Hi all, I have submitted draft-yossif-agent-mandate-problem-00, a short problem statement. No protocol, no mechanism.
The problem: a human authorizes intent at T0, an autonomous agent executes a specific parameterized action at T1, and nothing cryptographically binds the executed parameters to the constraints the human actually signed. OAuth scopes are static and session-bound, audit logs are self-asserted after the fact, and existing mandate-style work is payments-scoped. The draft states the gap and the requirements any general solution would need to meet. https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/ Given the WG charter now covers authorization for automated agents, I would welcome feedback on the problem definition itself: is it stated at the right level, and is anything missing from the requirements? Mohamad Khalil Yossif _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
