A new IETF non-working group email list has been created. List address: [email protected] Archive: https://mailarchive.ietf.org/arch/browse/audit/ To subscribe: https://mailman3.ietf.org/mailman3/lists/audit.ietf.org/
Purpose: Autonomous and semi-autonomous software agents are increasingly acting on behalf of users across multiple services and administrative domains. The increased use of complex agent communications introduces significant challenges for auditability and accountability. Existing mechanisms, such as system logs, tracing systems, and authorization frameworks, capture individual aspects of system behavior but lack interoperable support for correlating user intent, delegation chains, authorization state, and resulting actions across domains. This creates challenges for fundamental questions required for compliance, operational debugging, and user trust, such as who initiated an action, under which authority it occurred, and how permissions evolved during execution. The AUDIT effort aims to define interoperable protocol mechanisms and data models to enable auditing of complex, distributed, and time-evolving systems. This includes an architectural concept, common models for audit records, propagation of audit context across interactions, and integration with existing IETF protocols such as OAuth, HTTP, and attestation and transparency frameworks. This list belongs to IETF area: SEC For additional information, please contact the list administrators. _______________________________________________ IETF-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]
