been operating a construction for exactly that layer and would
like to contribute its semantics:

- Two escalation shapes with opposite timeout defaults: an approver
  gate that fails closed (expiry -> deny), and a veto window that
  releases on expiry only when an independent monitor's attested
  last-processed stream position shows it actually consumed the
  proposal before the window closed — silence as no-objection only
  when the objector was demonstrably reading — with degradation to
  gate semantics otherwise.

- An adjudication vocabulary that records an approval-over-objection
  as an override, rather than an ordinary approve.

- A deliberate distinction between "awaiting an approver" and "staged
  pending conditions" — different pauses with different safe defaults.

A short standalone specification of the release interlock ("Attested
Staged Release", v0.1 draft) is attached for discussion. Offered for
incorporation into the permit-profile family or as a companion
profile, whichever the group prefers.

-David