A new IETF non-working group email list has been created.

List address: [email protected]
Archive: https://mailarchive.ietf.org/arch/browse/audit/
To subscribe: https://mailman3.ietf.org/mailman3/lists/audit.ietf.org/

Purpose: Autonomous and semi-autonomous software agents are increasingly acting 
on behalf of users across multiple services and administrative domains. The 
increased use of complex agent communications introduces significant challenges 
for auditability and accountability. Existing mechanisms, such as system logs, 
tracing systems, and authorization frameworks, capture individual aspects of 
system behavior but lack interoperable support for correlating user intent, 
delegation chains, authorization state, and resulting actions across domains. 
This creates challenges for fundamental questions required for compliance, 
operational debugging, and user trust, such as who initiated an action, under 
which authority it occurred, and how permissions evolved during execution.

The AUDIT effort aims to define interoperable protocol mechanisms and data 
models to enable auditing of complex, distributed, and time-evolving systems. 
This includes an architectural concept, common models for audit records, 
propagation of audit context across interactions, and integration with existing 
IETF protocols such as OAuth, HTTP, and attestation and transparency frameworks.

This list belongs to IETF area: SEC

For additional information, please contact the list administrators.

_______________________________________________
IETF-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to