Hi all,

I have submitted draft-yossif-agent-mandate-problem-00, a short
problem statement. No protocol, no mechanism.

The problem: a human authorizes intent at T0, an autonomous agent
executes a specific parameterized action at T1, and nothing
cryptographically binds the executed parameters to the constraints
the human actually signed. OAuth scopes are static and session-bound,
audit logs are self-asserted after the fact, and existing
mandate-style work is payments-scoped. The draft states the gap and
the requirements any general solution would need to meet.

https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/

Given the WG charter now covers authorization for automated agents,
I would welcome feedback on the problem definition itself: is it
stated at the right level, and is anything missing from the
requirements?

Mohamad Khalil Yossif

_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to