| I would highly recommend looking at Karl McGuinness’s mission bound authorization work as it addresses this problem space.
-- George Fletcher Practical Identity LLC Hi all,I have submitted draft-yossif-agent-mandate-problem-00, a shortproblem statement. No protocol, no mechanism.The problem: a human authorizes intent at T0, an autonomous agentexecutes a specific parameterized action at T1, and nothingcryptographically binds the executed parameters to the constraintsthe human actually signed. OAuth scopes are static and session-bound,audit logs are self-asserted after the fact, and existingmandate-style work is payments-scoped. The draft states the gap andthe requirements any general solution would need to meet.https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/Given the WG charter now covers authorization for automated agents,I would welcome feedback on the problem definition itself: is itstated at the right level, and is anything missing from therequirements?Mohamad Khalil Yossif_______________________________________________OAuth mailing list -- [email protected]To unsubscribe send an email to [email protected]
|
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]