Blake, Morgan, Mohamad,

On amendment as a T0-grade event: I agree with the conclusion and want to state 
the operational consequence plainly, because it is the part an implementer will 
get wrong.

If an amendment is a principal-signed T0 event at the original evidence bar, 
then there is no amended mandate. There is a second mandate and the first is 
spent. That means a verifier never needs to reason about mandate mutation, and 
a resolver never needs an amendment code path. It only needs issuance, subset 
check, and spend. That is a smaller trusted surface, and it is the reason I 
would keep the T0 framing even though it prices amendment out of the 
asynchronous case.

One consequence worth writing into the problem statement: because amendment 
requires a present principal, the response space an escalation may offer is 
bounded by reachability, not only by declarer independence. A statement that 
lists accept, refuse, and amend as peers will mislead implementers into 
building an amend path that is unreachable in exactly the deployments that 
motivated escalation in the first place.

On single reliance, I support Morgan's split as stated: the mandate is standing 
authority, and reliance attaches to the evidence artifact. I want to reinforce 
why reliance must be an auditable event rather than something a counter 
prevents. With independent verifiers, each can honestly rely once. A counter 
held by any single party cannot distinguish honest concurrent reliance from 
replay, and a counter held by the runtime is held by the party the artifact 
exists to avoid trusting. An emitted, independently checkable reliance event is 
the only construction I have been able to make work across verifiers that do 
not coordinate.

On the lifecycle requirement, I would go one step further than "a timestamp is 
not a mechanism." The requirement is establishing the as-of state without 
trusting the party that held it. In deployed PKI terms that means the status 
assertion has to be verifiable by a relying party that trusts neither the 
issuer's runtime nor its operator. We run this against hardware-bound signing 
on our own CA and it is the requirement most often quietly unmet.

I am happy to contribute text for the amendment and reliance requirements if 
the authors want it.

Best,
Brian Vicente
Sanctum SecOps LLC


On Wednesday, August 26, 2026 at 12:13 PM UTC, 
[email protected] wrote:

Morgan, Taking the T0-grade amendment. It keeps the separation clean for the 
reason you give. One consequence. If an amendment is a principal-signed T0 
event at the original evidence bar, there is no amended mandate. There is a 
second mandate and the first is spent. That prices amend out of the 
asynchronous case, because a principal who can sign at T1 was reachable at T1, 
and an escalation with a reachable principal has a cheaper answer than 
amendment. So amend is not a peer of accept and refuse. It is available only 
where the principal is present, which means the response space an escalation 
may offer is bounded by reachability as well as by declarer independence. Worth 
saying in the document. Otherwise an implementer reads three outcomes as 
uniformly available and builds a flow that cannot produce one of them in the 
case the document exists for. Best, Blake On Wednesday, 26 August 2026 at 1:50 
AM, morganLR wrote: > Mohamad, > > The scope defense in your reply upthread is 
the most important paragraph this thread has produced. The evidence-bar versus 
governance-bar distinction is exactly right, and both load-bearing properties 
deserve to survive every revision: the principal as signer rather than as a 
subject of issuance is what makes the artifact mean something to a party who 
trusts neither the runtime nor its operator, and dynamic linking under PSD2 SCA 
is the deployed proof that regulators already require parameter binding at 
authorization. The general problem inherits that bar; it should not weaken it. 
> > Four requirements I believe the statement still needs, plus one on the 
Morrison exchange: > > Bounds versus parameters. Because agent intent is 
generated at runtime, T0 constraints are bounds, not parameters. That yields 
two requirements the current text allows to blur: T1 parameters must be 
provably within the signed T0 bounds (a subset check any verifier can perform), 
and designated action classes must obtain fresh principal evidence at T1 
itself, because for some consequences no bound is specific enough. Your 
escalating class is the second requirement; naming both keeps solutions honest 
about which they provide. > Survival across delegation. If the executing agent 
sub-delegates, the binding must narrow, not merely persist: evaluation at hop N 
must see constraints no wider than T0's, provably, or the gap reopens at the 
second hop. > Mandate lifecycle at T1. Your second property settles where the 
evidence is verified; what remains is the mandate's own state. The verifier 
needs to establish that the mandate had not been revoked or expired at the 
moment of execution, within a stated staleness bound, and that the signer's key 
was valid then, which implies signer-key lifecycle (rotation, compromise, 
repudiation) is part of the problem, not deployment detail. For the 
after-the-fact auditor this becomes: re-verification against the state as of 
the action instant, not as of the audit. > Single reliance. An evidence 
artifact bound to an exact payload can still be replayed against a second 
identical execution. The statement should require that evidence be relied upon 
once, and that the reliance itself be auditable. > > On the escalation 
exchange: the formulation you and Blake landed on reads right to me, and the 
declarer-independence principle (the response space not declared by the party 
whose error the amendment reports) is the load-bearing part. One addition would 
close the evidentiary side of it: every outcome that mutates the mandate, 
amendment above all, must itself be a T0-grade event, signed by the principal 
at the same evidence bar as the original mandate, so the auditor finds an 
unbroken chain of principal-signed states rather than a mandate whose middle 
was edited by the machinery around it. That also keeps Blake's separation 
clean: whether an amended value is inside the constraint set stays a 
constraint-set question, because the amendment that produced it is just another 
signed T0 state to check against. > > For comparison while drafting -01: R1, 
R4, R5, R7, and R10 of draft-reece-wimse-cross-org-delegation state 
formulations of the narrowing, binding, principal, lifecycle, and 
execution-time requirements above, and the AIMS adoption thread carries an open 
gap item on the mid-execution case where a problem statement at this level is 
the frame being asked for. > > Morgan 
_______________________________________________ OAuth mailing list -- 
[email protected] To unsubscribe send an email to [email protected]
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to