Blake, Morgan, Mohamad, On amendment as a T0-grade event: I agree with the conclusion and want to state the operational consequence plainly, because it is the part an implementer will get wrong.
If an amendment is a principal-signed T0 event at the original evidence bar, then there is no amended mandate. There is a second mandate and the first is spent. That means a verifier never needs to reason about mandate mutation, and a resolver never needs an amendment code path. It only needs issuance, subset check, and spend. That is a smaller trusted surface, and it is the reason I would keep the T0 framing even though it prices amendment out of the asynchronous case. One consequence worth writing into the problem statement: because amendment requires a present principal, the response space an escalation may offer is bounded by reachability, not only by declarer independence. A statement that lists accept, refuse, and amend as peers will mislead implementers into building an amend path that is unreachable in exactly the deployments that motivated escalation in the first place. On single reliance, I support Morgan's split as stated: the mandate is standing authority, and reliance attaches to the evidence artifact. I want to reinforce why reliance must be an auditable event rather than something a counter prevents. With independent verifiers, each can honestly rely once. A counter held by any single party cannot distinguish honest concurrent reliance from replay, and a counter held by the runtime is held by the party the artifact exists to avoid trusting. An emitted, independently checkable reliance event is the only construction I have been able to make work across verifiers that do not coordinate. On the lifecycle requirement, I would go one step further than "a timestamp is not a mechanism." The requirement is establishing the as-of state without trusting the party that held it. In deployed PKI terms that means the status assertion has to be verifiable by a relying party that trusts neither the issuer's runtime nor its operator. We run this against hardware-bound signing on our own CA and it is the requirement most often quietly unmet. I am happy to contribute text for the amendment and reliance requirements if the authors want it. Best, Brian Vicente Sanctum SecOps LLC On Wednesday, August 26, 2026 at 12:13 PM UTC, [email protected] wrote: Morgan, Taking the T0-grade amendment. It keeps the separation clean for the reason you give. One consequence. If an amendment is a principal-signed T0 event at the original evidence bar, there is no amended mandate. There is a second mandate and the first is spent. That prices amend out of the asynchronous case, because a principal who can sign at T1 was reachable at T1, and an escalation with a reachable principal has a cheaper answer than amendment. So amend is not a peer of accept and refuse. It is available only where the principal is present, which means the response space an escalation may offer is bounded by reachability as well as by declarer independence. Worth saying in the document. Otherwise an implementer reads three outcomes as uniformly available and builds a flow that cannot produce one of them in the case the document exists for. Best, Blake On Wednesday, 26 August 2026 at 1:50 AM, morganLR wrote: > Mohamad, > > The scope defense in your reply upthread is the most important paragraph this thread has produced. The evidence-bar versus governance-bar distinction is exactly right, and both load-bearing properties deserve to survive every revision: the principal as signer rather than as a subject of issuance is what makes the artifact mean something to a party who trusts neither the runtime nor its operator, and dynamic linking under PSD2 SCA is the deployed proof that regulators already require parameter binding at authorization. The general problem inherits that bar; it should not weaken it. > > Four requirements I believe the statement still needs, plus one on the Morrison exchange: > > Bounds versus parameters. Because agent intent is generated at runtime, T0 constraints are bounds, not parameters. That yields two requirements the current text allows to blur: T1 parameters must be provably within the signed T0 bounds (a subset check any verifier can perform), and designated action classes must obtain fresh principal evidence at T1 itself, because for some consequences no bound is specific enough. Your escalating class is the second requirement; naming both keeps solutions honest about which they provide. > Survival across delegation. If the executing agent sub-delegates, the binding must narrow, not merely persist: evaluation at hop N must see constraints no wider than T0's, provably, or the gap reopens at the second hop. > Mandate lifecycle at T1. Your second property settles where the evidence is verified; what remains is the mandate's own state. The verifier needs to establish that the mandate had not been revoked or expired at the moment of execution, within a stated staleness bound, and that the signer's key was valid then, which implies signer-key lifecycle (rotation, compromise, repudiation) is part of the problem, not deployment detail. For the after-the-fact auditor this becomes: re-verification against the state as of the action instant, not as of the audit. > Single reliance. An evidence artifact bound to an exact payload can still be replayed against a second identical execution. The statement should require that evidence be relied upon once, and that the reliance itself be auditable. > > On the escalation exchange: the formulation you and Blake landed on reads right to me, and the declarer-independence principle (the response space not declared by the party whose error the amendment reports) is the load-bearing part. One addition would close the evidentiary side of it: every outcome that mutates the mandate, amendment above all, must itself be a T0-grade event, signed by the principal at the same evidence bar as the original mandate, so the auditor finds an unbroken chain of principal-signed states rather than a mandate whose middle was edited by the machinery around it. That also keeps Blake's separation clean: whether an amended value is inside the constraint set stays a constraint-set question, because the amendment that produced it is just another signed T0 state to check against. > > For comparison while drafting -01: R1, R4, R5, R7, and R10 of draft-reece-wimse-cross-org-delegation state formulations of the narrowing, binding, principal, lifecycle, and execution-time requirements above, and the AIMS adoption thread carries an open gap item on the mid-execution case where a problem statement at this level is the frame being asked for. > > Morgan _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
