Subject: UC3 and UC4 Dangling Requirements Review Results

Hi Meiling and all,

Following your call for a quality check on dangling requirements, I have reviewed the latest version of the draft (draft-chen-oauth-agent-authz-use-cases-02) with a focus on Use Case 3 and Use Case 4. Here are my findings.

For Use Case 3 (Agent as User's Full Proxy to Access Third-Party Tools), the check passed. All six requirements listed in UC3 have corresponding entries in the Gap Analysis section. No dangling requirements were found.

For Use Case 4 (Agent as User's Proxy to Access Operating System Resources), I found issues. Two requirements lack explicit corresponding analysis in the Gap Analysis.

The first is "Task-Scoped Permissions". The Gap Analysis does not address why existing OS permission models cannot support task-bound lifecycle management or automatic revocation upon completion.

The second is "Secure Privilege Escalation". The current Gap Analysis only mentions "Over-Privileging by Default" as a consequence, but it does not analyze why existing elevation mechanisms (such as sudo, UAC, or macOS authorization dialogs) are unsuitable or insecure for agent-initiated requests, nor why "just-in-time" and "user-approved" elevation are difficult to achieve in this context.

I have prepared an issue on our GitHub repository to track this discrepancy. You can find it at the link below.

https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues/27

In the issue, I have also included proposed text for the missing Gap Analysis entries, which can be used directly for the -03 revision.

Let me know if you would like me to draft a pull request with the proposed changes.

Best regards,

Jia Chen

[email protected]


在 2026/8/13 17:56, Meiling Chen 写道:

Hi usecase co-authors,

I'm writing to ask for your help with a crucial quality check as we prepare for the |-03| submission of our agent authorization draft.

Recently, we received some excellent and precise feedback from Morgan on Use Case 6 (UC6). He pointed out a significant inconsistency: a requirement had been added to the "Requirements" list, but its corresponding analysis was completely missing from the "Gap Analysis" section. This created a broken link for the reader and weakened the argument for that use case.

While I have already fixed the specific issue in UC6, this incident highlights a potential systemic risk in our document. As the draft has evolved and we've added or refined requirements, we may have inadvertently created similar inconsistencies in other use cases.

Call to Action:

To prevent this from happening again and to strengthen the overall quality of our draft, I am asking each of you to please review all use cases (or at least the ones you are most familiar with) with a specific focus on the following:

Please verify that for every single requirement listed in a use case, there is a corresponding and explicit entry or discussion in the What's Missing (The Gap) or What Works (Partially) section for that same use case.

The goal is to ensure there are no "dangling requirements" where we state a need but fail to analyze why the existing landscape (the gap) makes it necessary.

Please try to complete your review by this Friday. If you find any discrepancies, please reply to this email thread or, even better, open an issue on our GitHub repository so we can track it formally.

Thanks for your help in ensuring the consistency and integrity of our work. This proactive check will make the document much stronger for the next round of community review.

Best regards,

Meiling
------------------------------------------------------------------------
[email protected]
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to