Guidelines  ·  2026-10-09

IETF draft: Signed Permissions and Action Receipts for Automated Agents (draft-izmaylov-agent-permission-receipts-00)

GuidelinesMedium impactGlobal
On 6 October 2026 (last updated 7 October 2026, in the reporting window) a new individual Internet-Draft was submitted to the IETF datatracker: 'Signed Permissions and Action Receipts for Automated Agents' (draft-izmaylov-agent-permission-receipts-00), intended for Standards Track. It specifies records allowing anyone to check, later and offline, what an AI agent was allowed to do and what it recorded doing: a permission a person signs with a passkey and machine-checkable limits; a receipt the agent signs for each action (Ed25519 and post-quantum ML-DSA-87); and a log whose tree head is signed and time-stamped. A verifier determines whether each action stayed within its permission, including helper agents' actions. JWS encoding is noted as non-essential, with COSE and SCITT registration profiles proposed as alternatives; comments are invited via GitHub (provared/provared).
Agentic systems need verifiable, audit-friendly records of permitted vs. actual action. This draft is a concrete proposal for the mechanism (signable permissions + signed per-action receipts + signed/transparent logs + offline verification) that underlies accountability in agentic security, complementing the earlier Agent Audit Trail I-D series (draft-sharif-agent-audit-trail) already tracked by this feed and addressing the excessive-agency problem surfaced in the Q3 2026 exploit roundup.
Agent runtime vendors, audit/GRC tooling vendors, and standards watchers should review and comment (deadline: I-D valid ~6 months, expires 9 April 2027); teams designing agent action-logging can use the content model as a reference for signed, tamper-evident receipts.
IETF Datatracker — draft-izmaylov-agent-permission-receipts-00
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →