Hi Blake,
Thank you so much for taking the time to review the draft. Your identification 
of the dangling requirements in UC8 and UC9, along with the formatting errors, 
was spot-on and extremely helpful. This is exactly the kind of detailed 
feedback that makes the document stronger.
We also want to take this opportunity to say that we warmly welcome this kind 
of review from everyone in the community. The more eyes we have on the draft, 
the better the final result will be, so please feel encouraged to share your 
thoughts at any time.
In your email, you mentioned that you could open these as issues. That would be 
incredibly helpful, and we would like to encourage this for any future feedback 
you or others might have.
For the specific points you've already raised, I am happy to open the issues on 
your behalf, crediting your feedback, so you don't have to do the work twice. 
Going forward, if you or anyone else spots an issue, creating a ticket on the 
repository would be the most effective way to help us address it.
You can find the issues page here: 
https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues/28
Thank you again for helping improve the quality of the document.
Best 
Meiling


[email protected]
 
From: Blake Morrison
Date: 2026-08-19 15:47
To: oauth
CC: chenmeiling; [email protected]
Subject: [OAUTH-WG] Re: draft-chen-oauth-agent-authz-use-cases-01
Hi Meiling,
 
Not a co-author but adding my two cents as a reader running the same check.
 
I went through the requirements against the gap analysis in each use case,
using the repo md since it is ahead of -02. UC1, UC2, UC5, UC7, UC10 and UC11
all check out, and Jia Chen has UC3 and UC4.
 
Two dangling.
 
UC8, requirement 2, fine-grained permission limited to a fixed set of domains
and to DS updating only. The three gaps cover multi-hop delegation syntax,
task and bulk revocation, and the audit-id claim. None of them reaches the
scoping requirement.
 
UC9, requirement 3, Delegated Authorization. Neither the hierarchical
delegation to sub-provider O&M teams nor the tenant case has an entry in What
Works or in What's Missing.
 
One other thing on UC8. Its requirements use plain bullets rather than the
bold-label shape the other use cases use, and the What's Missing heading and
all three of its gap bullets have unclosed bold markers, so they render as
asterisks. That is also why UC8 reads as empty to anything keying on the
labels, which is how I nearly missed it myself.
 
I will open these as issues if you would rather track them there.
 
Best,
Blake
 
 
On Thursday, 13 August 2026 at 7:57 PM, Meiling Chen 
<[email protected]> wrote:
 
> Hi usecase co-authors,
> 
> I'm writing to ask for your help with a crucial quality check as we prepare 
> for the `-03` submission of our agent authorization draft.
> 
> Recently, we received some excellent and precise feedback from Morgan on Use 
> Case 6 (UC6). He pointed out a significant inconsistency: a requirement had 
> been added to the "Requirements" list, but its corresponding analysis was 
> completely missing from the "Gap Analysis" section. This created a broken 
> link for the reader and weakened the argument for that use case.
> 
> While I have already fixed the specific issue in UC6, this incident 
> highlights a potential systemic risk in our document. As the draft has 
> evolved and we've added or refined requirements, we may have inadvertently 
> created similar inconsistencies in other use cases.
> 
> Call to Action:
> 
> To prevent this from happening again and to strengthen the overall quality of 
> our draft, I am asking each of you to please review all use cases (or at 
> least the ones you are most familiar with) with a specific focus on the 
> following:
> 
> Please verify that for every single requirement listed in a use case, there 
> is a corresponding and explicit entry or discussion in the What's Missing 
> (The Gap) or  What Works (Partially) section for that same use case.
> 
> The goal is to ensure there are no "dangling requirements" where we state a 
> need but fail to analyze why the existing landscape (the gap) makes it 
> necessary.
> 
> Please try to complete your review by this Friday. If you find any 
> discrepancies, please reply to this email thread or, even better, open an 
> issue on our GitHub repository so we can track it formally.
> 
> Thanks for your help in ensuring the consistency and integrity of our work. 
> This proactive check will make the document much stronger for the next round 
> of community review.
> 
> Best regards,
> 
> Meiling
> 
> [email protected]
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to