Subject: UC3 and UC4 Dangling Requirements Review Results
Hi Meiling and all,
Following your call for a quality check on dangling requirements, I have
reviewed the latest version of the draft
(draft-chen-oauth-agent-authz-use-cases-02) with a focus on Use Case 3
and Use Case 4. Here are my findings.
For Use Case 3 (Agent as User's Full Proxy to Access Third-Party Tools),
the check passed. All six requirements listed in UC3 have corresponding
entries in the Gap Analysis section. No dangling requirements were found.
For Use Case 4 (Agent as User's Proxy to Access Operating System
Resources), I found issues. Two requirements lack explicit corresponding
analysis in the Gap Analysis.
The first is "Task-Scoped Permissions". The Gap Analysis does not
address why existing OS permission models cannot support task-bound
lifecycle management or automatic revocation upon completion.
The second is "Secure Privilege Escalation". The current Gap Analysis
only mentions "Over-Privileging by Default" as a consequence, but it
does not analyze why existing elevation mechanisms (such as sudo, UAC,
or macOS authorization dialogs) are unsuitable or insecure for
agent-initiated requests, nor why "just-in-time" and "user-approved"
elevation are difficult to achieve in this context.
I have prepared an issue on our GitHub repository to track this
discrepancy. You can find it at the link below.
https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues/27
In the issue, I have also included proposed text for the missing Gap
Analysis entries, which can be used directly for the -03 revision.
Let me know if you would like me to draft a pull request with the
proposed changes.
Best regards,
Jia Chen
[email protected]
在 2026/8/13 17:56, Meiling Chen 写道:
Hi usecase co-authors,
I'm writing to ask for your help with a crucial quality check as we
prepare for the |-03| submission of our agent authorization draft.
Recently, we received some excellent and precise feedback from Morgan
on Use Case 6 (UC6). He pointed out a significant inconsistency: a
requirement had been added to the "Requirements" list, but its
corresponding analysis was completely missing from the "Gap Analysis"
section. This created a broken link for the reader and weakened the
argument for that use case.
While I have already fixed the specific issue in UC6, this incident
highlights a potential systemic risk in our document. As the draft has
evolved and we've added or refined requirements, we may have
inadvertently created similar inconsistencies in other use cases.
Call to Action:
To prevent this from happening again and to strengthen the overall
quality of our draft, I am asking each of you to please review all use
cases (or at least the ones you are most familiar with) with a
specific focus on the following:
Please verify that for every single requirement listed in a use case,
there is a corresponding and explicit entry or discussion in the
What's Missing (The Gap) or What Works (Partially) section for that
same use case.
The goal is to ensure there are no "dangling requirements" where we
state a need but fail to analyze why the existing landscape (the gap)
makes it necessary.
Please try to complete your review by this Friday. If you find any
discrepancies, please reply to this email thread or, even better, open
an issue on our GitHub repository so we can track it formally.
Thanks for your help in ensuring the consistency and integrity of our
work. This proactive check will make the document much stronger for
the next round of community review.
Best regards,
Meiling
------------------------------------------------------------------------
[email protected]
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]