# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-26T12:43:23Z", "synthesisSha256": "c866fcd3b26545b9a5def9b5cae7d51aafe8ca177a410e74075a957bd4b82ff5", "providerMode": "dual-provider", "providers": [ "Claude", "Grok" ], "waivedProviders": [] }, "metaModel": { "id": "WM-AI-002", "registryId": "vr.wm-ai-002", "name": "AI Agent", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.AI.AGT" ], "tags": [ "ai", "agent", "inf.ai.agt" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-ai-002-ai-agent/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-ai-002", "model": { "registry_id": "vr.wm-ai-002", "model_id": "WM-AI-002", "name": "AI Agent", "entry_kind": "entity", "purpose": "Describe an AI agent as a governed, identifiable non-human actor that holds delegated authority, is bound to tools and memory, operates under policy and oversight, and can be inspected, released, constrained and retired by an accountable party.", "scope_statement": "The subject is the durable, versioned agent definition plus the deployment context that makes it operable: identity and classification, capability and protocol surface, delegated authority and credentials, memory and data handling, lifecycle and runtime limits, oversight, and assurance evidence. The model is projection-neutral: JSON, YAML, Markdown, Git, MCP endpoints, graph stores and MongoDB collections are storage or interface projections of the same semantics. External standards are recorded as alignments only; no conformance is asserted without cited evidence.", "in_scope": [ "Agent identity, designation, aliases and version identity of a released agent definition", "Architectural archetype, autonomy level, regulatory role and risk classification", "Constituent bindings: invoked models, referenced configuration artefacts, callable sub-agents", "Declared capability surface: bound tools, accessible resources, declared skills, refusal scope", "Protocol bindings, capability advertisement, revision negotiation, descriptor authenticity", "Delegated authority: acting principal, delegation chain, credential scope, token audience binding", "Action authorisation policy, deny boundaries, consent and human-approval gates", "Memory store inventory, write authority, memory provenance and integrity controls", "Data categories, purpose limitation, residency constraints, retention and deletion duties", "Lifecycle states, release approval, rollback, suspension and decommission obligations", "Runtime operating envelope: step, time, concurrency and cost limits and breach behaviour", "Human oversight affordances, intervention records, incident handling", "Pre-deployment evaluation, in-service monitoring, telemetry conformance, conformity evidence" ], "out_of_scope": [ "Model training, weights, fine-tuning data and model cards, which belong to the AI system or model sibling", "Individual execution traces, spans, token counts and per-run outcomes, which belong to the agent run model", "Instruction text, templating and variable schemas of prompts or agent configuration files", "Natural-person records, employment and human competence records", "Internal implementation of the tools, APIs and services an agent calls", "Hosting, network and compute infrastructure topology", "Embodied actuation, motion planning and physical safety of robots", "Commercial contracting, billing and agent-to-agent payment settlement", "Any claim of certification or regulatory compliance not backed by cited evidence" ], "boundary_notes": [ { "neighbor": "WM-AI-001 AI system", "distinction": "The AI system is the product placed on the market and carries system-level obligations; the agent is one actor it exposes. Model inventory, system risk management and market placement stay in WM-AI-001; actor-level authority, tool bindings, memory and oversight stay here.", "source_refs": [ "SRC-008", "SRC-006" ] }, { "neighbor": "WM-AI-004 agent run", "distinction": "A run is a bounded execution event with traces and outcomes; the agent is the durable actor that runs reference. Correlation identifiers and version references live here; spans, messages and token usage live in WM-AI-004.", "source_refs": [ "SRC-011", "SRC-003" ] }, { "neighbor": "WM-AI-005 prompt or agent configuration", "distinction": "The configuration artefact carries instruction content and parameters; this model carries only the reference, the pinning mode and the approval status of that binding.", "source_refs": [ "SRC-001", "SRC-006" ] }, { "neighbor": "WM-PER-003 actor or person", "distinction": "Human principals, approvers and overseers are references to the person or party model. This model records the delegation relation and accountable role, not the human's own attributes.", "source_refs": [ "SRC-003", "SRC-008" ] }, { "neighbor": "Tool, server or external service model", "distinction": "A tool's own schema, endpoint contract and operator are a separate subject. This model records the binding, its effect class, trust status and approval, not the tool's internal definition.", "source_refs": [ "SRC-001", "SRC-013" ] }, { "neighbor": "Access-management and credential systems", "distinction": "Issuance mechanics, key material and authorisation-server internals stay in the identity domain; this model records which scopes and audiences an agent may hold and under whose delegation.", "source_refs": [ "SRC-002", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "Model Context Protocol Specification", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2026-07-28", "version_or_date": "Revision 2026-07-28 (current revision at time of access)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T09:12:00Z", "relevance": "Normative source for tool, resource and prompt primitives, per-request capability negotiation, extensions such as Tasks and Skills, and the user-consent and tool-safety principles including treating tool descriptions as untrusted." }, { "id": "SRC-002", "title": "Model Context Protocol - Authorization", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization", "version_or_date": "Revision 2025-06-18", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T09:14:00Z", "relevance": "Normative requirements for OAuth 2.1 flows, protected resource metadata discovery, resource indicators, token audience validation, prohibition of token pass-through and confused-deputy mitigation." }, { "id": "SRC-003", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:08:00Z", "relevance": "Defines Agent as a responsibility-bearing thing distinct from Activity and Entity, and supplies wasAttributedTo, wasAssociatedWith, actedOnBehalfOf, used, wasDerivedFrom, qualified associations and Plan for delegation and provenance modelling." }, { "id": "SRC-004", "title": "RFC 3339 - Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "July 2002, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:20:00Z", "relevance": "Normative timestamp grammar requiring full date, seconds and an explicit numeric offset or Z; basis for the model's time rules and the separation of event time from ingestion time." }, { "id": "SRC-005", "title": "RFC 9728 - OAuth 2.0 Protected Resource Metadata", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9728.html", "version_or_date": "April 2025, Standards Track", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:22:00Z", "relevance": "Defines resource identifier, authorization_servers, scopes_supported and WWW-Authenticate based discovery; supports capability advertisement, scope declaration and audience-bound access for agent-reachable resources." }, { "id": "SRC-006", "title": "AI Risk Management Framework (NIST AI 100-1)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://www.nist.gov/itl/ai-risk-management-framework", "version_or_date": "NIST AI 100-1, released 26 January 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:26:00Z", "relevance": "Voluntary framework organised around Govern, Map, Measure and Manage; grounds the governance, classification, measurement, monitoring and lifecycle-management structure of this model." }, { "id": "SRC-007", "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence", "version_or_date": "NIST AI 600-1, 26 July 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:30:00Z", "relevance": "Companion profile naming generative-AI risk categories including data privacy, information integrity, information security and human-AI configuration; used for data handling, evaluation and risk findings, with its non-agentic scope recorded as a conflict." }, { "id": "SRC-008", "title": "AI Act - Regulatory framework for artificial intelligence", "organization": "European Commission, Directorate-General for Communications Networks, Content and Technology", "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai", "version_or_date": "Regulation (EU) 2024/1689; in force 1 August 2024; general application 2 August 2026", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:18:00Z", "relevance": "Official summary of risk tiers, provider and deployer roles and high-risk obligations including activity logging for traceability, technical documentation, human oversight, robustness and transparency duties." }, { "id": "SRC-009", "title": "Article 14: Human Oversight - EU Artificial Intelligence Act", "organization": "EU Artificial Intelligence Act information portal (Future of Life Institute)", "url": "https://artificialintelligenceact.eu/article/14/", "version_or_date": "Regulation (EU) 2024/1689, Official Journal 13 June 2024", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-26T09:16:00Z", "relevance": "Reproduces Article 14 text used for the oversight findings: measures proportionate to risk and autonomy level, comprehension of capabilities and limitations, automation-bias awareness and a stop mechanism. Must be re-verified against the Official Journal text." }, { "id": "SRC-010", "title": "Agent2Agent (A2A) Protocol Specification", "organization": "A2A Project (Linux Foundation)", "url": "https://a2a-protocol.org/latest/specification/", "version_or_date": "Version 1.0.0 (latest released at time of access)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T09:10:00Z", "relevance": "Defines the Agent Card (name, description, url, provider, version, protocolVersion, capabilities, skills, securitySchemes, signatures), task lifecycle states and message, part and artifact structures used for capability advertisement and discovery." }, { "id": "SRC-011", "title": "OpenTelemetry Semantic Conventions for Generative AI - Agent spans", "organization": "OpenTelemetry (Cloud Native Computing Foundation)", "url": "https://github.com/open-telemetry/semantic-conventions-genai/blob/main/docs/gen-ai/gen-ai-agent-spans.md", "version_or_date": "main branch as accessed; attributes at Development stability", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T09:06:00Z", "relevance": "Defines gen_ai.operation.name values including create_agent, invoke_agent, plan and execute_tool, plus gen_ai.agent.id, gen_ai.agent.name, gen_ai.agent.description and gen_ai.conversation.id, and warns against recording transient in-memory agent instance identifiers." }, { "id": "SRC-012", "title": "NIST Special Publication 800-207: Zero Trust Architecture", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/207/final", "version_or_date": "SP 800-207, August 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T09:32:00Z", "relevance": "Establishes per-session authentication and authorisation as discrete functions, resource-centric protection and the absence of implicit trust from location or ownership; grounds the authorisation, delegation and monitoring findings." }, { "id": "SRC-013", "title": "OWASP Top 10 for Large Language Model Applications", "organization": "OWASP Foundation (OWASP GenAI Security Project)", "url": "https://owasp.org/www-project-top-10-for-large-language-model-applications/", "version_or_date": "Page states a 2026 edition dated 4 August 2026 while listing earlier-edition entry titles", "source_type": "classifier", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-08-26T09:34:00Z", "relevance": "Community risk taxonomy naming excessive agency, prompt injection, supply-chain and sensitive-information-disclosure risks; used to shape threat and limit findings, with its internal version inconsistency recorded as a conflict." }, { "id": "SRC-014", "title": "ISO/IEC 22989:2022 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/standard/74296.html", "version_or_date": "2022-07 (Edition 1)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T16:20:00Z", "relevance": "Normative definition of AI agent (3.1.1) as an automated entity that senses and responds to its environment and takes actions to achieve its goals; distinguishes agents from AI systems, components and human-defined objectives; supplies shared vocabulary for autonomy-related properties." }, { "id": "SRC-015", "title": "FIPA Agent Management Specification SC00023J", "organization": "Foundation for Intelligent Physical Agents (FIPA)", "url": "https://www.fipa.org/specs/fipa00023/SC00023J.html", "version_or_date": "2002-12-03 (Standard)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T17:10:00Z", "relevance": "Normative agent platform reference model: Agent Identifier (immutable name, addresses, resolvers), mandatory owner, AMS/DF/MTS, lifecycle states and transitions, registration/lease, directory search, and management functions register/deregister/modify/search/get-description." }, { "id": "SRC-016", "title": "FIPA ACL Message Structure Specification SC00061G", "organization": "Foundation for Intelligent Physical Agents (FIPA)", "url": "https://www.fipa.org/specs/fipa00061/SC00061G.html", "version_or_date": "2002-12-03 (Standard)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T16:55:00Z", "relevance": "Normative inter-agent message parameters: performative, sender, receiver, reply-to, content, language, encoding, ontology, protocol, conversation-id, reply-with, in-reply-to and reply-by; globally unique conversation identifiers." }, { "id": "SRC-017", "title": "Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated", "organization": "European Union (European Parliament and Council)", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng", "version_or_date": "2024/1689 as amended, consolidated 2026-07-27", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T17:45:00Z", "relevance": "Legal definition of an AI system as a machine-based system with varying levels of autonomy; provider and deployer roles; territorial scope for placing on the market and use; agent actors inherit operator duties from the system they instantiate rather than becoming legal persons." }, { "id": "SRC-018", "title": "NIST AI 800-2 Initial Public Draft: Practices for Automated Benchmark Evaluations of Language Models", "organization": "National Institute of Standards and Technology (NIST CAISI)", "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.800-2.ipd.pdf", "version_or_date": "January 2026 (ipd); DOI 10.6028/NIST.AI.800-2.ipd", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T16:40:00Z", "relevance": "Defines agent scaffolding as how a model is turned into an agent (for example ReAct or pre-built agent products), distinguishes inference, scaffolding and task settings, and requires explicit agent budgets and stopping conditions for agentic evaluation." }, { "id": "SRC-019", "title": "OWASP Top 10 for Agentic Applications for 2026 and Agentic AI Threats and Mitigations v1.1", "organization": "OWASP Foundation / Gen AI Security Project (Agentic Security Initiative)", "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/", "version_or_date": "Top 10 2026 (December 2025); Threats and Mitigations v1.1 December 2025", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-08-26T17:35:00Z", "relevance": "Peer-reviewed agentic threat taxonomy and Top 10 for autonomous applications that plan and act with tools: memory poisoning, goal manipulation, tool misuse, and the requirement to treat autonomy, authority, tool access and memory as first-class risk surfaces." } ], "structure": { "bundles": [ { "id": "agent-identity-and-constitution", "name": "Agent identity and constitution", "description": "What the agent is as a governed entity: authoritative identifier, designation, version identity, archetype and autonomy class, regulatory role, constituent bindings and definition provenance.", "rationale": "Provenance modelling treats an agent as a responsibility-bearing thing separate from the activities it performs; telemetry conventions require a stable non-transient agent identifier; agent-card publication requires a versioned public designation; and regulation attaches obligations to a classified system and to named provider and deployer roles.", "source_refs": [ "SRC-003", "SRC-010", "SRC-011", "SRC-008" ], "layers": [ { "id": "identity-and-designation", "name": "Identity and designation", "description": "How the agent is uniquely designated, how public and protocol-scoped names relate to the primary key, and how a released version is identified over time.", "source_refs": [ "SRC-011", "SRC-010", "SRC-003", "SRC-004" ], "findings": [ { "id": "agent-identifier-and-designation", "name": "Agent identifier and designation", "description": "The primary identifier designating this agent, the published human-readable designation, and the alias set that resolves to the same agent across protocols and registries.", "source_refs": [ "SRC-011", "SRC-010", "SRC-003" ], "questions": [ { "id": "q-id-authoritative", "text": "Which authoritative master-system identifier designates this agent, and which system issues it?", "kind": "identity", "answer_data": [ "Identifier value", "Issuing system reference", "Identifier scheme name" ] }, { "id": "q-id-designation", "text": "What human-readable name, description and purpose statement are published for the agent?", "kind": "definition", "answer_data": [ "Display name", "Free-form description", "Intended-purpose statement" ] }, { "id": "q-id-alias-resolution", "text": "Which alternate or protocol-scoped identifiers resolve to this same agent?", "kind": "interoperability", "answer_data": [ "Alias value", "Alias namespace or protocol", "Resolution direction and authority" ] }, { "id": "q-id-instance-vs-definition", "text": "How is a durable agent definition distinguished from a transient in-memory agent instance?", "kind": "classification", "answer_data": [ "Durability class code", "Instance-identifier handling rule", "Reason a transient identifier is or is not recorded" ] } ], "data_elements": [ { "id": "id-agent-identifier", "name": "Agent identifier", "description": "Primary key for the agent, assigned per the identity priority of the adopting Dimension.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "id-agent-name", "name": "Agent designation", "description": "Human-readable name published for humans and capability descriptors.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-011" ] }, { "id": "id-agent-description", "name": "Agent description", "description": "Free-form statement of what the agent is for.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "id-agent-alias", "name": "Alias identifier", "description": "Protocol-scoped or legacy identifier resolving to this agent; never a primary key.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "id-agent-namespace", "name": "Governed namespace IRI", "description": "Resolvable HTTPS namespace under which the agent identifier is minted.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-005" ] } ], "artifacts": [ { "id": "agent-identity-record", "name": "Agent identity record", "description": "Authoritative record binding primary identifier, designation, namespace and alias set, with the issuing system named.", "media_or_form": [ "structured record, format-neutral", "registry entry" ], "serial": false, "identity_strategy": "Keyed by the authoritative master-system identifier; aliases are attributes, never keys.", "source_refs": [ "SRC-011", "SRC-010" ] } ], "inline_only_rationale": null }, { "id": "agent-version-and-change-identity", "name": "Agent version and change identity", "description": "How a released agent definition is versioned, which fields are frozen so a version denotes one behaviour contract, when each version is effective and superseded, and its derivation lineage.", "source_refs": [ "SRC-010", "SRC-001", "SRC-004", "SRC-003" ], "questions": [ { "id": "q-ver-scheme", "text": "What versioning scheme identifies a released agent definition, and which changes force a new version?", "kind": "constraint", "answer_data": [ "Version scheme name", "Material-change rule set", "Version string" ] }, { "id": "q-ver-effective", "text": "From which instant is each agent version effective, and when was it superseded?", "kind": "temporal", "answer_data": [ "Effective-from timestamp", "Superseded-at timestamp", "Time source and offset" ] }, { "id": "q-ver-frozen", "text": "Which fields are frozen at release so that a version identifier always denotes the same behaviour contract?", "kind": "validation", "answer_data": [ "Frozen field list", "Digest of the frozen subset", "Verification method" ] }, { "id": "q-ver-lineage", "text": "Which prior agent version was this version derived from?", "kind": "provenance", "answer_data": [ "Predecessor version reference", "Derivation description", "Deriving actor reference" ] } ], "data_elements": [ { "id": "ver-agent-version", "name": "Agent version identifier", "description": "Released version label of the agent definition.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-010" ] }, { "id": "ver-effective-from", "name": "Version effective from", "description": "Instant at which the version became the governing definition.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "ver-superseded-at", "name": "Version superseded at", "description": "Instant at which a later version replaced this one.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "ver-derived-from", "name": "Derived-from version", "description": "Reference to the predecessor version this definition was derived from.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "ver-frozen-fields", "name": "Frozen field set", "description": "Fields immutable for the life of the version.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "agent-version-manifest", "name": "Agent version manifest", "description": "Immutable manifest of one released version listing frozen fields, effective interval, predecessor and canonical digest.", "media_or_form": [ "immutable structured record", "signed manifest" ], "serial": true, "identity_strategy": "Composite of agent identifier plus version identifier; never keyed by release date.", "source_refs": [ "SRC-010", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "classification-and-autonomy", "name": "Classification and autonomy", "description": "How the agent is typed by architecture and by the autonomy it may exercise, and how it is classified under applicable regulatory and risk frameworks.", "source_refs": [ "SRC-009", "SRC-008", "SRC-006", "SRC-013" ], "findings": [ { "id": "agent-typology-and-autonomy-level", "name": "Agent typology and autonomy level", "description": "The architectural archetype implemented and the autonomy the agent may exercise without a human decision point, including whether it may act on its own initiative.", "source_refs": [ "SRC-009", "SRC-006", "SRC-013" ], "questions": [ { "id": "q-aut-level", "text": "What level of autonomy is the agent authorised to exercise without a human decision point?", "kind": "classification", "answer_data": [ "Autonomy level code", "Scale definition reference", "Authorising decision reference" ] }, { "id": "q-aut-archetype", "text": "Which architectural archetype does the agent implement: single actor, orchestrator, sub-agent or scripted workflow?", "kind": "composition", "answer_data": [ "Archetype code", "Orchestration position", "Sub-agent count bound" ] }, { "id": "q-aut-initiative", "text": "Can the agent initiate activity without a human or upstream request, and under which trigger conditions?", "kind": "event", "answer_data": [ "Initiative mode code", "Trigger condition list", "Schedule or subscription reference" ] }, { "id": "q-aut-review", "text": "How often is the assigned autonomy level re-justified against observed behaviour?", "kind": "validation", "answer_data": [ "Review interval", "Last review timestamp", "Review outcome code" ] } ], "data_elements": [ { "id": "aut-level-code", "name": "Autonomy level code", "description": "Coded degree of independent action permitted to the agent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "aut-archetype-code", "name": "Architectural archetype code", "description": "Coded structural role of the agent in its deployment.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "aut-initiative-mode", "name": "Initiative mode", "description": "Whether the agent is reactive, scheduled or self-initiating.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "aut-review-interval", "name": "Autonomy review interval", "description": "Maximum period between re-justifications of the autonomy level.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "autonomy-classification-statement", "name": "Autonomy classification statement", "description": "Signed statement recording assigned autonomy level and archetype, the scale used, justification and review schedule.", "media_or_form": [ "structured record", "human-readable statement" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; superseded rather than overwritten.", "source_refs": [ "SRC-009", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "regulatory-role-and-risk-classification", "name": "Regulatory role and risk classification", "description": "Which regulatory role the operator holds per jurisdiction, the risk tier and use-case category, the disclosure duties that follow, and the evidence supporting the classification.", "source_refs": [ "SRC-008", "SRC-009", "SRC-006" ], "questions": [ { "id": "q-reg-actor-role", "text": "Is the operator of this agent a provider or a deployer in each jurisdiction where it operates?", "kind": "ownership", "answer_data": [ "Role code per jurisdiction", "Jurisdiction identifier", "Basis for the role determination" ] }, { "id": "q-reg-risk-tier", "text": "Which regulatory risk tier and use-case category does the agent fall into?", "kind": "classification", "answer_data": [ "Risk tier code", "Use-case category", "Framework reference and version" ] }, { "id": "q-reg-disclosure", "text": "Which disclosure duties apply when the agent interacts with natural persons or emits synthetic content?", "kind": "requirement", "answer_data": [ "Disclosure obligation code", "Disclosure text or marking method", "Trigger condition" ] }, { "id": "q-reg-evidence", "text": "What evidence supports the assigned risk classification, and who signed it off?", "kind": "evidence", "answer_data": [ "Assessment document reference", "Approver reference", "Decision timestamp" ] } ], "data_elements": [ { "id": "reg-role-code", "name": "Regulatory role code", "description": "Provider, deployer or other role held per jurisdiction.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "reg-risk-tier", "name": "Risk tier code", "description": "Assigned risk tier under the applicable framework.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "reg-jurisdiction", "name": "Jurisdiction scope", "description": "Jurisdictions in which the agent is placed, used, or whose output is used.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "reg-disclosure-duty", "name": "Disclosure obligation", "description": "Transparency duty triggered by interaction or output type.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "reg-decision-ref", "name": "Classification decision reference", "description": "Reference to the signed classification decision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "regulatory-classification-dossier", "name": "Regulatory classification dossier", "description": "Dossier recording role determination, risk tier, jurisdictional scope, disclosure duties and approving authority.", "media_or_form": [ "document set", "structured record" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus jurisdiction; versioned on any re-classification.", "source_refs": [ "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "constitution-and-provenance", "name": "Constitution and provenance", "description": "Which components the agent is assembled from, and who authored, derived and approved the definition.", "source_refs": [ "SRC-003", "SRC-001", "SRC-006", "SRC-010" ], "findings": [ { "id": "agent-constituent-bindings", "name": "Agent constituent bindings", "description": "The models invoked, the configuration artefacts governing instructions, the callable sub-agents, and whether each binding is pinned or floating.", "source_refs": [ "SRC-001", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-cmp-model-binding", "text": "Which model or models does the agent invoke, and are those bindings pinned or floating?", "kind": "composition", "answer_data": [ "Model reference", "Pin mode code", "Fallback model reference" ] }, { "id": "q-cmp-config-binding", "text": "Which configuration artefact governs the agent's instructions, and at which version?", "kind": "relationship", "answer_data": [ "Configuration artefact reference", "Configuration version", "Binding approval reference" ] }, { "id": "q-cmp-subagents", "text": "Which sub-agents or delegate agents may this agent instantiate or call?", "kind": "relationship", "answer_data": [ "Sub-agent reference", "Invocation direction", "Maximum delegation depth" ] }, { "id": "q-cmp-substitution", "text": "What happens to the agent's identity and approvals when a bound component is substituted?", "kind": "decision", "answer_data": [ "Substitution rule", "Re-approval requirement flag", "Version impact code" ] } ], "data_elements": [ { "id": "cmp-model-binding", "name": "Model binding", "description": "Reference to an invoked model with its pinning mode.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "cmp-configuration-ref", "name": "Configuration reference", "description": "Reference to the governing prompt or agent-configuration artefact and version.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "cmp-subagent-ref", "name": "Sub-agent reference", "description": "Reference to an agent this agent may call or instantiate.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "cmp-pin-mode", "name": "Binding pin mode", "description": "Whether bindings are pinned to an exact version or allowed to float.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "agent-composition-manifest", "name": "Agent composition manifest", "description": "Manifest enumerating model, configuration and sub-agent bindings with pin modes and re-approval rules.", "media_or_form": [ "structured record", "dependency graph" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; immutable once its version is released.", "source_refs": [ "SRC-001", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "definition-provenance-and-attribution", "name": "Definition provenance and attribution", "description": "Who authored, derived and approved the definition, how responsibility for outputs is attributed, and how the provenance record itself is protected.", "source_refs": [ "SRC-003", "SRC-006", "SRC-010" ], "questions": [ { "id": "q-prv-author", "text": "Which party authored and which party approved this agent definition?", "kind": "provenance", "answer_data": [ "Authoring party reference", "Approving party reference", "Approval timestamp" ] }, { "id": "q-prv-derivation", "text": "From which template, framework or upstream agent definition was this definition derived?", "kind": "provenance", "answer_data": [ "Upstream definition reference", "Derivation type code", "Licence or usage terms" ] }, { "id": "q-prv-attribution", "text": "How is responsibility for the agent's outputs attributed back to a responsible party?", "kind": "ownership", "answer_data": [ "Attribution rule", "Responsible party reference", "Qualified association role" ] }, { "id": "q-prv-integrity", "text": "How is the provenance record protected against later undetected modification?", "kind": "security", "answer_data": [ "Canonical digest", "Signing key or process identifier", "Verification procedure reference" ] } ], "data_elements": [ { "id": "prv-authored-by", "name": "Authored by", "description": "Party or agent that authored the definition.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "prv-approved-by", "name": "Approved by", "description": "Party that approved the definition for use.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "prv-derived-from", "name": "Derived from", "description": "Upstream definition, template or framework the definition derives from.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "prv-statement", "name": "Provenance statement", "description": "Qualified association linking activity, agent and plan for the definition's creation.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "prv-definition-digest", "name": "Definition digest", "description": "Digest over the canonical form of the definition.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "agent-provenance-graph", "name": "Agent provenance graph", "description": "Provenance record expressing authorship, approval, derivation and attribution as qualified relations between entities, activities and agents.", "media_or_form": [ "provenance graph", "structured record" ], "serial": false, "identity_strategy": "Keyed by agent version identifier; each assertion carries its own asserting party and time.", "source_refs": [ "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "capability-and-interoperability", "name": "Capability and interoperability", "description": "What the agent can do and how that surface is declared, discovered, negotiated and trusted by other parties.", "rationale": "Tool and resource primitives, skill declarations and capability descriptors are the contract other systems rely on; the same sources that define them also warn that descriptor content is untrusted and that protocol revisions change the available primitives.", "source_refs": [ "SRC-001", "SRC-010", "SRC-011", "SRC-005" ], "layers": [ { "id": "capability-surface", "name": "Capability surface", "description": "The concrete tool and resource bindings the agent holds and the skills it declares to callers.", "source_refs": [ "SRC-001", "SRC-010", "SRC-013" ], "findings": [ { "id": "tool-and-resource-bindings", "name": "Tool and resource bindings", "description": "Which tools and data resources the agent is bound to, which cause irreversible effects, how each provider is vetted, and how a binding change is detected and re-approved.", "source_refs": [ "SRC-001", "SRC-013", "SRC-011" ], "questions": [ { "id": "q-tul-inventory", "text": "Which tools, functions and data resources is the agent bound to, and from which servers or providers?", "kind": "composition", "answer_data": [ "Tool binding entry", "Provider or server reference", "Binding approval status" ] }, { "id": "q-tul-effect-class", "text": "Which bound tools are read-only and which cause irreversible or externally visible effects?", "kind": "classification", "answer_data": [ "Effect class code", "Reversibility flag", "External visibility flag" ] }, { "id": "q-tul-trust", "text": "How is each tool provider vetted, and are tool descriptions treated as untrusted content?", "kind": "security", "answer_data": [ "Vetting decision reference", "Trust level code", "Descriptor sanitisation rule" ] }, { "id": "q-tul-change", "text": "How is a change to a bound tool's schema, description or endpoint detected and re-approved?", "kind": "event", "answer_data": [ "Descriptor digest", "Change detection method", "Re-approval requirement flag" ] } ], "data_elements": [ { "id": "tul-binding", "name": "Tool binding", "description": "One bound tool or function with identifier, provider and approval status.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "tul-server-ref", "name": "Tool server reference", "description": "Reference to the server or provider exposing the tool.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "tul-effect-class", "name": "Effect class", "description": "Coded reversibility and external-visibility class of a bound tool.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "tul-descriptor-digest", "name": "Tool descriptor digest", "description": "Digest of the approved tool descriptor used to detect drift.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "tul-resource-scope", "name": "Resource scope", "description": "Data resources and URI boundaries the agent may read.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "tool-binding-registry-entry", "name": "Tool binding registry entry", "description": "Per-binding record holding provider, effect class, vetting decision, approved descriptor digest and re-approval state.", "media_or_form": [ "structured record", "allowlist entry" ], "serial": true, "identity_strategy": "Composite of agent identifier, tool identifier and provider identifier; descriptor digest carried as an attribute.", "source_refs": [ "SRC-001", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "skill-and-task-declaration", "name": "Skill and task declaration", "description": "The task types the agent declares, the input and output modalities per skill, the requests it must refuse or route away, and the evidence each declared skill is met.", "source_refs": [ "SRC-010", "SRC-001", "SRC-006" ], "questions": [ { "id": "q-skl-declaration", "text": "Which skills or task types does the agent declare that it can perform?", "kind": "definition", "answer_data": [ "Skill identifier", "Skill description", "Example invocation" ] }, { "id": "q-skl-io-modes", "text": "Which input and output content types does the agent accept and produce per skill?", "kind": "interoperability", "answer_data": [ "Input mode list", "Output mode list", "Default mode indicator" ] }, { "id": "q-skl-refusal", "text": "Which requests must the agent refuse or route elsewhere?", "kind": "exception", "answer_data": [ "Out-of-scope request class", "Refusal behaviour code", "Routing target reference" ] }, { "id": "q-skl-evidence", "text": "What evidence shows the agent performs each declared skill at the stated quality?", "kind": "evidence", "answer_data": [ "Evaluation reference", "Metric value", "Evidence timestamp" ] } ], "data_elements": [ { "id": "skl-declaration", "name": "Skill declaration", "description": "One declared skill with identifier, description and scope.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-010" ] }, { "id": "skl-input-modes", "name": "Input modes", "description": "Accepted input content types for the agent or a skill.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "skl-output-modes", "name": "Output modes", "description": "Produced output content types for the agent or a skill.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "skl-refusal-scope", "name": "Refusal scope", "description": "Request classes the agent must refuse or route away.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "agent-capability-card", "name": "Agent capability card", "description": "Published descriptor listing declared skills, modalities, refusal scope and supporting evidence references.", "media_or_form": [ "published descriptor", "structured record" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; the descriptor name field is a display alias, not a key.", "source_refs": [ "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "protocol-and-discovery", "name": "Protocol conformance and discovery", "description": "Which protocols and revisions the agent speaks, how it advertises and negotiates them, and how consumers verify a descriptor is authentic.", "source_refs": [ "SRC-001", "SRC-010", "SRC-005" ], "findings": [ { "id": "protocol-conformance-and-advertisement", "name": "Protocol conformance and advertisement", "description": "Protocol bindings and revisions per endpoint, negotiation and failure behaviour, descriptor authenticity, and the evidence behind any conformance claim.", "source_refs": [ "SRC-001", "SRC-010", "SRC-005" ], "questions": [ { "id": "q-prt-bindings", "text": "Which agent and tool protocols, at which revisions, does the agent speak on each endpoint?", "kind": "interoperability", "answer_data": [ "Protocol name", "Supported revision list", "Endpoint URI and transport" ] }, { "id": "q-prt-negotiation", "text": "How does the agent negotiate protocol revisions and behave when no mutually supported revision exists?", "kind": "process", "answer_data": [ "Negotiation mechanism", "Unsupported-version error behaviour", "Backward-compatibility window" ] }, { "id": "q-prt-authenticity", "text": "How can a consumer verify that a published capability descriptor genuinely belongs to this agent?", "kind": "security", "answer_data": [ "Descriptor signature", "Signing key identifier", "Verification procedure reference" ] }, { "id": "q-prt-conformance", "text": "Which conformance claims are asserted, and what test evidence supports them?", "kind": "validation", "answer_data": [ "Claimed specification and revision", "Test suite reference", "Test result timestamp" ] } ], "data_elements": [ { "id": "prt-binding", "name": "Protocol binding", "description": "A protocol offered by the agent with its transport and role.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "prt-endpoint-uri", "name": "Endpoint URI", "description": "Canonical resource URI on which the protocol is offered.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "prt-supported-revisions", "name": "Supported revisions", "description": "Protocol revisions the agent accepts.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "prt-descriptor-signature", "name": "Descriptor signature", "description": "Signature over the published capability descriptor.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "prt-conformance-evidence", "name": "Conformance evidence reference", "description": "Reference to test evidence supporting a conformance claim.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "published-agent-descriptor", "name": "Published agent descriptor", "description": "Externally retrievable, signed descriptor combining identity, skills, protocol revisions, endpoints and security schemes for discovery.", "media_or_form": [ "published descriptor", "signed document", "discovery endpoint response" ], "serial": false, "identity_strategy": "Addressed by canonical resource URI; bound to the agent identifier inside the payload and verified by signature.", "source_refs": [ "SRC-010", "SRC-005", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "discovery-manifest-and-locators", "name": "Discovery manifest and locators", "description": "A2A requires a self-describing Agent Card covering identity, capabilities, skills, interfaces and authentication, commonly retrieved from a well-known URI. FIPA Directory Facilitators provide yellow-pages service descriptions. Extended cards may be released only after authentication. Locators are identifiers plus access hints, not the storage format.", "source_refs": [ "SRC-015", "SRC-010" ], "questions": [ { "id": "discovery-manifest-and-locators-q01", "text": "Where is this agent's discovery manifest published, and which protocol bindings, tenants and protocol versions does it advertise?", "kind": "interoperability", "answer_data": [ "manifest_locator", "supported_interfaces", "protocol_bindings", "tenant_id", "protocol_version" ] }, { "id": "discovery-manifest-and-locators-q02", "text": "Does the agent offer an authenticated extended discovery card, and which additional skills or interfaces appear only after authentication?", "kind": "access", "answer_data": [ "extended_card_supported", "extended_skill_delta", "required_security_schemes" ] }, { "id": "discovery-manifest-and-locators-q03", "text": "Which optional interaction capabilities (streaming, push notifications, extensions) does the agent declare, and how are undeclared capabilities rejected?", "kind": "classification", "answer_data": [ "streaming_flag", "push_notifications_flag", "extensions_list", "capability_rejection_policy" ] }, { "id": "discovery-manifest-and-locators-q04", "text": "Which default input and output media types does the agent accept across skills?", "kind": "interoperability", "answer_data": [ "default_input_modes", "default_output_modes" ] } ], "data_elements": [ { "id": "discovery-manifest-and-locators-data01", "name": "Discovery manifest locator", "description": "URI or directory key where the Agent Card or DF description is obtained.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "discovery-manifest-and-locators-data02", "name": "Supported interfaces", "description": "Ordered list of interface locators with protocol binding, protocol version and optional tenant.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "discovery-manifest-and-locators-data03", "name": "Security schemes", "description": "Declared authentication and authorization schemes for contacting the agent.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "discovery-manifest-and-locators-data04", "name": "Declared capabilities", "description": "Boolean and extension capability set from the discovery manifest.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [ { "id": "discovery-manifest-and-locators-artifact01", "name": "Agent discovery card", "description": "Self-describing manifest of identity, skills, interfaces, capabilities and security requirements, independent of JSON-versus-protobuf encoding.", "media_or_form": [ "discovery-manifest", "directory-entry" ], "serial": true, "identity_strategy": "Identified by agent master-system id plus manifest version; well-known locator is a secondary key.", "source_refs": [ "SRC-010", "SRC-015" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "authority-delegation-and-access-control", "name": "Authority, delegation and access control", "description": "On whose behalf the agent acts, what it may do, which credentials carry that permission, and where a human decision is required before it acts.", "rationale": "Provenance modelling makes delegation explicit through acting-on-behalf-of relations; authorization specifications require audience-bound tokens and forbid pass-through; zero-trust guidance requires per-session authorisation with no implicit trust; and protocol trust principles require explicit user consent before tool invocation.", "source_refs": [ "SRC-003", "SRC-002", "SRC-012", "SRC-001", "SRC-009" ], "layers": [ { "id": "delegation-and-credentials", "name": "Delegation and credentials", "description": "The chain from an originating human principal to the agent and its sub-agents, and the credentials carrying the granted authority.", "source_refs": [ "SRC-003", "SRC-002", "SRC-005", "SRC-012" ], "findings": [ { "id": "principal-and-delegation-chain", "name": "Principal and delegation chain", "description": "The principal on whose behalf the agent acts, the full chain to sub-agents, the non-delegable authorities, and each delegation's validity window.", "source_refs": [ "SRC-003", "SRC-002", "SRC-012" ], "questions": [ { "id": "q-dlg-principal", "text": "On whose behalf is the agent acting for a given activity, and how is that principal identified?", "kind": "authority", "answer_data": [ "Principal reference", "Principal identifier scheme", "Activity scope" ] }, { "id": "q-dlg-chain", "text": "What is the full delegation chain from the originating human principal to this agent and its sub-agents?", "kind": "relationship", "answer_data": [ "Ordered chain of party references", "Delegation depth", "Chain assertion timestamp" ] }, { "id": "q-dlg-limits", "text": "Which authorities may never be sub-delegated onward to another agent?", "kind": "constraint", "answer_data": [ "Non-delegable authority list", "Enforcement point reference", "Violation handling code" ] }, { "id": "q-dlg-validity", "text": "For how long and under which conditions does a delegation remain valid?", "kind": "temporal", "answer_data": [ "Valid-from timestamp", "Valid-until timestamp", "Revocation condition list" ] } ], "data_elements": [ { "id": "dlg-principal-ref", "name": "Acting principal reference", "description": "Party on whose behalf the agent acts.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "dlg-chain", "name": "Delegation chain", "description": "Ordered sequence of delegating parties from originating principal to acting agent.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "dlg-non-delegable", "name": "Non-delegable authority", "description": "Authority that must not be passed onward to a sub-agent.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "dlg-valid-until", "name": "Delegation valid until", "description": "Instant after which the delegation no longer holds.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "delegation-grant-record", "name": "Delegation grant record", "description": "Record of one delegation: granting principal, receiving agent, scope, non-delegable exclusions and validity window.", "media_or_form": [ "structured record", "append-only grant log" ], "serial": true, "identity_strategy": "Keyed by grant identifier issued by the granting authority; parties referenced by their own authoritative identifiers.", "source_refs": [ "SRC-003", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "credential-scope-and-token-binding", "name": "Credential scope and token binding", "description": "The credentials the agent may present, their binding to an intended resource audience, the minimum scope per skill, and rotation and revocation.", "source_refs": [ "SRC-002", "SRC-005", "SRC-012" ], "questions": [ { "id": "q-crd-inventory", "text": "Which credentials, tokens or keys can the agent present, and who issued each?", "kind": "security", "answer_data": [ "Credential reference", "Issuer identifier", "Credential type code" ] }, { "id": "q-crd-audience", "text": "How is each token bound to its intended resource audience, and is pass-through forbidden?", "kind": "constraint", "answer_data": [ "Resource audience identifier", "Audience validation rule", "Pass-through prohibition flag" ] }, { "id": "q-crd-minimisation", "text": "What is the minimum scope set required for each declared skill?", "kind": "requirement", "answer_data": [ "Skill reference", "Required scope list", "Justification statement" ] }, { "id": "q-crd-rotation", "text": "How are agent credentials rotated, revoked and re-issued?", "kind": "process", "answer_data": [ "Rotation interval", "Revocation trigger list", "Re-issue procedure reference" ] } ], "data_elements": [ { "id": "crd-credential-ref", "name": "Credential reference", "description": "Pointer to a credential the agent may present; key material is never stored in the model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "crd-granted-scopes", "name": "Granted scopes", "description": "Authorisation scopes attached to a credential.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "crd-token-audience", "name": "Token audience", "description": "Canonical resource identifier a token is valid for.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "id": "crd-rotation-interval", "name": "Rotation interval", "description": "Maximum period before a credential must be rotated.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "crd-revocation-state", "name": "Revocation state", "description": "Current revocation status of a credential.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [ { "id": "agent-credential-scope-map", "name": "Agent credential scope map", "description": "Map from declared skills to minimum credentials, scopes and resource audiences, with rotation and revocation state.", "media_or_form": [ "structured record", "access matrix" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; credentials referenced by issuer-assigned identifiers, never by value.", "source_refs": [ "SRC-002", "SRC-005" ] } ], "inline_only_rationale": null } ] }, { "id": "permission-boundaries-and-consent", "name": "Permission boundaries and consent", "description": "The policy authorising each action, the categorical prohibitions, the bounded blast radius, and the points where a human must consent.", "source_refs": [ "SRC-012", "SRC-001", "SRC-009", "SRC-013" ], "findings": [ { "id": "action-authorization-policy", "name": "Action authorisation policy", "description": "Which policy decision point authorises each action, which actions are categorically forbidden, how far a single action can reach, and how an emergency deviation is approved.", "source_refs": [ "SRC-012", "SRC-001", "SRC-013" ], "questions": [ { "id": "q-pol-decision-point", "text": "Which policy decision point authorises each agent action, and is the decision made per request?", "kind": "access", "answer_data": [ "Policy decision point reference", "Decision granularity code", "Input signals used" ] }, { "id": "q-pol-deny", "text": "Which actions, targets or environments are categorically forbidden to the agent?", "kind": "constraint", "answer_data": [ "Deny rule", "Target pattern", "Enforcement point reference" ] }, { "id": "q-pol-blast-radius", "text": "What is the maximum blast radius of a single authorised action, and how is it bounded?", "kind": "measurement", "answer_data": [ "Impact bound quantity and unit", "Bounding mechanism", "Measurement method" ] }, { "id": "q-pol-override", "text": "How is an emergency deviation from policy requested, approved and recorded?", "kind": "exception", "answer_data": [ "Override request reference", "Dual-approval record", "Override validity window" ] } ], "data_elements": [ { "id": "pol-policy-ref", "name": "Authorisation policy reference", "description": "Reference to the governing authorisation policy and its version.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "pol-deny-rule", "name": "Deny rule", "description": "Categorical prohibition on an action, target or environment.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "pol-environment-scope", "name": "Environment scope", "description": "Environments in which the agent may act, such as sandbox, staging or production.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "pol-max-impact", "name": "Maximum impact bound", "description": "Quantitative ceiling on the effect of a single authorised action.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "pol-override-ref", "name": "Policy override record reference", "description": "Reference to an approved emergency deviation.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [ { "id": "agent-authorization-policy", "name": "Agent authorisation policy", "description": "Versioned policy defining decision points, allow and deny rules, environment scope, impact bounds and override procedure.", "media_or_form": [ "policy document", "machine-evaluable rule set" ], "serial": false, "identity_strategy": "Keyed by policy identifier and version; bound to agent versions by explicit reference rather than name matching.", "source_refs": [ "SRC-012", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "human-approval-and-consent-gates", "name": "Human approval and consent gates", "description": "Which operations require explicit human consent, what evidences that consent, whether approval is per action, per session or standing, and how rubber-stamping is resisted.", "source_refs": [ "SRC-001", "SRC-009", "SRC-008" ], "questions": [ { "id": "q-cns-points", "text": "Which operations require explicit user consent before the agent may proceed?", "kind": "decision", "answer_data": [ "Gated operation class", "Consent requirement code", "Bypass conditions if any" ] }, { "id": "q-cns-evidence", "text": "What is recorded to evidence that consent or approval was given, by whom and when?", "kind": "evidence", "answer_data": [ "Approver reference", "Approval timestamp", "Presented request summary" ] }, { "id": "q-cns-duration", "text": "Does a granted approval cover a single action, a session or a standing authorisation?", "kind": "temporal", "answer_data": [ "Approval granularity code", "Approval validity window", "Renewal requirement" ] }, { "id": "q-cns-fatigue", "text": "How is the oversight interface protected against approval fatigue and rubber-stamping?", "kind": "quality", "answer_data": [ "Prompt-rate limit", "Batching or grouping rule", "Review sampling measure" ] } ], "data_elements": [ { "id": "cns-gate", "name": "Consent gate", "description": "An operation class requiring explicit human approval.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "cns-approval-record", "name": "Approval record", "description": "Structured evidence of a granted or refused approval.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "cns-granularity", "name": "Approval granularity", "description": "Whether an approval is per action, per session or standing.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "cns-approver-ref", "name": "Approver reference", "description": "Party that granted or refused the approval.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "consent-and-approval-log", "name": "Consent and approval log", "description": "Append-only log of consent prompts, decisions, approvers, presented content and validity windows.", "media_or_form": [ "append-only log", "structured record" ], "serial": true, "identity_strategy": "Sequential entry identifier per agent; each entry carries event time and ingestion time separately.", "source_refs": [ "SRC-001", "SRC-009" ] } ], "inline_only_rationale": null }, { "id": "standing-goals-and-stop-criteria", "name": "Goals and success criteria", "description": "An ISO AI agent takes actions to achieve its goals. Goal statements, in-scope objectives, explicit out-of-scope objectives and measurable success or stop criteria belong on the agent record so that goal hijack can be detected against a baseline. Run-specific tasks remain WM-AI-004.", "source_refs": [ "SRC-014", "SRC-019" ], "questions": [ { "id": "standing-goals-and-stop-criteria-q01", "text": "What standing goals and in-scope objectives is this agent authorised to pursue?", "kind": "definition", "answer_data": [ "primary_goals", "in_scope_objectives", "goal_owner_id" ] }, { "id": "standing-goals-and-stop-criteria-q02", "text": "Which objectives are explicitly out of scope, and which stop or success criteria terminate pursuit of a goal?", "kind": "constraint", "answer_data": [ "out_of_scope_objectives", "success_criteria", "stop_criteria" ] }, { "id": "standing-goals-and-stop-criteria-q03", "text": "Who may change the agent's goal set, and what evidence is required before a goal mutation is accepted?", "kind": "decision", "answer_data": [ "goal_change_role", "change_evidence_required", "last_goal_change_event_time" ] } ], "data_elements": [ { "id": "standing-goals-and-stop-criteria-data01", "name": "Primary goals", "description": "Standing goal statements the agent is authorised to pursue.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "standing-goals-and-stop-criteria-data02", "name": "Success and stop criteria", "description": "Measurable conditions under which pursuit of a goal succeeds or must stop.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-019" ] }, { "id": "standing-goals-and-stop-criteria-data03", "name": "Goal owner reference", "description": "Person or organisation accountable for the declared goals.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] } ], "artifacts": [ { "id": "standing-goals-and-stop-criteria-artifact01", "name": "Agent goal charter", "description": "Serial statement of authorised goals, exclusions and success criteria against which goal-manipulation checks are made.", "media_or_form": [ "policy-document", "structured-record" ], "serial": true, "identity_strategy": "Keyed by agent master-system id plus charter version.", "source_refs": [ "SRC-014", "SRC-019" ] } ], "inline_only_rationale": null } ] }, { "id": "accountable-roles", "name": "Accountable roles", "description": "Which named parties are accountable for the agent, how duties are separated, and how accountability survives organisational change.", "source_refs": [ "SRC-008", "SRC-006", "SRC-009" ], "findings": [ { "id": "ownership-and-accountability-assignment", "name": "Ownership and accountability assignment", "description": "The organisation and roles accountable in production, separation of build, approval and operation duties, escalation contacts and response targets, and accountability transfer.", "source_refs": [ "SRC-008", "SRC-006", "SRC-009" ], "questions": [ { "id": "q-own-accountable", "text": "Which named organisation and role is accountable for this agent in production?", "kind": "ownership", "answer_data": [ "Accountable organisation reference", "Accountable role title", "Accountability start timestamp" ] }, { "id": "q-own-separation", "text": "How are build, approval and operation duties separated across roles?", "kind": "authority", "answer_data": [ "Role to duty mapping", "Incompatible-duty pairs", "Enforcement mechanism" ] }, { "id": "q-own-escalation", "text": "Who is contactable, and within what response time, when the agent misbehaves?", "kind": "process", "answer_data": [ "Escalation contact record", "Response time target", "Coverage window" ] }, { "id": "q-own-handover", "text": "What happens to accountability when the owning team, vendor or contract changes?", "kind": "lifecycle", "answer_data": [ "Handover record reference", "Effective transfer timestamp", "Outstanding obligation list" ] } ], "data_elements": [ { "id": "own-accountable-org", "name": "Accountable organisation", "description": "Organisation answerable for the agent's operation.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "own-accountable-role", "name": "Accountable role", "description": "Named roles holding defined duties for the agent.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "own-escalation-contact", "name": "Escalation contact", "description": "Contact route for misbehaviour or incident escalation.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "own-response-target", "name": "Response time target", "description": "Committed maximum time to first human response.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "own-handover-record", "name": "Handover record", "description": "Reference to a recorded transfer of accountability.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "agent-accountability-register-entry", "name": "Agent accountability register entry", "description": "Register entry naming the accountable organisation, roles, duty separation, escalation routes and handover history.", "media_or_form": [ "register entry", "structured record" ], "serial": false, "identity_strategy": "Keyed by agent identifier; historical assignments retained as time-bounded rows rather than overwritten.", "source_refs": [ "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "memory-state-and-data-governance", "name": "Memory, state and data governance", "description": "What the agent remembers, what may write into that memory, which data it may process for which purpose, and how long anything is kept.", "rationale": "Durable agent memory is a governed data store with its own privacy, integrity and retention duties; risk taxonomies name data privacy, information integrity and poisoning as first-order concerns, and protocol trust principles forbid transmitting user data without consent.", "source_refs": [ "SRC-007", "SRC-013", "SRC-001", "SRC-008" ], "layers": [ { "id": "memory-architecture", "name": "Memory architecture", "description": "Which stores hold agent state, how they are scoped and isolated, and how their contents are kept trustworthy.", "source_refs": [ "SRC-007", "SRC-013", "SRC-003", "SRC-001" ], "findings": [ { "id": "memory-store-inventory", "name": "Memory store inventory", "description": "The stores read and written, which persist beyond a session and where, how memory is isolated between tenants and sessions, and which source wins on conflict.", "source_refs": [ "SRC-001", "SRC-007", "SRC-013" ], "questions": [ { "id": "q-mem-kinds", "text": "Which memory stores does the agent read from and write to, and what is each store's scope?", "kind": "composition", "answer_data": [ "Store identifier", "Store kind code", "Scope of applicability" ] }, { "id": "q-mem-persistence", "text": "Which memory persists beyond a session, and in which storage locality is it held?", "kind": "spatial", "answer_data": [ "Persistence scope code", "Storage locality or region", "Residency constraint reference" ] }, { "id": "q-mem-isolation", "text": "How is memory isolated between tenants, users and sessions?", "kind": "privacy", "answer_data": [ "Isolation boundary code", "Partition key", "Leak test evidence reference" ] }, { "id": "q-mem-precedence", "text": "When stored memory conflicts with current instructions or retrieved context, which source prevails?", "kind": "constraint", "answer_data": [ "Precedence rule", "Conflict detection method", "Escalation behaviour" ] } ], "data_elements": [ { "id": "mem-store", "name": "Memory store", "description": "One store the agent reads or writes, with kind and scope.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "mem-persistence-scope", "name": "Persistence scope", "description": "Whether memory is per turn, per session or durable.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "mem-storage-locality", "name": "Storage locality", "description": "Physical or logical region where durable memory resides.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "mem-isolation-boundary", "name": "Isolation boundary", "description": "Boundary enforced between tenants, users or sessions.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "mem-precedence-rule", "name": "Precedence rule", "description": "Rule resolving conflicts between memory, instructions and retrieved context.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "memory-store-inventory-record", "name": "Memory store inventory record", "description": "Inventory of agent memory stores with kind, scope, locality, isolation boundary and precedence rules.", "media_or_form": [ "structured record", "inventory table" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus store identifier; store identifiers assigned by the owning data platform.", "source_refs": [ "SRC-001", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "memory-write-integrity", "name": "Memory write integrity", "description": "What may write into durable memory and under whose authority, the provenance each item carries, controls against poisoning, and correction or quarantine of bad items.", "source_refs": [ "SRC-013", "SRC-003", "SRC-007" ], "questions": [ { "id": "q-mwi-write-authority", "text": "What is permitted to write into durable agent memory, and under whose authority?", "kind": "authority", "answer_data": [ "Write permission rule", "Authorising party reference", "Writer class code" ] }, { "id": "q-mwi-provenance", "text": "For each memory item, what records its origin, observation time and confidence?", "kind": "provenance", "answer_data": [ "Origin reference", "Observation timestamp", "Confidence value" ] }, { "id": "q-mwi-poisoning", "text": "Which controls detect and contain poisoned or adversarially injected memory?", "kind": "security", "answer_data": [ "Control identifier", "Detection signal", "Containment action" ] }, { "id": "q-mwi-correction", "text": "How is an incorrect memory item corrected, quarantined or rolled back?", "kind": "process", "answer_data": [ "Correction procedure reference", "Quarantine state", "Rollback target" ] } ], "data_elements": [ { "id": "mwi-write-rule", "name": "Write permission rule", "description": "Rule stating which sources may write to which memory store.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "mwi-item-provenance", "name": "Memory item provenance", "description": "Origin, deriving activity and asserting party for a memory item.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "mwi-observation-time", "name": "Observation time", "description": "Instant at which the remembered fact was observed, distinct from write time.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "mwi-integrity-check", "name": "Integrity check", "description": "Digest or validation applied to a stored memory item.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "mwi-quarantine-state", "name": "Quarantine state", "description": "Whether an item is active, quarantined or withdrawn.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "memory-item-provenance-record", "name": "Memory item provenance record", "description": "Per-item record of origin, observation time, writing authority, integrity check and quarantine state.", "media_or_form": [ "structured record", "append-only journal" ], "serial": true, "identity_strategy": "Item identifier assigned by the memory store, referenced with the store identifier to stay unique across stores.", "source_refs": [ "SRC-003", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "data-protection-and-retention", "name": "Data protection and retention", "description": "Which data categories the agent may process for which purposes, and how long each record class is kept before deletion.", "source_refs": [ "SRC-007", "SRC-008", "SRC-001", "SRC-006" ], "findings": [ { "id": "data-category-and-purpose-limits", "name": "Data category and purpose limits", "description": "Categories of personal, confidential or regulated data permitted, declared purposes for each, cross-boundary transfer conditions, and verification of minimisation.", "source_refs": [ "SRC-007", "SRC-008", "SRC-001" ], "questions": [ { "id": "q-dat-categories", "text": "Which categories of personal, confidential or regulated data may the agent process?", "kind": "privacy", "answer_data": [ "Data category code", "Sensitivity level", "Lawful basis or authorisation reference" ] }, { "id": "q-dat-purpose", "text": "For which declared purposes may each data category be used, and what use is forbidden?", "kind": "constraint", "answer_data": [ "Permitted purpose list", "Prohibited use list", "Purpose binding mechanism" ] }, { "id": "q-dat-transfer", "text": "Under which conditions may data leave a jurisdiction, tenant or trust boundary?", "kind": "access", "answer_data": [ "Transfer condition", "Destination boundary identifier", "Safeguard reference" ] }, { "id": "q-dat-minimisation", "text": "How is it verified that the agent requests only the data it needs?", "kind": "validation", "answer_data": [ "Minimisation test reference", "Observed field usage measure", "Finding and remediation reference" ] } ], "data_elements": [ { "id": "dat-category", "name": "Data category", "description": "Class of data the agent is permitted to process.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "dat-permitted-purpose", "name": "Permitted purpose", "description": "Declared purpose for which a data category may be used.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "dat-transfer-condition", "name": "Transfer condition", "description": "Condition permitting movement across a boundary.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "dat-residency-constraint", "name": "Residency constraint", "description": "Jurisdictional constraint on where data may be stored or processed.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [ { "id": "agent-data-handling-statement", "name": "Agent data handling statement", "description": "Statement of data categories, permitted purposes, prohibited uses, transfer conditions and residency constraints.", "media_or_form": [ "policy statement", "structured record" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; re-issued whenever categories or purposes change.", "source_refs": [ "SRC-007", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "retention-and-deletion-rules", "name": "Retention and deletion rules", "description": "How long each class of record, log and memory is retained and on what clock, deletion triggers and verification, legal holds, and resolution of conflicting duties.", "source_refs": [ "SRC-008", "SRC-006", "SRC-007", "SRC-004" ], "questions": [ { "id": "q-ret-period", "text": "How long is each class of agent record, log and memory retained, and from which clock does the period run?", "kind": "retention", "answer_data": [ "Retention class code", "Retention period", "Clock start event" ] }, { "id": "q-ret-trigger", "text": "Which events trigger deletion, and how is deletion verified across replicas and backups?", "kind": "event", "answer_data": [ "Deletion trigger event", "Verification method", "Replica and backup coverage" ] }, { "id": "q-ret-hold", "text": "How does a legal hold or open investigation suspend normal deletion?", "kind": "exception", "answer_data": [ "Hold flag and scope", "Authorising reference", "Hold release condition" ] }, { "id": "q-ret-conflict", "text": "How are conflicting duties resolved between audit retention and erasure rights?", "kind": "decision", "answer_data": [ "Conflict resolution rule", "Deciding authority", "Recorded rationale" ] } ], "data_elements": [ { "id": "ret-class", "name": "Retention class", "description": "Class assigned to a record type for retention purposes.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "ret-period", "name": "Retention period", "description": "Duration for which a retention class is kept.", "value_kind": "duration", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "ret-deletion-verification", "name": "Deletion verification", "description": "Method and result proving deletion across all copies.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "ret-legal-hold", "name": "Legal hold flag", "description": "Whether deletion is currently suspended by a hold.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "ret-conflict-rule", "name": "Retention conflict rule", "description": "Rule resolving competing retention and erasure duties.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "retention-schedule-entry", "name": "Retention schedule entry", "description": "Entry binding a record class to its retention period, clock start, deletion trigger, hold handling and verification method.", "media_or_form": [ "schedule entry", "structured record" ], "serial": false, "identity_strategy": "Keyed by retention class identifier issued by the owning data governance function, scoped to the agent identifier.", "source_refs": [ "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "lifecycle-and-runtime-operation", "name": "Lifecycle and runtime operation", "description": "How an agent moves through its governed states, how releases are approved and rolled back, and how it is bounded and overseen while running.", "rationale": "Risk-management guidance organises AI work as a governed lifecycle with explicit management actions; regulation requires high-risk systems to be effectively overseen by natural persons while in use, including intervention and stop; and excessive agency is a named risk that must be bounded by explicit operating limits.", "source_refs": [ "SRC-006", "SRC-008", "SRC-009", "SRC-013" ], "layers": [ { "id": "lifecycle-and-change-control", "name": "Lifecycle and change control", "description": "The legal states of an agent, transitions between them, and the approval and rollback controls governing releases.", "source_refs": [ "SRC-006", "SRC-008", "SRC-004" ], "findings": [ { "id": "agent-lifecycle-state-model", "name": "Agent lifecycle state model", "description": "States an agent may occupy, legal transitions, preconditions for production, conditions forcing suspension, and decommission obligations.", "source_refs": [ "SRC-006", "SRC-008", "SRC-004" ], "questions": [ { "id": "q-lif-states", "text": "Which lifecycle states may an agent occupy, and which transitions between them are legal?", "kind": "lifecycle", "answer_data": [ "State code list", "Allowed transition pairs", "State machine reference" ] }, { "id": "q-lif-preconditions", "text": "What must be true before an agent may move into an active production state?", "kind": "state", "answer_data": [ "Precondition list", "Verification evidence reference", "Approving role" ] }, { "id": "q-lif-suspension", "text": "Which conditions force immediate suspension or withdrawal of the agent?", "kind": "event", "answer_data": [ "Suspension trigger code", "Detecting control", "Authorised suspender role" ] }, { "id": "q-lif-decommission", "text": "What must be preserved, migrated or destroyed when the agent is retired?", "kind": "retention", "answer_data": [ "Preservation obligation list", "Migration target reference", "Destruction confirmation" ] } ], "data_elements": [ { "id": "lif-state", "name": "Lifecycle state", "description": "Current governed state of the agent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "lif-state-entered-at", "name": "State entered at", "description": "Instant at which the current state was entered.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "lif-allowed-transition", "name": "Allowed transition", "description": "Legal transition from one state to another with its guard condition.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "lif-suspension-reason", "name": "Suspension reason", "description": "Coded reason for suspension or withdrawal.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "lif-decommission-plan", "name": "Decommission plan reference", "description": "Reference to the plan governing retirement obligations.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "agent-lifecycle-state-record", "name": "Agent lifecycle state record", "description": "Append-only history of lifecycle states with entry instants, actors, reasons and guard evidence.", "media_or_form": [ "append-only state history", "structured record" ], "serial": true, "identity_strategy": "Sequential transition identifier per agent; current state derived from the latest entry, never a lone mutable field.", "source_refs": [ "SRC-006", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "release-approval-and-rollback", "name": "Release approval and rollback", "description": "Approval gates before production, which changes are material and force re-approval, rollback speed and target, and the record proving who approved on what evidence.", "source_refs": [ "SRC-006", "SRC-008", "SRC-007" ], "questions": [ { "id": "q-rel-gate", "text": "Which approval gates must be passed before an agent version reaches production?", "kind": "decision", "answer_data": [ "Gate identifier", "Gate owner role", "Pass or fail outcome" ] }, { "id": "q-rel-materiality", "text": "Which changes count as material and therefore require re-approval?", "kind": "classification", "answer_data": [ "Materiality rule", "Affected field list", "Re-approval requirement flag" ] }, { "id": "q-rel-rollback", "text": "How quickly can a released agent version be rolled back, and to which known-good state?", "kind": "process", "answer_data": [ "Rollback target version reference", "Rollback time objective", "Rollback test evidence" ] }, { "id": "q-rel-record", "text": "What record proves who approved a release, on what evidence and at what time?", "kind": "evidence", "answer_data": [ "Approver reference", "Evidence bundle reference", "Approval timestamp" ] } ], "data_elements": [ { "id": "rel-gate", "name": "Release gate", "description": "A required approval gate with owner and outcome.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "rel-materiality", "name": "Change materiality", "description": "Coded materiality of a change to the agent definition.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "rel-rollback-target", "name": "Rollback target version", "description": "Known-good version to which the agent can be reverted.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "rel-rollback-objective", "name": "Rollback time objective", "description": "Committed maximum time to complete a rollback.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "rel-approval-timestamp", "name": "Approval timestamp", "description": "Instant at which a gate decision was recorded.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "release-approval-record", "name": "Release approval record", "description": "Record of gate outcomes, approvers, supporting evidence, materiality assessment and rollback plan for one agent version.", "media_or_form": [ "structured record", "signed decision document" ], "serial": true, "identity_strategy": "Keyed by agent version identifier plus sequential release attempt number.", "source_refs": [ "SRC-006", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "directory-registration-and-lease", "name": "Directory registration and lease", "description": "An agent must register with the AMS of its home platform to obtain a valid AID. DF registration advertises services and may carry a lease time after which the DF may silently remove the entry. Register, deregister, modify and search are the management functions.", "source_refs": [ "SRC-015" ], "questions": [ { "id": "directory-registration-and-lease-q01", "text": "Is this agent registered with its home AMS, and which ams-agent-description (name, ownership, state) is stored?", "kind": "lifecycle", "answer_data": [ "ams_registered", "ownership_string", "ams_state" ] }, { "id": "directory-registration-and-lease-q02", "text": "Which Directory Facilitators hold a description of this agent, and when does each registration lease expire or renew?", "kind": "temporal", "answer_data": [ "df_ids", "lease_duration_or_expiry", "renewal_required" ] }, { "id": "directory-registration-and-lease-q03", "text": "What search constraints, access restrictions and exception codes apply when other agents look up this agent?", "kind": "access", "answer_data": [ "search_visibility", "max_depth_policy", "exception_codes" ] } ], "data_elements": [ { "id": "directory-registration-and-lease-data01", "name": "AMS registered flag", "description": "Whether the agent currently holds an AMS registration on its HAP.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "directory-registration-and-lease-data02", "name": "Directory lease time", "description": "Duration or absolute expiry of DF registration; unlimited if omitted by a DF that does not support leases.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015" ] }, { "id": "directory-registration-and-lease-data03", "name": "AMS ownership string", "description": "Owner recorded on the ams-agent-description.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015" ] } ], "artifacts": [ { "id": "directory-registration-and-lease-artifact01", "name": "Directory agent description", "description": "AMS and/or DF description records for this agent, including lease metadata.", "media_or_form": [ "directory-entry", "structured-record" ], "serial": true, "identity_strategy": "Keyed by AID name on the issuing AMS or DF; lease expiry is metadata, not identity.", "source_refs": [ "SRC-015" ] } ], "inline_only_rationale": null } ] }, { "id": "runtime-control-and-execution-linkage", "name": "Runtime control and execution linkage", "description": "How humans supervise and stop the agent, how its consumption is bounded, and how running activity ties back to the exact agent version.", "source_refs": [ "SRC-009", "SRC-013", "SRC-011", "SRC-004" ], "findings": [ { "id": "human-oversight-and-intervention", "name": "Human oversight and intervention", "description": "Affordances letting a competent person understand, monitor and interrupt the agent in use, the stop mechanism and residual state, counter-measures to automation bias, and intervention records.", "source_refs": [ "SRC-009", "SRC-008", "SRC-001" ], "questions": [ { "id": "q-ovs-design", "text": "Which interface affordances let a competent person understand, monitor and interrupt the agent while it is in use?", "kind": "requirement", "answer_data": [ "Affordance list", "Displayed capability and limitation summary", "Overseer competence requirement" ] }, { "id": "q-ovs-stop", "text": "How is the agent stopped mid-task, and what state does a stop leave behind?", "kind": "process", "answer_data": [ "Stop mechanism description", "Post-stop state definition", "Compensating action list" ] }, { "id": "q-ovs-bias", "text": "How does the oversight design counter automation bias and over-reliance on agent output?", "kind": "quality", "answer_data": [ "Bias counter-measure", "Confidence or uncertainty display rule", "Training requirement reference" ] }, { "id": "q-ovs-record", "text": "What is recorded when a human overrides, corrects or halts the agent?", "kind": "event", "answer_data": [ "Intervention type code", "Intervening party reference", "Event and ingestion timestamps" ] } ], "data_elements": [ { "id": "ovs-affordance", "name": "Oversight affordance", "description": "Interface capability supporting understanding, monitoring or interruption.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "ovs-stop-mechanism", "name": "Stop mechanism", "description": "Means by which operation is interrupted or halted.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "ovs-competence", "name": "Overseer competence requirement", "description": "Competence, training or authority required of the assigned overseer.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "ovs-intervention", "name": "Intervention event", "description": "Recorded human override, correction or halt.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [ { "id": "oversight-intervention-log", "name": "Oversight intervention log", "description": "Append-only log of human interventions with type, actor, target activity, event time and ingestion time.", "media_or_form": [ "append-only log", "structured record" ], "serial": true, "identity_strategy": "Sequential entry identifier per agent; each entry references the run or activity identifier issued by the execution system.", "source_refs": [ "SRC-009", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "operating-limits-and-budgets", "name": "Operating limits and budgets", "description": "Caps on steps, tool calls, recursion depth and wall-clock time per task, token, compute and monetary budgets, the concurrency ceiling, and defined breach behaviour.", "source_refs": [ "SRC-013", "SRC-007", "SRC-006" ], "questions": [ { "id": "q-lim-steps", "text": "What limits cap the agent's steps, tool calls, recursion depth and wall-clock time per task?", "kind": "constraint", "answer_data": [ "Maximum step count", "Maximum tool call count", "Task time limit" ] }, { "id": "q-lim-cost", "text": "Which token, compute and monetary budgets apply, and what happens when they are exhausted?", "kind": "measurement", "answer_data": [ "Budget quantity and unit", "Budget window", "Exhaustion behaviour code" ] }, { "id": "q-lim-concurrency", "text": "How many concurrent tasks and sessions may the agent hold, and how is contention resolved?", "kind": "state", "answer_data": [ "Concurrency ceiling", "Queueing or shedding policy", "Priority rule" ] }, { "id": "q-lim-breach", "text": "What is the defined behaviour on limit breach: halt, degrade or escalate?", "kind": "exception", "answer_data": [ "Breach action code", "Notification target", "Recovery procedure reference" ] } ], "data_elements": [ { "id": "lim-max-steps", "name": "Maximum steps", "description": "Cap on reasoning or action steps within one task.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "lim-max-tool-calls", "name": "Maximum tool calls", "description": "Cap on tool invocations within one task.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "lim-task-time", "name": "Task time limit", "description": "Wall-clock ceiling for one task.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "lim-cost-budget", "name": "Cost budget", "description": "Token, compute or monetary budget with unit and window.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "lim-concurrency", "name": "Concurrency limit", "description": "Maximum simultaneous tasks or sessions.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "lim-breach-action", "name": "Breach action", "description": "Defined behaviour when a limit is exceeded.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "operating-envelope-specification", "name": "Operating envelope specification", "description": "Specification of step, time, concurrency and cost limits with breach behaviour and notification targets.", "media_or_form": [ "specification document", "machine-enforceable configuration" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; enforced values referenced by the runtime rather than duplicated.", "source_refs": [ "SRC-013", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "run-and-session-linkage", "name": "Run and session linkage", "description": "How an execution record references the exact agent version, which correlation identifiers tie activity into one task, how event time is separated from observation time, and what must be captured for reconstruction.", "source_refs": [ "SRC-011", "SRC-010", "SRC-004", "SRC-003" ], "questions": [ { "id": "q-run-reference", "text": "How does an execution record reference the exact agent version that produced it?", "kind": "relationship", "answer_data": [ "Agent version reference", "Reference mechanism", "Immutability guarantee" ] }, { "id": "q-run-correlation", "text": "Which correlation identifiers tie messages, tool calls and sub-agent activity into one task?", "kind": "interoperability", "answer_data": [ "Conversation identifier", "Task or context identifier", "Parent and child span linkage" ] }, { "id": "q-run-time-separation", "text": "How are event time and observation or ingestion time recorded separately for agent activity?", "kind": "temporal", "answer_data": [ "Event timestamp", "Observation or ingestion timestamp", "Clock source and offset" ] }, { "id": "q-run-replay", "text": "What must be captured so that an agent activity can be reconstructed later?", "kind": "evidence", "answer_data": [ "Required capture field list", "Content recording policy", "Reconstruction test evidence" ] } ], "data_elements": [ { "id": "run-ref", "name": "Run reference", "description": "Reference to an execution record produced by this agent version.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "run-conversation-id", "name": "Conversation identifier", "description": "Correlation identifier for a conversation or thread spanning multiple activities.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "run-task-id", "name": "Task identifier", "description": "Correlation identifier for a task and its context across agents.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "run-event-time", "name": "Event time", "description": "Instant at which the agent activity occurred.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "run-observed-at", "name": "Observation or ingestion time", "description": "Instant at which the record was observed or ingested by the store.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "This finding produces no artefact of its own. It defines reference and correlation semantics carried as inline fields on records owned elsewhere: the execution record is the artefact of WM-AI-004 and the telemetry span is the artefact of the observability finding. Materialising a further artefact here would create a second, divergent copy of run data; only the linkage rules and identifier semantics belong to the agent." } ] } ] }, { "id": "assurance-observability-and-risk", "name": "Assurance, observability and risk", "description": "What is measured before and during service, what is recorded so behaviour can be audited, and what evidence supports risk and conformity claims.", "rationale": "Risk-management guidance requires measurement and management functions; regulation requires activity logging for traceability; telemetry conventions supply a shared attribute vocabulary for agent and tool operations; and published risk taxonomies supply the threat classes an agent deployment must be assessed against.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008", "SRC-011", "SRC-013" ], "layers": [ { "id": "evaluation-and-monitoring", "name": "Evaluation and monitoring", "description": "How the agent is tested before release and watched while in service.", "source_refs": [ "SRC-006", "SRC-007", "SRC-012" ], "findings": [ { "id": "pre-deployment-evaluation", "name": "Pre-deployment evaluation", "description": "Capability, safety and robustness evaluations run against a version, acceptance thresholds and who set them, representativeness of the evaluation set, and evaluation provenance.", "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-evl-suite", "text": "Which capability, safety and robustness evaluations were run against this agent version?", "kind": "measurement", "answer_data": [ "Evaluation suite identifier", "Evaluation scope", "Result summary" ] }, { "id": "q-evl-thresholds", "text": "Which acceptance thresholds must be met for release, and who set them?", "kind": "requirement", "answer_data": [ "Threshold value and unit", "Setting authority reference", "Justification statement" ] }, { "id": "q-evl-representative", "text": "How well does the evaluation set represent the intended operating context?", "kind": "quality", "answer_data": [ "Representativeness assessment", "Known coverage gap list", "Assessing party reference" ] }, { "id": "q-evl-provenance", "text": "When was each evaluation run, on which version, and by whom?", "kind": "provenance", "answer_data": [ "Run timestamp", "Evaluated version reference", "Executing party reference" ] } ], "data_elements": [ { "id": "evl-run", "name": "Evaluation run", "description": "One executed evaluation with suite, scope and configuration.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "evl-metric-result", "name": "Metric result", "description": "Measured value produced by an evaluation.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "evl-threshold", "name": "Acceptance threshold", "description": "Value a metric must meet or exceed for release.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "evl-evaluated-version", "name": "Evaluated version", "description": "Agent version the evaluation was run against.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "evl-evaluated-at", "name": "Evaluated at", "description": "Instant at which the evaluation was executed.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [ { "id": "agent-evaluation-report", "name": "Agent evaluation report", "description": "Report of evaluation suites, metric results, thresholds, representativeness assessment and run provenance for one agent version.", "media_or_form": [ "report document", "structured result set" ], "serial": true, "identity_strategy": "Keyed by agent version identifier plus sequential evaluation run number; result sets referenced by their own run identifiers.", "source_refs": [ "SRC-006", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "in-service-performance-monitoring", "name": "In-service performance monitoring", "description": "Live indicators showing the agent remains inside its accepted envelope, drift detection, the share of activity sampled for human review, and the response when a threshold is crossed.", "source_refs": [ "SRC-006", "SRC-007", "SRC-012" ], "questions": [ { "id": "q-mon-live-metrics", "text": "Which live indicators show that the agent is still performing within its accepted envelope?", "kind": "measurement", "answer_data": [ "Metric identifier", "Baseline value", "Current value and window" ] }, { "id": "q-mon-drift", "text": "How is behavioural drift caused by model, tool or data change detected?", "kind": "state", "answer_data": [ "Drift signal identifier", "Detection method", "Comparison baseline reference" ] }, { "id": "q-mon-sampling", "text": "What proportion of agent activity is sampled for human quality review, and how is the sample selected?", "kind": "quality", "answer_data": [ "Sample rate", "Selection strategy", "Reviewer role" ] }, { "id": "q-mon-response", "text": "What is the defined response when a monitored indicator crosses its alert threshold?", "kind": "process", "answer_data": [ "Alert threshold value", "Response playbook reference", "Escalation target" ] } ], "data_elements": [ { "id": "mon-metric", "name": "Monitored metric", "description": "Indicator tracked while the agent is in service.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "mon-alert-threshold", "name": "Alert threshold", "description": "Value at which a monitored metric raises an alert.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "mon-sample-rate", "name": "Review sample rate", "description": "Proportion of activity selected for human review.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "mon-drift-signal", "name": "Drift signal", "description": "Coded indicator of behavioural drift.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "agent-monitoring-baseline", "name": "Agent monitoring baseline", "description": "Baseline definition of monitored metrics, thresholds, drift signals, sampling strategy and response playbook references.", "media_or_form": [ "structured record", "monitoring configuration" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; superseded baselines retained with their validity windows.", "source_refs": [ "SRC-006", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "evaluation-settings-and-validation-status", "name": "Evaluation, provenance and quality evidence", "description": "NIST AI 800-2 requires evaluations of agent systems to report scaffolding, tool availability, aggregation strategies, agent budget and stopping conditions separately from model inference settings. Quality claims without those settings are not comparable. OWASP assessments provide threat-coverage evidence. Provenance covers who created the agent, from which product or scaffold, and which measurements were observed.", "source_refs": [ "SRC-018", "SRC-019" ], "questions": [ { "id": "evaluation-settings-and-validation-status-q01", "text": "Which inference, scaffolding and task settings were used in the latest evaluation of this agent, and are they sufficient to reproduce the result?", "kind": "measurement", "answer_data": [ "inference_settings", "scaffolding_settings", "task_settings", "reproducibility_flag" ] }, { "id": "evaluation-settings-and-validation-status-q02", "text": "What quality, safety or threat-coverage claims are made for this agent, and which artefacts or probe results support them?", "kind": "quality", "answer_data": [ "claims", "supporting_artifact_ids", "threat_coverage_status" ] }, { "id": "evaluation-settings-and-validation-status-q03", "text": "What validation status does this agent currently hold (unevaluated, draft, passed, failed, waived), and who attested it?", "kind": "validation", "answer_data": [ "validation_status", "attestor_id", "attestation_event_time" ] }, { "id": "evaluation-settings-and-validation-status-q04", "text": "Who created or imported this agent record, from which source system, and at what event versus ingestion times?", "kind": "provenance", "answer_data": [ "created_by", "source_system", "creation_event_time", "ingestion_time" ] } ], "data_elements": [ { "id": "evaluation-settings-and-validation-status-data01", "name": "Evaluation settings", "description": "Inference, scaffolding and task settings per NIST AI 800-2.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "evaluation-settings-and-validation-status-data02", "name": "Validation status", "description": "Current evaluation or assurance status of the agent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018" ] }, { "id": "evaluation-settings-and-validation-status-data03", "name": "Provenance block", "description": "Creator, source system, event time and ingestion time.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-018" ] } ], "artifacts": [ { "id": "evaluation-settings-and-validation-status-artifact01", "name": "Agent evaluation report", "description": "Report of benchmark or probe results with scaffolding, budget, stopping condition and threat coverage.", "media_or_form": [ "evaluation-report", "evidence-pack" ], "serial": true, "identity_strategy": "Keyed by evaluation report identifier issued by the evaluating system; agent id is a foreign key.", "source_refs": [ "SRC-018", "SRC-019" ] } ], "inline_only_rationale": null } ] }, { "id": "observability-and-audit", "name": "Observability and audit", "description": "What the agent emits so its behaviour can be traced, and how incidents and exceptions are handled and fed back.", "source_refs": [ "SRC-011", "SRC-008", "SRC-002", "SRC-006" ], "findings": [ { "id": "telemetry-and-audit-record-conformance", "name": "Telemetry and audit record conformance", "description": "The attribute schema emitted for agent invocations and tool executions, events that must be logged, controls on recording message content, and log protection and retention.", "source_refs": [ "SRC-011", "SRC-008", "SRC-002" ], "questions": [ { "id": "q-tel-schema", "text": "Which telemetry attribute schema is emitted for agent invocations and tool executions?", "kind": "interoperability", "answer_data": [ "Attribute namespace and version", "Operation name values", "Stability level of the convention" ] }, { "id": "q-tel-completeness", "text": "Which events must be logged so that agent activity remains traceable for its whole lifetime?", "kind": "requirement", "answer_data": [ "Required event list", "Minimum field set per event", "Coverage verification method" ] }, { "id": "q-tel-content", "text": "Which message content may be recorded in telemetry, and how is sensitive content redacted?", "kind": "privacy", "answer_data": [ "Content recording mode", "Redaction rule", "Approving authority reference" ] }, { "id": "q-tel-integrity", "text": "How are logs protected from tampering, and for how long are they kept?", "kind": "security", "answer_data": [ "Integrity mechanism", "Access restriction", "Log retention period" ] } ], "data_elements": [ { "id": "tel-attribute-set", "name": "Telemetry attribute set", "description": "Attribute keys emitted for agent and tool operations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "tel-required-event", "name": "Required log event", "description": "Event type that must be logged for traceability.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "tel-redaction-rule", "name": "Redaction rule", "description": "Rule governing removal or masking of sensitive content in logs.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "tel-log-retention", "name": "Log retention period", "description": "Duration for which agent logs are retained.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "tel-log-integrity", "name": "Log integrity method", "description": "Mechanism making log records tamper-evident.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "agent-telemetry-profile", "name": "Agent telemetry profile", "description": "Profile declaring emitted attributes, required events, content recording mode, redaction rules, integrity mechanism and log retention.", "media_or_form": [ "structured record", "telemetry configuration" ], "serial": false, "identity_strategy": "Keyed by agent identifier plus version identifier; attribute keys referenced by their governed external names.", "source_refs": [ "SRC-011", "SRC-008" ] } ], "inline_only_rationale": null }, { "id": "incident-and-exception-management", "name": "Incident and exception management", "description": "What counts as an incident, near miss or serious malfunction, reporting recipients and deadlines, pre-authorised containment actions, and feedback into policy and classification.", "source_refs": [ "SRC-008", "SRC-006", "SRC-013" ], "questions": [ { "id": "q-inc-definition", "text": "What counts as an agent incident, near miss or serious malfunction?", "kind": "definition", "answer_data": [ "Incident class definition", "Severity scale", "Inclusion and exclusion examples" ] }, { "id": "q-inc-reporting", "text": "To whom and within what deadline must an incident be reported?", "kind": "process", "answer_data": [ "Recipient list", "Reporting deadline", "Report content template reference" ] }, { "id": "q-inc-containment", "text": "Which containment actions are pre-authorised without further approval?", "kind": "authority", "answer_data": [ "Pre-authorised action list", "Authorising policy reference", "Actor role permitted to execute" ] }, { "id": "q-inc-feedback", "text": "How does an incident feed back into agent policy, limits or classification?", "kind": "decision", "answer_data": [ "Corrective change reference", "Decision owner", "Effective change timestamp" ] } ], "data_elements": [ { "id": "inc-record", "name": "Incident record", "description": "Structured account of an agent incident or near miss.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "inc-severity", "name": "Incident severity", "description": "Coded severity assigned to an incident.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "inc-reporting-deadline", "name": "Reporting deadline", "description": "Maximum time from detection to required report.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "inc-containment-action", "name": "Containment action", "description": "Pre-authorised action to limit incident impact.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "inc-corrective-change", "name": "Corrective change reference", "description": "Reference to the policy, limit or classification change made after an incident.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "agent-incident-record", "name": "Agent incident record", "description": "Record of one incident with classification, severity, timeline, containment actions, reports issued and corrective changes.", "media_or_form": [ "structured record", "incident report document" ], "serial": true, "identity_strategy": "Incident identifier issued by the incident management system; referenced from the agent record rather than duplicated.", "source_refs": [ "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "risk-and-conformity-evidence", "name": "Risk and conformity evidence", "description": "The threats the deployment has been assessed against and the documentation that supports risk acceptance and any framework alignment claim.", "source_refs": [ "SRC-006", "SRC-007", "SRC-013", "SRC-008" ], "findings": [ { "id": "threat-model-and-conformity-evidence", "name": "Threat model and conformity evidence", "description": "Agent-specific threats assessed, residual risks accepted and by whom, the documentation demonstrating alignment to an applicable framework, and the currency of the assessment.", "source_refs": [ "SRC-013", "SRC-006", "SRC-007", "SRC-008" ], "questions": [ { "id": "q-rsk-threat-model", "text": "Which agent-specific threats has this deployment been assessed against?", "kind": "security", "answer_data": [ "Threat entry identifier", "Taxonomy reference and version", "Affected component" ] }, { "id": "q-rsk-residual", "text": "Which residual risks are accepted, by whom, and with what compensating controls?", "kind": "decision", "answer_data": [ "Residual risk statement", "Accepting party reference", "Compensating control list" ] }, { "id": "q-rsk-conformity", "text": "Which documentation set demonstrates alignment to the applicable framework or regulation?", "kind": "evidence", "answer_data": [ "Document set reference", "Framework and clause mapping", "Evidence completeness assessment" ] }, { "id": "q-rsk-currency", "text": "When was the risk assessment last refreshed, and what triggers a re-assessment?", "kind": "temporal", "answer_data": [ "Assessment date", "Re-assessment trigger list", "Next scheduled review" ] } ], "data_elements": [ { "id": "rsk-threat-entry", "name": "Threat entry", "description": "One assessed threat with its taxonomy reference.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "rsk-residual-acceptance", "name": "Residual risk acceptance", "description": "Recorded acceptance of a residual risk with accepting party and rationale.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "rsk-control-mapping", "name": "Control mapping", "description": "Mapping from a framework clause to the implementing control and its evidence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "rsk-assessment-date", "name": "Assessment date", "description": "Calendar date on which the risk assessment was completed.", "value_kind": "date", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "rsk-reassessment-trigger", "name": "Re-assessment trigger", "description": "Condition that forces the risk assessment to be redone.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] } ], "artifacts": [ { "id": "agent-risk-and-conformity-dossier", "name": "Agent risk and conformity dossier", "description": "Dossier holding the threat model, residual risk acceptances, control-to-clause mapping and supporting evidence for alignment claims.", "media_or_form": [ "document set", "structured evidence index" ], "serial": true, "identity_strategy": "Keyed by agent identifier plus sequential assessment number; supersedes prior dossiers without deleting them.", "source_refs": [ "SRC-006", "SRC-007", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "register-agent-definition", "name": "Register agent definition", "description": "Create the authoritative agent record, assign its identifier per the identity priority and bind it to an accountable owner and a regulatory role determination.", "inputs": [ "Proposed designation and purpose statement", "Accountable organisation and role references", "Jurisdiction scope", "Constituent bindings" ], "outputs": [ "Agent identity record", "Assigned authoritative identifier", "Initial lifecycle state entry" ], "preconditions": [ "An accountable organisation is named", "A regulatory role and risk determination exists for each jurisdiction", "No existing record already claims the same authoritative identifier" ], "effects": [ "The agent becomes citable by other models and records", "An append-only lifecycle history is opened with an RFC 3339 entry instant" ], "source_refs": [ "SRC-011", "SRC-010", "SRC-006", "SRC-008" ] }, { "id": "publish-capability-descriptor", "name": "Publish capability descriptor", "description": "Emit the externally retrievable descriptor listing identity, declared skills, modalities, protocol revisions, endpoints and security schemes, signed so consumers can verify origin.", "inputs": [ "Agent version manifest", "Skill declarations and modalities", "Protocol bindings and endpoints", "Signing key reference" ], "outputs": [ "Published agent descriptor", "Descriptor digest and signature", "Discovery endpoint response" ], "preconditions": [ "The agent version is in a state permitting external exposure", "Each declared skill has supporting evaluation evidence or is marked unevidenced" ], "effects": [ "External consumers can discover and verify the agent's capability surface", "Any later change to declared capability invalidates the published digest" ], "source_refs": [ "SRC-010", "SRC-001", "SRC-005" ] }, { "id": "grant-delegated-authority", "name": "Grant delegated authority", "description": "Record a delegation from a principal to the agent with an explicit scope, resource audience, non-delegable exclusions and validity window.", "inputs": [ "Granting principal reference", "Requested scope set and resource audiences", "Validity window", "Non-delegable exclusion list" ], "outputs": [ "Delegation grant record", "Updated credential scope map" ], "preconditions": [ "The granting principal holds the authority being delegated", "The requested scope is the minimum required for a declared skill", "Target resource audiences are canonical and resolvable" ], "effects": [ "The agent may act on behalf of the principal within the recorded scope until expiry or revocation", "The delegation chain depth increases by one for any onward sub-delegation" ], "source_refs": [ "SRC-003", "SRC-002", "SRC-005", "SRC-012" ] }, { "id": "revoke-agent-authority", "name": "Revoke agent authority", "description": "Withdraw a delegation or credential immediately and propagate the revocation to sub-agents and dependent grants.", "inputs": [ "Grant or credential reference", "Revocation reason code", "Revoking party reference" ], "outputs": [ "Updated revocation state", "Revocation event record", "List of affected downstream grants" ], "preconditions": [ "The revoking party is the granting principal or an authorised administrator" ], "effects": [ "The agent can no longer present the revoked authority", "Downstream sub-delegations derived from the grant are marked invalid" ], "source_refs": [ "SRC-002", "SRC-012", "SRC-009" ] }, { "id": "evaluate-release-readiness", "name": "Evaluate release readiness", "description": "Run the required evaluations against a candidate agent version and compare results with the acceptance thresholds set by the responsible authority.", "inputs": [ "Candidate agent version reference", "Evaluation suite references", "Acceptance threshold set" ], "outputs": [ "Agent evaluation report", "Pass or fail determination per threshold", "Coverage gap list" ], "preconditions": [ "The candidate version manifest is frozen", "Thresholds are recorded with their setting authority" ], "effects": [ "A release gate can be decided on recorded evidence", "Coverage gaps are carried forward into the risk dossier" ], "source_refs": [ "SRC-006", "SRC-007", "SRC-008" ] }, { "id": "transition-lifecycle-state", "name": "Transition lifecycle state", "description": "Move the agent to a new governed lifecycle state, recording actor, reason, guard evidence and the entry instant.", "inputs": [ "Target state code", "Acting party reference", "Guard evidence references" ], "outputs": [ "New lifecycle state entry", "Updated derived current state" ], "preconditions": [ "The transition is legal under the recorded state machine", "All preconditions for the target state are evidenced", "The acting party holds the authority for that transition" ], "effects": [ "The agent's operational permissions change with the state", "Prior state entries remain immutable in the append-only history" ], "source_refs": [ "SRC-006", "SRC-008", "SRC-004" ] }, { "id": "record-oversight-intervention", "name": "Record oversight intervention", "description": "Capture a human override, correction, pause or halt with the intervening party, the affected activity and both event and ingestion times.", "inputs": [ "Intervention type code", "Intervening party reference", "Affected run or activity identifier", "Reason statement" ], "outputs": [ "Oversight intervention log entry", "Post-stop state description", "Optional incident linkage" ], "preconditions": [ "The intervening party is an authorised overseer", "The affected activity is identifiable by a correlation identifier" ], "effects": [ "The agent's activity is interrupted or corrected as recorded", "Evidence of effective human oversight is preserved for audit" ], "source_refs": [ "SRC-009", "SRC-008", "SRC-011" ] }, { "id": "emit-agent-activity-telemetry", "name": "Emit agent activity telemetry", "description": "Emit conformant telemetry for agent invocation and tool execution operations, applying the content recording mode and redaction rules.", "inputs": [ "Operation name", "Agent identifier and version reference", "Correlation identifiers", "Content recording mode" ], "outputs": [ "Telemetry span or record set", "Redaction outcome summary" ], "preconditions": [ "A telemetry profile is bound to the agent version", "Redaction rules are approved by the data steward" ], "effects": [ "Agent activity becomes traceable against a shared attribute vocabulary", "Event time and ingestion time are recorded separately on each record" ], "source_refs": [ "SRC-011", "SRC-004", "SRC-008" ] }, { "id": "apply-retention-and-erasure", "name": "Apply retention and erasure", "description": "Enforce the retention schedule across agent records, logs and memory, honouring legal holds and verifying deletion across replicas and backups.", "inputs": [ "Retention schedule entries", "Deletion trigger event", "Legal hold status" ], "outputs": [ "Deletion verification record", "Tombstone entries for erased items", "Exception list where deletion was blocked" ], "preconditions": [ "No legal hold or open incident references the target items", "The retention clock start event is recorded" ], "effects": [ "Expired items are removed from all copies or reported as exceptions", "Identity and audit history survive erasure of the underlying content" ], "source_refs": [ "SRC-008", "SRC-007", "SRC-006" ] }, { "id": "search-agent-directory", "name": "Search agent directory", "description": "Query AMS white pages or DF yellow pages with a partial description template and search constraints.", "inputs": [ "description template", "search-constraints (max-depth, max-results, search-id)", "caller credentials" ], "outputs": [ "matching ams-agent-descriptions or df-agent-descriptions", "empty set if none match" ], "preconditions": [ "Caller is permitted to see matching entries" ], "effects": [ "No state change; may federate to other DFs when max-depth allows" ], "source_refs": [ "SRC-015" ] }, { "id": "bind-or-unbind-agent-tools", "name": "Bind or unbind tools", "description": "Attach or detach MCP tools and resources to the agent's standing inventory, with consent and schema validation requirements.", "inputs": [ "agent identifier", "tool definitions or names", "consent policy", "caller credentials" ], "outputs": [ "updated tool registry", "optional list-changed notification" ], "preconditions": [ "Caller is authorised", "Tool names satisfy uniqueness and safety constraints", "User consent policy is defined for newly bound tools" ], "effects": [ "Standing tool set changes", "Subsequent runs see the new inventory", "Audit log records the change" ], "source_refs": [ "SRC-001" ] }, { "id": "deregister-agent-directory-entry", "name": "Deregister agent", "description": "Remove AMS and DF descriptions so the AID can be released and message delivery no longer targets the agent.", "inputs": [ "master-system agent identifier", "authorising principal" ], "outputs": [ "deregistration result", "released AID notice" ], "preconditions": [ "Agent is registered", "Caller is authorised or is the AMS enforcing destroy" ], "effects": [ "Directory entries are removed", "Further search no longer returns the agent", "AID may be reused only according to platform policy" ], "source_refs": [ "SRC-015" ] } ], "composition": [ { "target": "WM-AI-001 (AI system)", "relation": "COMPOSE", "purpose": "An AI system exposes one or more agent actors. System-level obligations, model inventory and market placement remain in WM-AI-001; actor-level authority, tool bindings, memory and oversight remain here so the two are not duplicated.", "required": false, "source_refs": [ "SRC-008", "SRC-006" ] }, { "target": "WM-AI-005 (prompt or agent configuration)", "relation": "REFERENCE", "purpose": "The agent references the instruction or configuration artefact that governs its behaviour, with a version and pin mode. Instruction text, templating and variables are modelled there, not here.", "required": true, "source_refs": [ "SRC-001", "SRC-006" ] }, { "target": "WM-AI-004 (agent run or execution record)", "relation": "REFERENCE", "purpose": "Each execution record references the exact agent version that produced it, giving execution provenance. Spans, messages, token usage and outcomes belong to WM-AI-004.", "required": false, "source_refs": [ "SRC-011", "SRC-003" ] }, { "target": "WM-PER-003 (parent actor or person model)", "relation": "CHILD", "purpose": "The AI agent specialises the generic responsibility-bearing actor. Human principals, approvers and overseers are recorded there and referenced from delegation and accountability findings.", "required": false, "source_refs": [ "SRC-003", "SRC-008" ] }, { "target": "W3C PROV-O provenance vocabulary", "relation": "ALIGN", "purpose": "Align agent, activity, entity, attribution, association, delegation and derivation semantics with a published provenance ontology rather than inventing local provenance terms. Alignment only; no conformance is claimed.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "OpenTelemetry GenAI semantic conventions for agent spans", "relation": "ALIGN", "purpose": "Align agent and tool operation naming and identifier attributes with a shared telemetry vocabulary. The convention is at Development stability, so the alignment is advisory and versioned separately.", "required": false, "source_refs": [ "SRC-011" ] }, { "target": "A2A Agent Card and task lifecycle", "relation": "ALIGN", "purpose": "Align published capability advertisement, skills, modalities, security schemes and card signatures with an inter-agent discovery format. The card name is treated as an alias, never a primary key.", "required": false, "source_refs": [ "SRC-010" ] }, { "target": "Model Context Protocol tool and resource primitives and authorization", "relation": "ALIGN", "purpose": "Align tool and resource binding semantics, consent requirements, revision negotiation and audience-bound token handling with a published tool-integration protocol.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Regulation (EU) 2024/1689 provider and deployer obligations", "relation": "ALIGN", "purpose": "Align role determination, risk classification, logging for traceability, human oversight and transparency findings with the applicable regulatory obligations where the agent falls in scope.", "required": false, "source_refs": [ "SRC-008", "SRC-009" ] }, { "target": "NIST AI RMF 1.0 and the Generative AI Profile", "relation": "ALIGN", "purpose": "Align governance, mapping, measurement and management findings with a voluntary risk framework and its generative-AI companion, noting that neither squarely covers tool-using autonomous agents.", "required": false, "source_refs": [ "SRC-006", "SRC-007" ] }, { "target": "NIST SP 800-207 zero trust access policy", "relation": "ALIGN", "purpose": "Align per-request authorisation, least privilege and continuous verification of agent actions with zero-trust tenets rather than a bespoke local access theory.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "Tool or external service model (sibling; no registry identifier assigned in the supplied extract)", "relation": "REFERENCE", "purpose": "Tool schemas, endpoint contracts and operators belong to a separate subject that this model only references. Marked as an unresolved boundary because the sibling model identifier was not present in the registry extract.", "required": false, "source_refs": [ "SRC-001", "SRC-013" ] }, { "target": "Embodied or robotic agent extension (not registered)", "relation": "EXTEND", "purpose": "Physical siting, actuation safety and mechanical harm surfaces are outside this model. An extension would be required before applying WM-AI-002 to embodied agents; recorded as a gap rather than asserted as covered.", "required": false, "source_refs": [ "SRC-006", "SRC-008" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension MUST name a single accountable owner package for WM-AI-002 records and publish the owning organisation and role before any agent record is created.", "The owner package MUST declare which identifier system is authoritative for agent identity in that Dimension and how it maps to protocol-scoped identifiers such as agent-card names and provider-assigned agent identifiers.", "The owner package MUST declare jurisdictional scope and the regulatory role held per deployment, since obligations differ between provider and deployer.", "The owner package MUST publish retention classes, the policy decision point used for action authorisation, and the escalation route for agent incidents." ], "namespace_guidance": "Mint agent identifiers in a stable HTTPS namespace owned by the Dimension, of the form /world-model/ai/agent/{agent-id}, with version-scoped children of the form .../{agent-id}/version/{version-id}. Never derive a namespace from a mutable display name, an endpoint hostname or a release date. Protocol-scoped names and endpoint URIs are aliases recorded inside the agent's namespace, not primary identifiers, and canonical resource URIs used for token audience binding are kept lowercase, fragment-free and separate from the identity namespace.", "registry_links": [ "Vercy world-model registry entry vr.wm-ai-002 and its composition links", "Local tool and server allowlist registry referenced by tool bindings", "Credential, scope and delegation registry referenced by authority grants", "External alignment registries: the OpenTelemetry GenAI attribute registry and the A2A Agent Card schema", "Incident management register referenced by incident records" ] }, "canon_and_patch": { "canonicalization_rules": [ "Serialise records as UTF-8 with lexicographically ordered object keys and no insignificant whitespace before hashing or signing; digests are computed over the canonical form, never over a storage projection.", "Normalise all time values to RFC 3339 with seconds and an explicit offset or Z before comparison, retaining the original offset when local civil time is meaningful.", "Resolve every alias to its primary identifier before equality or deduplication tests; alias tables are inputs to canonicalisation, not substitutes for it.", "Normalise endpoint and resource URIs to lowercase scheme and host with no fragment and no trailing slash unless the slash is semantically significant.", "Represent absent values by omitting the field rather than by empty strings or null placeholders, so that digests are stable across projections." ], "patch_rules": [ "Patches address content by stable local identifier path, never by array position or display name.", "A patch that would change a field frozen at release MUST create a new agent version instead of mutating the existing one.", "Every patch carries the acting party, a reason, the event time and the ingestion time, and is retained at least as long as the record it modifies.", "Patches to authority scope, tool bindings, memory scope or autonomy level require re-approval by the accountable owner before they take effect.", "Lifecycle transitions and log entries are appended, never patched; corrections are new entries that supersede prior ones by explicit reference." ], "compatibility_rules": [ "Adding an optional field or a new code value is backwards compatible; removing a field, narrowing cardinality or changing the meaning of an existing code is breaking and requires a major model version.", "Consumers MUST ignore unknown fields and MUST NOT infer semantics from field order or from a storage projection's structure.", "Alignments to external standards are versioned independently of this model; upgrading an alignment target never silently changes local semantics and must be recorded as an explicit change.", "A protocol revision change in a bound interface is treated as a material change to the agent version, because available primitives differ between revisions." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record for the agent, such as the deployment platform's agent registry identifier or a provider-assigned hosted agent identifier.", "Governed global identifier or IRI minted in the owning Dimension's HTTPS namespace and resolvable to the agent identity record.", "UUID or ULID assigned by the adopting Dimension when neither of the above exists, recorded together with the reason no governed identifier was available.", "Protocol-scoped names, endpoint URIs and display names are aliases only and MUST NOT be used as primary keys; a release date, version date or any other date is never an identifier.", "Transient in-memory agent instance identifiers MUST NOT be promoted to primary keys, because they do not survive the process that created them." ], "timestamp_rule": "All time values use RFC 3339 with explicit seconds and an explicit UTC offset or the literal Z; a local time without an offset is rejected on ingest. Event time, meaning the instant the agent activity, decision or state transition actually occurred, is recorded separately from observation or ingestion time, meaning the instant the record reached the store, and both are stored whenever they differ. Memory items additionally carry an observation time distinct from their write time. Durations use ISO 8601 duration form and are never substituted for a timestamp; a date-only value is used only where the source is genuinely date-granular and is never treated as an instant.", "serial_naming_rule": "Serial artefacts are named ----, with a monotonically increasing sequence per agent and artefact kind, starting at 000001. Sequence numbers are never reused after deletion or supersession, gaps are permitted and meaningful, and no date, timestamp or version-date component appears anywhere in the name.", "integrity_rule": "Each artefact stores a digest of its canonical form together with the identifier of the signer or issuing process and the digest algorithm. Artefacts published for external discovery are signed, and consumers MUST verify both digest and signature before trusting any capability, skill or tool description they contain. Tool descriptors, agent cards and retrieved context are treated as untrusted content regardless of digest validity: a valid signature proves origin, not safety." }, "policies": [ "Least privilege by default: an agent holds no authority that has not been explicitly granted, scoped to a named resource audience and bounded in time.", "No token pass-through: a credential presented to the agent MUST NOT be forwarded unchanged to a downstream service; downstream access uses a separately issued, audience-bound credential.", "Consent before consequential action: operations with irreversible or externally visible effects require an explicit, recorded human approval unless a standing authorisation covers exactly that action class.", "Traceability: every authority change, tool binding change, lifecycle transition and human intervention is recorded with the acting party, event time and ingestion time.", "Untrusted descriptor content: tool descriptions, agent cards, memory items and retrieved context are treated as data, never as authority-granting instructions.", "No conformance without evidence: alignment to an external standard may be asserted only with a cited clause mapping and dated test or assessment evidence.", "Least privilege on tools, directory data and extended Agent Cards; undeclared A2A capabilities must be rejected.", "Human consent and a denial path are required before invoking tools that execute code or exfiltrate data.", "Goal, mandate and policy changes are audited and cannot be performed by the agent on its own standing charter without an authorised principal.", "No conformance claim to ISO, FIPA, A2A, MCP or the EU AI Act without linked evidence.", "Memory stores are integrity-protected against poisoning and are opaque to A2A peers by default." ], "crud": { "read": [ "Any authenticated Dimension member may read agent identity, designation, declared skills, protocol bindings and current lifecycle state.", "Reading credential scope maps, delegation grants, memory inventories, incident records or authorisation policies requires an explicit scope grant and is logged.", "External consumers read only the published capability descriptor; internal policy, evaluation and risk records are never exposed through the discovery endpoint." ], "create": [ "Creating an agent record requires an accountable owner, a regulatory role determination per jurisdiction, and an initial lifecycle state entry with an RFC 3339 entry instant.", "Creation assigns the identifier per the identity priority and records which system issued it and why lower-priority schemes were not used.", "Tool bindings, delegations and credentials may only be created against an existing agent version that is not retired." ], "update": [ "Non-material updates patch the current version in place with full patch provenance including actor, reason, event time and ingestion time.", "Material updates to instructions, tool bindings, authority scope, autonomy level or bound protocol revision create a new agent version and reset release approval.", "Lifecycle transitions, consent decisions and interventions are appended as new entries; the previous entry is never edited in place." ], "delete": [ "Agent records are retired, not deleted; retirement preserves identity, version history and audit records for the applicable retention period.", "Hard deletion is permitted only for data subject erasure or unlawful content, is scoped to the affected items, and leaves a tombstone recording what was removed, under which authority and when.", "Deletion is blocked while a legal hold, open incident or active investigation references the record, and the block is reported as a retention exception rather than silently ignored." ] }, "roles": [ { "name": "Agent owner (accountable deployer)", "responsibilities": [ "Hold named accountability for the agent in production", "Approve authority grants, tool bindings and autonomy level", "Sign residual risk acceptances and release decisions" ] }, { "name": "Agent builder and maintainer", "responsibilities": [ "Author and maintain the agent definition and its constituent bindings", "Submit versions for release approval with evidence attached", "Keep capability descriptors and documentation current with the released version" ] }, { "name": "Oversight operator", "responsibilities": [ "Monitor live agent behaviour against the accepted envelope", "Exercise intervention, pause and stop authority", "Record interventions with reason, affected activity and timing" ] }, { "name": "Risk and compliance reviewer", "responsibilities": [ "Validate regulatory role, risk classification and disclosure duties", "Review evaluation evidence and the conformity dossier", "Trigger re-assessment when a re-assessment condition occurs" ] }, { "name": "Identity and access administrator", "responsibilities": [ "Issue, scope, rotate and revoke agent credentials and delegations", "Enforce audience binding and the prohibition on token pass-through", "Review break-glass grants independently of the requester" ] }, { "name": "Data steward", "responsibilities": [ "Approve data categories, purposes, memory scope and isolation boundaries", "Approve redaction rules for telemetry content recording", "Own the retention schedule and authorise erasure and legal holds" ] } ], "access": { "default_rule": "Deny by default. Access to any node is granted per request to an authenticated subject holding an explicit grant for that scope; no access is inherited from network location, asset ownership, session age or from holding a grant on a different node.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Break-glass read of authority, credential and memory findings during a live incident: time-boxed, dual-approved, and fully logged with automatic expiry.", "Regulator, auditor or supervisory-authority read access to classification, oversight, log and conformity findings under a recorded legal basis and a defined scope.", "Public read of the published capability descriptor artefact only, carrying no internal identifiers, policy content or evaluation detail.", "Data subject access to memory items about that subject, mediated by the data steward and limited to items attributable to the requester.", "Public discovery fields on a published Agent Card or DF description are readable without authentication when the publisher marked them public.", "AMS may read and destroy any resident agent for platform safety.", "Break-glass access by a security reviewer is allowed for incident response and must be audited." ], "audit_requirements": [ "Every read of a credential, delegation, memory inventory, authorisation policy or incident node is logged with subject, grant reference, event time and ingestion time.", "Every grant, revocation, scope change and break-glass use is logged and reviewed by a party independent of the requester.", "Audit logs are tamper-evident and retained at least as long as the records they describe, and their own access is logged.", "Discrepancies between granted scope and observed access are reported as exceptions and fed into the incident process.", "Record actor, action, target scope, outcome, event time and ingestion time for register, modify, lifecycle, mandate, tool-bind, evaluate and decommission.", "Retain audit records independently of DF leases and of agent destroy, for the stated retention period or legal hold." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner and accountable role", "Identifier authority and namespace", "Retention and deletion policy URL", "Alignment and conflict register URL" ], "read_order": [ "AGENTS.md - bootstrap contract, identity of the model and pointers to every other required document", "Specification URL - model scope, boundaries, bundle, layer and finding structure and question surface", "Storage type URL - the concrete projection in use and its canonicalisation, patch and integrity rules", "Interface URL - access interface, scopes, authentication and the discovery endpoint contract", "Processes URL - CRUD, lifecycle, approval, oversight, incident and retention processes", "Registry entry vr.wm-ai-002 - composition links, sibling models and unresolved boundaries" ] } }, "coverage": { "claim": "Merged model covers the AI agent as a durable, versioned, governed non-human actor: identity and version, classification and autonomy, capability, tool and skill surface, discovery and protocol bindings, delegated authority, credentials and consent gates, memory and data governance, lifecycle, directory registration, runtime limits and oversight, telemetry, incident and assurance evidence. Coverage is claimed only against the retrieved evidence set as of 2026-08-26, as alignment and never as conformance. It is not complete for embodied or robotic agents, agent commerce and payment mandates, multi-agent coalition or emergent behaviour, or FIPA platform semantics beyond registration, lease and directory lookup.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Authoritative identifier, governed namespace, aliases and version identity are modelled, with an explicit rule against transient in-memory identifiers and against dates as identifiers. Residual weakness: no cross-organisation agent identifier registry exists, so global uniqueness is Dimension-local by construction." }, { "dimension": "lifecycle", "status": "covered", "notes": "Append-only state history, legal transitions, production preconditions, suspension triggers, release gates, rollback and decommission obligations are modelled. Concrete state vocabularies are deliberately left to the adopting Dimension because no retrieved source prescribes one for agents." }, { "dimension": "relationships", "status": "covered", "notes": "Delegation chains, principal references, sub-agent composition, model and configuration bindings, run linkage and accountable-party relations are modelled as typed references rather than embedded copies." }, { "dimension": "temporal", "status": "covered", "notes": "RFC 3339 with seconds and explicit offset is mandated; event time is separated from observation or ingestion time, and memory items carry observation time distinct from write time. Validity windows exist for versions, delegations and approvals." }, { "dimension": "provenance", "status": "covered", "notes": "Definition authorship, approval, derivation and attribution use published provenance semantics; memory items and telemetry records carry their own origin and timing. Provenance records themselves are digest-protected." }, { "dimension": "ownership", "status": "covered", "notes": "Accountable organisation and roles, duty separation, escalation contacts, response targets and accountability handover are modelled, together with the regulatory provider or deployer determination per jurisdiction." }, { "dimension": "validation", "status": "covered", "notes": "Pre-deployment evaluation with thresholds, representativeness assessment, conformance test evidence, minimisation checks and frozen-field digest verification are all present. Threshold values themselves are deployment-specific." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default per-request authorisation, four access scopes, break-glass and regulator exceptions, audit requirements, audience-bound credentials and the prohibition on token pass-through are modelled." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention classes, clock start events, deletion triggers and verification across replicas, legal holds, tombstones and conflict resolution between audit duties and erasure rights are modelled. Evidence gap: concrete statutory retention periods were taken from a Commission summary page rather than verified clause by clause in the Official Journal text." }, { "dimension": "interoperability", "status": "covered", "notes": "Protocol bindings and revisions, negotiation and failure behaviour, signed descriptors, shared telemetry attributes and correlation identifiers are modelled. Weakness: the telemetry convention is at Development stability and the agent-card and telemetry identity anchors disagree with each other." }, { "dimension": "autonomy and authority", "status": "covered", "notes": "Autonomy level, archetype, initiative mode, delegation limits, non-delegable authorities and consent gates are modelled, with autonomy re-justified against observed behaviour on a stated interval." }, { "dimension": "memory and state", "status": "covered", "notes": "Store inventory, persistence scope, isolation boundaries, precedence on conflict, write authority, item provenance, poisoning controls and quarantine are modelled as first-class agent context rather than as runtime detail." }, { "dimension": "safety and security", "status": "covered", "notes": "Tool effect classes, provider vetting, untrusted descriptor handling, blast-radius bounds, incident classification and containment, threat modelling and residual risk acceptance are modelled. Threat taxonomy support rests partly on a tier-3 source with a version inconsistency." }, { "dimension": "measurement and cost", "status": "covered", "notes": "Step, tool-call, time, concurrency and budget limits with breach behaviour, plus live metrics, drift signals, alert thresholds and review sampling, are modelled. No retrieved primary source prescribes specific limit values." }, { "dimension": "spatial and physical siting", "status": "gap", "notes": "Location is modelled only as data residency and storage locality, which is adequate for a software agent. Embodied agents needing actuation envelopes, physical siting and mechanical safety are explicitly out of scope and carried as an EXTEND link to an unregistered extension model rather than claimed as covered." } ], "known_omissions": [ "Agent-to-agent trust establishment beyond transport authentication and card signatures: no retrieved primary source defines the trust root, so the model records signature verification without prescribing a trust anchor.", "Statutory log-retention periods and serious-incident reporting deadlines under Regulation (EU) 2024/1689 were derived from the Commission's official summary page rather than verified article by article, because EUR-Lex was not retrievable during this research.", "ISO/IEC 42001 and ISO/IEC 22989 could not be retrieved (HTTP 403), so terminology for agent, autonomy and heteronomy rests on non-ISO sources and no ISO alignment is asserted.", "Embodied and robotic agents, actuation safety and physical harm surfaces are not modelled.", "Agent commerce: payments, contracting, pricing and settlement between agents are not modelled.", "Multi-agent emergent behaviour, coalition formation and market-level effects are only partially reached through delegation-chain and sub-agent findings.", "Model-level properties such as training data, weights and fine-tuning are deliberately excluded and belong to the AI system or model sibling.", "Human competence, training and certification of overseers are referenced but modelled in the person or party sibling, not here.", "No primary ISO or IEC schema for LLM long-term memory, episodic memory or memory-poisoning mitigations beyond OWASP threat language.", "IETF and community drafts (AID DNS discovery, SAMP, A2A WebFinger) are emerging and not treated as canonical.", "NIST CAISI AI Agent Standards Initiative (announced 2026-02-17) has not yet issued a durable identity or authorization standard; this model should be revisited when those deliverables appear.", "OWASP Agentic Skills Top 10 and payment/mandate protocols (for example AP2 or x402) lack sufficient primary, multi-organisation backing in the sources fetched for this run.", "Physical embodiment, swarm orchestration topologies and agent legal personhood are out of scope or unsupported.", "ISO/IEC 42001 AI management systems and ISO/IEC 23894 risk management apply to organisations and systems, not to a single agent record, and were not inlined." ], "conflicts": [ "MCP revision 2026-07-28 lists only Elicitation as a client feature and describes stateless, per-request capability negotiation, whereas revision 2025-06-18 listed Sampling and Roots with stateful connections. Any model that hard-codes MCP client primitives will break across revisions, so this model records protocol primitives as version-scoped bindings rather than as intrinsic agent attributes.", "The MCP authorization chapter used here is published under revision 2025-06-18 while the current revision is 2026-07-28; the cited authorization requirements may have moved. Treated strictly as an alignment, never as a conformance claim.", "OpenTelemetry GenAI agent attributes are marked Development stability, so despite wide adoption they are not a stable interoperability contract and the alignment is advisory.", "Identity anchors disagree across standards: the telemetry convention's agent identifier is provider-assigned and explicitly not for transient instances, the A2A agent-card name is a display-scoped label, and MCP defines no agent identity at all. None is globally unique, so the adopting Dimension must mint its own primary key and treat all three as aliases.", "The OWASP LLM Top 10 page presents a 2026 edition date while listing entry titles from an earlier edition; specific LLM0x identifiers must be re-verified before being cited, so this model cites the taxonomy conceptually rather than by entry number.", "NIST AI 600-1 addresses systems that generate content and does not squarely cover tool-using autonomous agents; relying on it alone as an agent risk taxonomy under-covers tool misuse, delegation-chain accountability and autonomy tiering. This model therefore supplements it with zero-trust and community threat sources and flags the residual gap.", "FIPA AID (immutable name plus addresses/resolvers) versus A2A Agent Card (name, version, supportedInterfaces) versus MCP serverInfo: three identity surfaces, none globally authoritative across ecosystems.", "FIPA requires at least one owner; A2A provider is optional; EU duties attach to providers and deployers of AI systems, not to 'agents'.", "A2A opaque execution hides tools and memory from peers; MCP requires tools to be explicit to the host: both can be true of one agent but must not be collapsed.", "FIPA lifecycle (initiated/active/suspended/waiting/transit) is not the A2A TaskState machine (SUBMITTED/WORKING/COMPLETED/FAILED/CANCELED/REJECTED/INPUT_REQUIRED/AUTH_REQUIRED).", "ISO/IEC 22989 'AI agent' is a concept; the EU AI Act regulates 'AI systems' with autonomy. Claiming that every ISO agent is an EU AI system, or that the Act defines agents, is a category error." ], "regional_assumptions": [ "Regulation (EU) 2024/1689 obligations are assumed only where the agent is placed on the EU market or its output is used in the EU. General application is 2 August 2026, with prohibited practices from 2 February 2025, general-purpose AI governance from 2 August 2025 and certain high-risk categories from 2 December 2027 and 2 August 2028.", "NIST AI RMF, the Generative AI Profile and SP 800-207 are voluntary in the United States unless imposed by contract, procurement condition or a sector regulator.", "Data residency rules, erasure rights and incident-reporting deadlines vary by jurisdiction and are modelled as parameters on the agent record, never as global constants.", "No global agent identifier registry exists in any jurisdiction reviewed, so identifier authority is Dimension-local and cross-organisation resolution depends on alias mapping.", "Sector overlays such as finance, health and critical infrastructure are assumed to add obligations rather than replace those modelled here; none was retrieved or verified during this research.", "EU provider/deployer fields are required in substance only when the exposing system is in territorial scope of Regulation 2024/1689.", "FIPA AMS/DF patterns remain normative in some industrial multi-agent platforms and are treated as an alignment even where LLM-agent products do not implement them.", "A2A well-known Agent Card discovery assumes internet or enterprise HTTP locators; offline or mesh agents need equivalent locators.", "NIST AI 800-2 is an initial public draft of evaluation practice, not a binding US regulation." ], "adversarial_checks": [ "Boundary test: each finding was tested against the question could this be answered entirely inside WM-AI-004 or WM-AI-005. Findings that could were removed or reduced to reference semantics, which is why run and session linkage carries no artefact of its own.", "Counterexample test: a deterministic scripted workflow that calls tools but never initiates action. The archetype and initiative-mode findings classify it out of the agent case rather than forcing agent semantics onto it, confirming the autonomy dimension discriminates rather than decorates.", "Counterexample test: an embodied robot controller. Spatial siting, actuation envelopes and mechanical harm are not covered; this is recorded as a checklist gap and an EXTEND composition link instead of being silently absorbed.", "Unsupported-structure test: candidate layers for agent goals, beliefs and desires, and for agent personality, were rejected because no retrieved authoritative source defines or requires them for an operable agent record. Attractive but unsupported structure was not admitted.", "Identity-abuse test: could a display name, agent-card name or endpoint URL serve as the primary key? Rejected, because the telemetry convention warns against transient identifiers, endpoints are mutable, and card names are display-scoped; all three are recorded as aliases only.", "Conformance-inflation test: every external standard appears as an ALIGN link with an explicit evidence requirement, and a no-conformance-without-evidence policy is stated. No node asserts compliance with any regulation, ISO standard or framework.", "Source-integrity test: two retrieved sources were internally inconsistent or version-mismatched (the OWASP page and the split-revision MCP authorization chapter). Both were downgraded in authority tier or restricted in use rather than cited as settled, and the inconsistencies are recorded as conflicts.", "Verified that A2A TaskState and run transcripts were not modelled as the agent lifecycle.", "Verified that MCP, JSON, Git and MongoDB were treated as projections, not as the agent semantic.", "Verified that ISO 22989, FIPA, A2A, MCP and the EU AI Act are recorded as ALIGN relations without a universal conformance claim.", "Verified that owner/provider/deployer are persons or organisations (WM-PER-003 and legal entities), not the agent itself.", "Verified that dates are not used as identifiers and that event time is separated from observation or ingestion time.", "Marked memory schema, IETF drafts, CAISI future identity work and payment mandates as omissions rather than canonical nodes." ] }, "researchAdjudication": { "providerMode": "dual-provider", "activeProviders": [ "claude", "grok" ], "waivedProviders": [], "providerPolicy": {}, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "Both providers independently classify WM-AI-002 as an entity and agree on the four sibling boundaries: the enclosing AI system (WM-AI-001), the bounded execution record (WM-AI-004), the instruction artefact (WM-AI-005) and the natural person (WM-PER-003). Claude adds two further boundaries (tool or external service, and access-management or credential systems) with source refs, giving the more complete boundary set. Subject is fixed as the durable, versioned agent definition plus the deployment context that makes it operable; transient in-memory instances, run traces, task state machines and prompt bodies stay outside. Grok's registration-centric framing (one AID, one platform, exactly one lifecycle state) is absorbed as deployment context on the same entry rather than split into a second entry, because Claude's scope statement already claims operable deployment context; the definition-versus-registration seam is recorded as a decision and a publication hold, not as a split." }, "decisions": [ { "concept": "Base provider selection", "disposition": "claude as base", "rationale": "Claude carries six sourced boundary notes against four, an explicit in-scope and out-of-scope split, an inline-only rationale where a finding would otherwise duplicate a sibling's artefact, and complete coverage of credentials, consent, oversight, telemetry, incident and conformity evidence. Size was not decisive; boundary completeness and the demonstrated removal of sibling-owned content were." }, { "concept": "Definition versus deployed registration", "disposition": "single entry, seam recorded", "rationale": "Base treats the subject as a versioned definition plus deployment context; the source provider treats it as one registered actor with exactly one platform state. Both are retained on one entry because the base scope statement already claims operable deployment context, but the accepted registration and lease finding attaches to the deployment, not the version, and this must be stated in the draft." }, { "concept": "EU AI Act risk tier attachment", "disposition": "inherited from exposing system", "rationale": "The base asks which regulatory risk tier the agent falls into; the source provider correctly notes the Regulation addresses AI systems and assigns duties to providers and deployers, not to a legal class called agent. Resolved by framing: the agent record carries the determination inherited from the exposing AI system with a reference, never an autonomous legal classification." }, { "concept": "Discovery manifest and locators", "disposition": "accepted", "rationale": "Adds retrieval locator, authenticated extended card tiering and declared interaction capability flags, none of which exist in the base protocol-conformance finding, and all evidence-backed in A2A and FIPA directory practice." }, { "concept": "Directory registration and lease", "disposition": "accepted", "rationale": "Adds AMS registration as an identifier precondition, DF lease expiry as ungoverned disappearance, and directory search visibility. Closes a real hole where base retention rules assume deletion is always a governed act." }, { "concept": "Standing goals and stop criteria", "disposition": "accepted, conditional", "rationale": "Overrides the base adversarial rejection of goals because that rejection was made without the ISO definitional source. Admitted only as goals, exclusions, stop criteria and change authority; beliefs, desires and personality stay rejected. Conditional on ISO clause verification." }, { "concept": "Evaluation settings and validation status", "disposition": "accepted", "rationale": "Adds reproducibility and comparability of evaluation results plus a current attested validation status, both absent from the base evaluation layer, and sourced from the newest agent-specific evaluation practice draft in either pack." }, { "concept": "Scaffolding, budget and decommission", "disposition": "rejected", "rationale": "Two of its three questions duplicate base operating limits and base lifecycle decommission. Its unique contribution, scaffolding disclosure, already enters through the accepted evaluation settings question, so admitting the node would create a second competing budget and retirement surface." }, { "concept": "Delegated authority and oversight mandate", "disposition": "rejected", "rationale": "Fully covered by the base principal and delegation chain, action authorisation policy and human approval and consent gate findings, which are more granular on audience binding, non-delegable authority and approval duration." }, { "concept": "Policy, guardrails and threat posture", "disposition": "rejected", "rationale": "Duplicates base action authorisation policy, threat model and conformity evidence, and data category limits. The underlying agentic threat taxonomy is instead recorded as a source upgrade over the base's version-inconsistent OWASP page." }, { "concept": "Memory and context architecture", "disposition": "rejected", "rationale": "Base already splits store inventory from write integrity with poisoning, provenance and quarantine controls, which is stronger. Peer-facing memory opacity and context-compression semantics are the only genuine deltas and are deferred rather than imported as a competing node." }, { "concept": "Communication protocol profiles", "disposition": "rejected", "rationale": "Overlaps base protocol conformance and base run and session linkage on bindings, versions and correlation identifiers. Its distinctive opaque-execution rule, peer opacity while host tool exposure remains explicit, is deferred as a constraint to attach to an existing finding." }, { "concept": "Ownership, legal roles, access and retention", "disposition": "rejected", "rationale": "Duplicates base regulatory role, accountability assignment, audit conformance and retention findings. Record-level create, read, update and destroy scoping is platform registry meta-governance, not agent-domain semantics." }, { "concept": "Master identity node", "disposition": "rejected as node", "rationale": "Duplicates the base identifier and designation finding. The one genuine delta, an explicit name-equality rule with immutability of the primary name for the agent's lifetime, is deferred as a constraint to add to the existing identity finding rather than a second identity node." }, { "concept": "FIPA platform lifecycle vocabulary", "disposition": "rejected as node, deferred as alignment", "rationale": "Base deliberately leaves the state vocabulary to the adopting Dimension. The FIPA state set and its per-state message buffering policy are a source-backed candidate vocabulary and belong as an alignment on the existing lifecycle finding, not as a rival state machine." }, { "concept": "Kind and autonomy classification test", "disposition": "rejected as node", "rationale": "The base typology finding and its counterexample check already discriminate scripted workflows from agents. The ISO definitional inclusion test is deferred until the ISO clause text is verified from a licensed copy." }, { "concept": "Composition and peer relationship set", "disposition": "rejected as node", "rationale": "Parent system, owner and configuration links duplicate base constituent bindings and accountability findings, and the base models relationships as distributed typed references by design. The lateral peer set is a genuine base-admitted gap and is deferred to research." }, { "concept": "Run and session linkage artefact", "disposition": "retained inline-only", "rationale": "Base correctly emits no artefact here because the execution record and telemetry span are owned by siblings. Nothing in the source provider justifies materialising a second copy of run data on the agent entry." } ], "publicationHolds": [ "Source verification incomplete: every accepted source URL and revision must be re-fetched and pinned before publication, including the two A2A URLs that differ only by trailing slash between providers.", "ISO/IEC 22989 is contested between providers: one reports HTTP 403 and asserts no ISO alignment, the other cites it as a retrieved tier-1 source. No ISO alignment, and no ISO-derived agent or autonomy definition, may be published until the clause text is verified from a licensed copy. The accepted standing-goals finding depends on this.", "EU AI Act citations must be re-verified article by article against the EUR-Lex consolidated text supplied by the source provider, replacing the Commission summary page used by the base, specifically for log retention periods and serious-incident reporting deadlines.", "Model Context Protocol authorization requirements in the base are cited from revision 2025-06-18 while the current revision is 2026-07-28; re-verify every credential, audience-binding and token pass-through statement against the current revision before publishing.", "OWASP material must be cited conceptually only. The base page carries a 2026 edition date over earlier-edition entry titles, and the source provider's agentic taxonomy is self-rated tier 3; no LLM0x or agentic entry identifier may be cited by number until edition numbering is verified.", "OpenTelemetry GenAI agent attributes are at Development stability and NIST AI 800-2 is an initial public draft; both must be published as advisory alignment, never as stable interoperability contracts or binding evaluation requirements.", "Multi-profile validation not performed: the merged model must be exercised against at least an enterprise assistant deployment, a FIPA-style industrial multi-agent platform, and an EU-scope high-risk deployment before publication, since the accepted registration and lease structure has only been validated against the FIPA profile.", "The draft must state explicitly that the EU risk tier and provider or deployer role are inherited from the exposing AI system and are not a legal classification of the agent itself, and that no node asserts conformance to any regulation, standard or framework." ], "deferredResearch": [ "Lateral peer-agent relations: which peers an agent may discover, delegate to or refuse, and the trust root for inter-agent authentication beyond transport security and descriptor signatures. Both providers record this as a gap and neither retrieved a source defining a trust anchor.", "Opaque-execution constraint: whether an agent must withhold internal plans, memory and tool implementations from protocol peers while exposing tools explicitly to its host, and whether that belongs as a constraint on the existing protocol-conformance finding.", "Agent memory schema: no ISO or IEC schema defines working, episodic or long-term agent memory. Investigate context-compression and unbounded-horizon memory and their interaction with stopping conditions, plus peer-facing memory opacity.", "Identity semantics: adopt an explicit name-equality rule and lifetime immutability constraint for the primary identifier on the existing identity finding, and confirm no cross-organisation agent identifier registry exists in any reviewed jurisdiction.", "FIPA platform state vocabulary: decide whether the initiated, active, suspended, waiting and transit state set with per-state message buffering becomes the normative vocabulary or remains an alignment against the adopting Dimension's own states.", "Emerging standards watch: NIST CAISI agent standards deliverables on durable identity and authorization, IETF and community discovery drafts, and agent payment or mandate protocols, none of which had sufficient primary multi-organisation backing in either evidence pack.", "Assess whether the deployed registration warrants a separate entry from the versioned agent definition once the registration and lease structure is exercised against a second platform profile." ] }, "statistics": { "sources": 19, "bundles": 6, "layers": 15, "findings": 32, "questions": 126, "artifacts": 31, "functions": 12 } }