Morgan,

Taking the T0-grade amendment. It keeps the separation clean for the reason
you give.

One consequence. If an amendment is a principal-signed T0 event at the
original evidence bar, there is no amended mandate. There is a second mandate
and the first is spent. That prices amend out of the asynchronous case,
because a principal who can sign at T1 was reachable at T1, and an escalation
with a reachable principal has a cheaper answer than amendment.

So amend is not a peer of accept and refuse. It is available only where the
principal is present, which means the response space an escalation may offer
is bounded by reachability as well as by declarer independence.

Worth saying in the document. Otherwise an implementer reads three outcomes as
uniformly available and builds a flow that cannot produce one of them in the
case the document exists for.

Best,
Blake



On Wednesday, 26 August 2026 at 1:50 AM, morganLR 
<[email protected]> wrote:

> Mohamad,
> 
> The scope defense in your reply upthread is the most important paragraph this 
> thread has produced. The evidence-bar versus governance-bar distinction is 
> exactly right, and both load-bearing properties deserve to survive every 
> revision: the principal as signer rather than as a subject of issuance is 
> what makes the artifact mean something to a party who trusts neither the 
> runtime nor its operator, and dynamic linking under PSD2 SCA is the deployed 
> proof that regulators already require parameter binding at authorization. The 
> general problem inherits that bar; it should not weaken it.
> 
> Four requirements I believe the statement still needs, plus one on the 
> Morrison exchange:
> 
> Bounds versus parameters. Because agent intent is generated at runtime, T0 
> constraints are bounds, not parameters. That yields two requirements the 
> current text allows to blur: T1 parameters must be provably within the signed 
> T0 bounds (a subset check any verifier can perform), and designated action 
> classes must obtain fresh principal evidence at T1 itself, because for some 
> consequences no bound is specific enough. Your escalating class is the second 
> requirement; naming both keeps solutions honest about which they provide.
> Survival across delegation. If the executing agent sub-delegates, the binding 
> must narrow, not merely persist: evaluation at hop N must see constraints no 
> wider than T0's, provably, or the gap reopens at the second hop.
> Mandate lifecycle at T1. Your second property settles where the evidence is 
> verified; what remains is the mandate's own state. The verifier needs to 
> establish that the mandate had not been revoked or expired at the moment of 
> execution, within a stated staleness bound, and that the signer's key was 
> valid then, which implies signer-key lifecycle (rotation, compromise, 
> repudiation) is part of the problem, not deployment detail. For the 
> after-the-fact auditor this becomes: re-verification against the state as of 
> the action instant, not as of the audit.
> Single reliance. An evidence artifact bound to an exact payload can still be 
> replayed against a second identical execution. The statement should require 
> that evidence be relied upon once, and that the reliance itself be auditable.
> 
> On the escalation exchange: the formulation you and Blake landed on reads 
> right to me, and the declarer-independence principle (the response space not 
> declared by the party whose error the amendment reports) is the load-bearing 
> part. One addition would close the evidentiary side of it: every outcome that 
> mutates the mandate, amendment above all, must itself be a T0-grade event, 
> signed by the principal at the same evidence bar as the original mandate, so 
> the auditor finds an unbroken chain of principal-signed states rather than a 
> mandate whose middle was edited by the machinery around it. That also keeps 
> Blake's separation clean: whether an amended value is inside the constraint 
> set stays a constraint-set question, because the amendment that produced it 
> is just another signed T0 state to check against.
> 
> For comparison while drafting -01: R1, R4, R5, R7, and R10 of 
> draft-reece-wimse-cross-org-delegation state formulations of the narrowing, 
> binding, principal, lifecycle, and execution-time requirements above, and the 
> AIMS adoption thread carries an open gap item on the mid-execution case where 
> a problem statement at this level is the frame being asked for.
> 
> Morgan

_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to