Roadmap

Built in public, day by day

A horizontal timeline over roadmap.yaml, the source of truth. Every bar is a real piece of work. Click a workstream to unfold it; click any bar for the full story. Colors are status: shipped, in flight, queued, cut.

Loading the roadmap…

669 roadmap items, grouped by status. Updated from roadmap.yaml. Day 1 is 2026-02-17.

Active (1)

Ship the disclosed gaps: closing the Implementation Status set from -03

Day 152–185 Protocol active

Revision 03 states, for every claim it makes, whether the code runs today or the gap is disclosed in its Implementation Status appendix. This sprint closes the disclosed set: the canonicalization migration for the two named emitters through the parked breaking-change review, a shared ReceiptV1 envelope across the three SDKs, a published DecisionRefV1 computation, all seven facets signed in delegation records, and issuance-path narrowing hardening with stricter adapter verification. Started the day the revision was submitted, because the appendix is what defines the set.

In progress (6)

Lifecycle cases taken to CoSAI, OWASP and AgenTrust

Day 217 outward in_progress

The handover case on the CoSAI decommissioning thread, the denial case back to the OWASP thread it came from, and a delegation verifier for the AgenTrust integrations that keeps receipt evidence and delegation authority as two results.

7.0.0 shipped without npm provenance, and its tag waits for a safe way to add one

Day 216 security in_progress

It was published by hand, so its bytes match and its commit is recorded, but it has no provenance attestation where 6.0.1 did. Both release workflows publish on tag, so a retrospective tag would run a publication pipeline against an existing version. The tag and a dated SECURITY.md note are deferred.

A vocabulary re-date pinned its evidence by revision, tree and digest, and the keys and verifier that give the evidence its meaning were still floating

Day 213 vocabulary in_progress

The commit, tree object and discovery-copy digest all reproduce. Twelve of the twenty-three vectors are deliberate derivations, not artifacts as issued. The runner that reports twenty-three of twenty-three imports the issuer's own verifier, so the result is author-produced inside one trust domain. Its two packages are installed unversioned while the README documents version-dependent verdicts, and twelve vectors resolve keys from a live JWKS endpoint with no snapshot in the tree. Changes requested on the evidence record only. The signal's status, issuer count and promotion trigger are untouched. The refused-vector count is stated with its predicate, because every frozen vector expects an expiry failure and two carry a signed false verdict that is not a verification failure.

Chain narrowing is checked pairwise and skips when either side omits the field

Day 179 Protocol in_progress

Each hop compares a child against the link immediately before it, and every comparison is guarded on both sides carrying the constraint. A link omitting a spend limit or depth ceiling removes the comparison rather than widening anything itself, so the descendant below is measured against nothing. Expiry already refuses this in both implementations, with the reasoning in the source comment. Three dimensions lack the rule. The specification already covers all of it: an unbounded child under a bounded parent is invalid, a missing facet is invalid rather than an implicit unconstrained value, depth decrements per hop, and child validity intervals are contained in their parent's. The gap is implementation, not specification, and the draft's implementation status appendix has stated the wire format lag in public since July.

The enforcement path runs single-phase, so the two-phase claim comes off every surface

Day 178 Protocol in_progress

The deployed configuration evaluates, returns a verdict, and commits spend in one step. The specified model where an approval is minted and then separately consumed before dispatch is not what runs. Recorded as a hard constraint on public language: nothing describes the enforcement here as two-phase, as issuing consumable approvals, or as preventing replay at dispatch, until it is built or the sentence changes. An implementation behind a coherent specification is an ordinary state; describing the gap as closed is not.

Shipped (610)

Authority Lifecycle v0.3.0-draft, one catalog file, a semantic taxonomy and a verification model

Day 220 Research done

cases.json is now the single source of truth for all 170 cases, CASES.md and BOUNDARY-CASES.md are generated from it, and CI fails on drift, on schema violations and on any unresolved internal link. Cases are grouped by the authority question each one asks, in 18 semantic families, rather than by the research leg that found them, and every id is unchanged. 134 lifecycle cases, 126 verified, 7 reviewed hypotheticals and 1 candidate, with 36 boundary cases kept apart under six named reasons. The model adds a verification model naming what a verifier may say about an artifact and what an enforcement point decides about one action. The precedent sources say nothing about AI agents and the repository says so.

Twenty-eight new lifecycle fixture families in the conformance lab, and what the SDK can decide of them

Day 220 conformance done

Tracking issue #122, seven stacked pull requests #123 to #129 and three follow-ups through #132, all merged on green. Every family is labelled candidate against proposed text, so the vectors test wording in the lifecycle repository and not a published specification. Measured against the SDK across 29 families, 633 vectors and 635 decision units, an SDK call reproduced the expected result for 50 units under 7.1.0 and 161 under 7.2.0, a move of 111 units across 12 families with 0 fail and 0 regressions. The remaining 474 are not_supported, meaning no SDK API decides them and the family harness supplies the deciding step. That is not a coverage score for the suite.

Chain selection ships as a draft-03 section 3.3 conformance fix in SDK 7.2.0 and Python 4.2.0

Day 220 Protocol done

Section 3.3 says an action selects one root-to-leaf authority chain and a verifier must not union scopes or budgets across chains. Every other authority entry point took one chain, so the rule had no surface and a pooling implementation was indistinguishable from a selecting one. The new module holds no union by construction. One private function judges one chain, a result names one chain id and never a set, and a held entry that is two chains concatenated into one array is refused by name before verification. An unknown revocation answer is undecided, never refused. 19 parity cases, run byte-identical in both SDKs. The fallback surface is marked proposed, not draft-03.

Seven opt-in lifecycle modules in both SDKs, marked proposed rather than specified

Day 220 sdk done

Lifecycle state, activation, bounds, capability binding, status coverage, authority state and suspension. None is required by draft-03. Each new record type carries a proposed namespace instead of aps, every reason code is module-local, and each module says in its own doc comment that implemented does not mean specified. The state vocabulary reports six artifact verdicts alongside chain verification and never merges into it, keeps what an enforcement point decides at one authorization boundary as three separate outcomes, and requires a not_established verdict to name which of source, freshness or coverage was missing. Existing behaviour is byte identical and the conformance suite output is unchanged under both builds.

Thirty-four lifecycle terms in the vocabulary, a merged delegation verifier, and a canonicalization gap between two A2A SDKs

Day 220 outward done

vocabulary-lifecycle.yaml adds 34 authority-lifecycle concept terms as a separate maintainer-governed file, every definition a verbatim quote of 40 words or fewer from the concept document, filed apart from signal types because a verifier reasons about them rather than an issuer stamping them into an envelope. The AgenTrust delegation verifier merged. The A2A Go maintainers merged a canonicalization fix, which left a2a-python on the other side of the line. Its canonicalizer strips empty strings, lists and dicts before signing with no exception for fields the specification marks REQUIRED, so a card signed by one SDK recomputes to a different payload in the other. Filed as an issue, no patch offered. Two CoSAI WS4 comments went out on the decision-to-effect corpus and on descendant, in-flight and authority-definition questions.

Two questions on the App Defense Alliance tool provenance section, and a note that a refactor would drop it

Day 219 Standards done

Section 2.4.2 of the AI Agent Specification requires refusing revoked tools. Its test does not say whether revocation happens after session setup, and the section does not say what happens when revocation status cannot be established. Filed as two issues. A reformatting pull request cut before the section merged left it out of both new files, and got a short note.

A late approval reaches the replacement invocation in Goose's confirmation router, reproduced on current main

Day 219 outward done

Goose #11739 says approvals are matched only by the provider's request id. A registers, its receiver is dropped, B registers the same id, and the router has already pruned A's closed sender. A late AllowOnce meant for A's prompt still goes to B, so cleanup does not change the result. The same test with a different id passes. The ACP path is keyed the same way, but the existing fixtures could not drive two real stream invocations through that interleaving, so no runtime claim is made there. Tests posted on the issue. The fix belongs to the assigned maintainer.

Two candidate mappings in the lab, one with a script that runs ContextForge's own cache code

Day 219 conformance done

One maps the ASA-WG section to existing revocation families. One maps IBM ContextForge's policy engine requirements to the cached authorization family, and includes a script that loads two ContextForge source files unmodified at a pinned commit and refuses to run otherwise. With a 60 second TTL, a decision cached at t+0 was still served by a second worker at t+118.5, because a Redis hit starts a fresh in-memory TTL. Whether that TTL is meant to be the propagation window in their issue is not established. Neither mapping is a conformance claim.

OpenClaw's hook receives MCP tool names with the transport prefix, shown in a live Claude CLI run

Day 219 outward done

For OpenClaw #155946. A hook matching db__query never fired and the tool ran. The same hook returning requireApproval never fired either. A hook matching mcp__db__query fired, blocked, and the tool never ran. So the name arrives with its prefix, and a matching block lands before the MCP server executes. Evidence only, no fix proposed.

Python 4.1.0 published through a gated workflow with attestations

Day 218 sdk done

The workflow checks the tag equals the version and the commit is on main, runs the full suite (2,127 passed, 6 skipped), then publishes. Wheel and sdist each carry a PEP 740 attestation. A clean install reports 4.1.0.

SDK 7.1.0 exports the delegation issuance functions its own docs pointed at

Day 218 Protocol done

issueAuthorityDelegation, issueSubAuthorityDelegation, scope comparison and budget were documented and not exported from the package root. 7.1.0 exports them, with direct authority revocation and opt-in predecessor binding. Published on npm with provenance. The post-publish check hit a 404 while the registry was processing and passed on rerun.

Twelve lab pull requests merged, most of them revocation and authority cases

Day 218 conformance done

Lab #106 to #117. A revoked ancestor fails a deeper descendant, one agent identity runs under an old and a replacement chain, cached authorization after revocation, denial continuity, approval as a single-use permit, historical key selection, one chain per action on the real scope and budget code, issuer refusal with distinct codes, and candidate cases against the AuthZEN ARAP profile. The two SDK-pinned families were re-recorded on 7.1.0 with only the version string and one new not-checked field allowed to differ.

A WIMSE draft review, one AuthZEN ARAP case, and the first contribution in an AAIF working group

Day 218 Standards done

A review of the WIMSE agent audit record draft on #144. One candidate case against the AuthZEN ARAP profile on #663. A mapping of lab families to the freshness and revocation rules in AAIF Identity and Trust #5.

agent-authority-lifecycle published

Day 217 Research done

Revocation, succession, suspension and handover gathered in one repository, each claim labeled specified, tested, candidate or open.

The gateway published as agent-passport-gateway

Day 217 Product done

Open by default. 245 commits of real history, with deployment details, tenant data and internal notes removed from every revision. The operator email is a setting with no default. The only signed commit is the release commit.

Gateway enforces ancestor revocation across sub-delegation chains

Day 217 security done

A sub-delegation could keep acting after a delegation above it was revoked. Every sub-delegation is now bound to its inbound chain and each ancestor is checked at evaluation time. Reproduced with a four-hop chain before the fix. Production held no active chain longer than one hop. Deployed.

MCP 6.1.0 keeps capability-token replay state across processes and restarts

Day 217 security done

Used tokens are recorded as files on disk, created exclusively so only one process can win. The hosted service keeps them on a volume. Closed only after a live test: redeem, restart with a new process confirmed, redeem the same token, rejected.

Per-claim binding of observation coverage merged into the CoSAI candidate cases

Day 216 conformance done

Coverage now has to be tied to the claim it supports, and matching identifiers alone do not establish the link. The reviewer who raised it confirmed the wording. The cases stay candidates until the workstream adopts the rule.

A hand-copied metric line dropped from INTEGRATION.md

Day 216 Ops done

The values were current. The line went because it was copied by hand.

The lab's oracle-safety corpus re-minted for the stage rules, and the suite pinned to 7.0.0

Day 216 conformance done

All 26 committed receipts failed the new stage validation before the re-mint and none fail after it. The suite now depends on exact 7.0.0, so its lanes run against the released package.

PriorSeal's sibling adapter verified clean and referenced from INTEGRATION.md

Day 216 Ecosystem done

Installed from the registry in a clean environment and checked at the commit its author named, with no corrections.

SDK 7.0.0 and Python 4.0.0 published, both reconciled to draft-03

Day 216 sdk done

Action references, receipts and authority delegation now follow draft-pidlisnyi-aps-03 in TypeScript and Python. Each package was installed clean from its registry and checked against the artifact it was built from. The TypeScript suite runs 5,491 tests with none failing. Major versions for both, because verification results changed shape.

Seven rulings settled where draft-03 was silent or the two SDKs disagreed

Day 216 Protocol done

The required signature set decides a receipt's state, and extra signatures are reported beside it. A key that cannot be resolved, malformed key material included, is indeterminate and never a signature failure. An empty scope_required is rejected by default. No SDK input grammar becomes protocol.

aeoess.com's home became a single interactive line above the four projects

Day 215 site done

The entry chooser was removed. The page makes no new external requests.

Asked to make claim binding explicit, we sent the edited cases and one line

Day 215 conformance done

The reviewer resolved his original objection and asked for coverage tied to the claim in the rule text. The answer was suite PR #98, not another explanation on the thread.

Closure became a gate on the whole surface, with a fourth reason a change may exist

Day 215 process done

A job is judged by whether its surface matches the draft, checked at the end. The fourth reason is implementation hardening, for reliability and resource safety where the protocol does not prescribe the runtime property. One commit carries one reason.

Three dependency updates merged, four SDK bumps held behind the reconciliation

Day 215 Ops done

The CodeQL action pin was checked against its upstream annotated tag before merging.

The insumerapi crosswalk refreshed to the wallet_state block the API issues today

Day 215 vocabulary done

Merged after a clean clone passed its tests and the live key set matched the snapshot committed with #166.

Four PriorSeal fixture inputs delivered, shaped against draft-03 sections 5.3.1, 5.3.2 and 5.4

Day 215 Ecosystem done

Built on an isolated branch cut from 6.0.1, so the reconciliation work was never touched. The adapter's author had held his work waiting for them.

A review loop with no stopping rule ran nine cycles in eleven hours before it was capped

Day 215 process done

A job closed when neither reviewer had an unresolved correctness finding, and each pass found something. The eighth found a real ledger defect, a reservation accepted after a cancel, which belongs to hardening. Closure is now at most two whole cycles, and later findings are classified and carried.

The AEP driver and CoSAI claim binding threads answered without new asks

Day 214 conformance done

A semantic AEP implementation, if one is done, uses the packaged corpus pinned and keeps its first blind run. Per-claim binding belongs in the CoSAI rule text, and its shape stays the workstream's call.

AuthorityDelegationV1 is the draft-03 authority record, and legacy Delegation is a compatibility surface

Day 214 Protocol done

External verifiers should target AuthorityDelegationV1. The older createDelegation and verifyDelegation family stays shipped in both SDKs, off the draft path.

A three-day reconciliation of both SDKs to draft-03 began with a rule-by-rule matrix

Day 214 Protocol done

Every draft-03 rule was checked against both implementations, and each gap was ruled on before code changed. Each change declares one reason: a repair toward the draft, hardening of an existing path, or evolution toward -04. A new rule is never presented as an old one.

A planning note would have put the draft's action reference label on a different digest

Day 214 Protocol done

The Python helper hashes camelCase keys, a sorted scope array and a timestamp truncated to seconds. Section 4.2's form is snake_case with one scope string and milliseconds. The matrix caught it before code moved, and the helper stays documented as pre-draft.

Cross-stack conformance vectors from mcp-audit-gateway merged into the lab

Day 214 conformance done

An external contribution, reviewed and merged by rebase.

PriorSeal will bind APS decision evidence through a sibling adapter

Day 214 Ecosystem done

The proposal to bind APS decision receipts to PriorSeal EVM execution receipts was answered with a separate adapter on published APS surfaces, and its author accepted the direction.

The TRACE action receipt integration went back to draft the day it opened

Day 214 interop done

Its fixture was issued by a gateway where draft-03 requires the acting agent, and its result was free-form where the draft fixes one. It waited for SDKs that enforce both.

The wallet_state re-date merged once its keys and verifier were pinned next to its bytes

Day 214 vocabulary done

Packages versioned with a lockfile, a key set snapshot committed, 23 of 23 from a clean install. The approval corrected an error in our own earlier review of vector 22.

AuthZEN landed an official binding_hash vector directory and cited the larger set offered in July

Day 213 Standards done

The issue that carried the offer closed because the maintainers' own pull request merged a known-answer directory and referenced the larger corpus while doing it. The larger set, thirty-five normative cases, five around unresolved spec decisions and eight rejection cases, recomputed in TypeScript, Python and Go and checked byte for byte against each other, remains available. One comment on the closed issue says so. A diff against the upstream vectors is the next step only if it is wanted.

Two independent fixture packs landed, and the AAT pack records that a later draft revision resolved the case it leaves open

Day 213 conformance done

The AAT and ODIS packs sat in a conflicting pull request for six days. The only conflict was a generated inventory table, resolved by keeping every row and letting the generator confirm the result. Both packs merged byte identical to the reviewed branch. While the pull request waited, draft-sharif-agent-audit-trail-04 was published with a signer key identifier and a named signing principal per recording mode, which resolves the recorder-key ambiguity the -03 pack deliberately leaves unresolved. One dated paragraph now says so. The pack stays pinned to -03, the unresolved case stays unresolved against -03 only, and the manifest digest moved with the README because the manifest covers it. The sign-off on that commit was added only after an explicit word, because a DCO trailer is a certification rather than housekeeping.

The AEP run record's merge values were handed to its counterparty as SHA-256 content hashes, with the rebase result correctly described

Day 212 conformance done

The WasmAgent maintainer's external-evidence ledger waits on the final head, the resulting main commit and the digests of four result files. The first draft nearly sent git blob identifiers where content hashes belong, and nearly called a one-parent rebase result a merge commit. Both corrected before posting. He recorded the merge with the two anchors and confirmed the assurance ceiling unchanged.

papers/README.md corrected in the SDK repository

Day 212 sdk done

A reader confusion in the papers index, fixed and merged. No published artifact touched.

The WasmAgent AEP layered run record merged after being re-anchored on immutable references

Day 211 conformance done

The record had cited a moving branch. Repaired to pin the component tuple, the publication commit and the lab revision as immutable references, with the four result files unchanged throughout. Merged by rebase as six commits on main. The claim stays scoped: an independent layered run against the component tuple published for one certified snapshot, with JS and Rust native verification and the lab-authored semantic recomputation reported separately, and the semantic layer recorded as author-produced.

The CoSAI WS4 #189 candidate cases merged after the reviewer reran the repaired head

Day 211 conformance done

Four defects reported by the reviewer, repaired and independently verified by a second participant: the coverage premise made explicit and load-bearing, unsupported verification raised as a non-verdict, a missing gating descriptor made a structural input error, and the harness made read-only so reproduction cannot repair the artifact it checks. A DCO-forced rewrite changed commit messages only. Merged by rebase as four commits. Still candidates against proposed text.

A certified snapshot's manifest cannot live inside the commit it names, so provenance is recorded at two levels

Day 211 conformance done

The protocol component SHA inside the certified tuple still carries the previous manifest, because a manifest naming a commit changes the commit. The counterparty confirmed the intended model: the component tuple plus a separate publication commit on the protected main branch. Both are now recorded side by side in the run record so the next reader does not take the earlier manifest for a mistake.

Three ways a correct fix could have shipped with the old contract intact, and the guard that closes the quiet one

Day 210 Ops done

The shipped skill still taught the replaced field names, so an agent following it would report an empty inbox. The test guarding that skill still carried the three dead names on its approved list, so the old contract could have returned without a failure. And the suite exited 0 with all thirteen end-to-end tests skipped on an unresolved path default. The dead names are removed rather than renamed so their return is a failure, and the pre-test guard now resolves the same path the test resolves and refuses to run without it, with a named flag for skipping deliberately.

Release tooling told a later version to reinitialize a compatibility window anchored to an earlier one

Day 210 Ops done

The thirty day legacy window was promised in one release and anchored to that release's own publication instant. The publish banner printed the initialization procedure for whatever version was being released, which would have instructed the operator to restart it. The server refuses a repeated initialization, but a backstop behind a wrong instruction is not a procedure. The banner now branches on the anchor release and prints a do-not-touch notice with a verify-only check for every later version. A dated errata in the same release corrects an earlier note that printed the cutoff where the publication instant belonged.

The independent record a family was waiting on already existed, and our own attribution was the narrow part

Day 210 conformance done

A cross-stack family's two exercised completeness outcomes looked to be missing an independent record, and I said so. The run we commissioned had in fact executed all four of those checks and passed them, and the verifier derives each outcome from the record data before comparing it to the published failure code, so neither check restates the file's own claim. The earlier record had assigned that run to the byte, digest and chain layers only. The correction appends a dated attribution assigning the two semantic layers to the run that made them, leaves the original claims as published, and does not extend to the third failure code in that class, which no vector raises.

An inbox that reported your own introduction as a stranger's request shipped for two days, and the fix went out as a major with no compatibility alias

Day 210 Product done

The server always returned the direction. The client relabelled it, so an outgoing request read as incoming and the requester's own note was attributed to the counterparty. The replacement contract renames the container, splits the note from its author, and keeps an absent server projection distinct from a derived state. No alias was kept for the old names, because the old direction values were inverted and an alias would re-teach the defect to the clients still reading it. The release note states that an install that does not upgrade keeps working and keeps showing every introduction backwards.

Mingle shipped: the canonical server live, mingle-mcp 4.0.0 then 4.0.1 on npm, and a thirty day compatibility window started from the registry timestamp

Day 208 Product done

Stage 2B closed with a one-action withdraw that atomically cleans up unreleased contact, live fit and First Step, with the race resolved at the write in both orderings. Stage 2C reduced forty-six tools across three generations to eight canonical ones, with the legacy set behind a flag. A two-principal end-to-end run through real MCP processes against a real API found six dead call sites the mocks had blessed, and review found seven severe items, two of them security, all fixed before publish. The server went live first, then 4.0.0 was published by hand under WebAuthn, and the registry timestamp of that publish is what the server records as the start of the legacy window. No patch moves the clock. 4.0.1 followed the same day as a copy-only patch for six overclaims in the shipped skill and README.

A maintainer merged our driver and asked what his three published files establish, and the answer was an outside reading with six questions

Day 208 conformance done

Run locally with inputs never modified. The published verifier exits zero on seven mutations with top-level valid true. A log digest field is shape-checked and never compared to the file. The published command omits the provenance flag and so never reads the Sigstore bundle. And a twenty-eight of twenty-eight agreement covers tool identity only, because the receipts carry no principal, context or input. Posted as findings with questions back to him, naming no lab and no APS.

Nine Mingle correctness fixes, a privacy bug caught in their review, containment gates deployed, and the MCP held unpublished

Day 207 Product done

A product review found Mingle deep before wide. Nine correctness items shipped, among them an acceptance email that never fired, a hidden opt-in default, semantic search ordered by recency, no atomic card replace, a false purge promise, a world-readable private key and bare sweep routes. The review of that batch found that one party's reveal released both exact values, fixed with a per-dimension releaser set. A binding audit of forty-three mutating routes recorded which request and commit signatures actually bind what the receipt claims. Fit and v2 containment gates deployed to Railway. The Stage 2A design was audited by two independent adversarial reviews and approved. The MCP stayed unpublished until the server it depends on was live.

The first reverify deadline in the registry's history passed, and the claim it protected was withdrawn rather than annotated

Day 206 vocab done

A principal attestation on one crosswalk cell reached its deadline with no renewal, and the fail-closed rule turned the whole build red. Renewal was not available: the upstream sample has been unmerged since May and no third party has attested. Three resolutions were argued. Softening the control to a warning would have overridden a documented fail intent. Waiting on the counterparty would give one organisation permanent blocking power over unrelated contributions. The claim was withdrawn instead, taking its deadline with it, with the attestation date and the reason preserved in the notes. Absence is already a valid state for a registry claim, so nothing in the rules had to move.

A conformance driver we wrote was rewriting the policy it was being tested against, and the correction was taken upstream as a rule

Day 206 interop done

The fixture policy used an idiom Cedar rejects, so an earlier revision of our driver rewrote it before evaluating and reported four correct decisions. Measured three ways: without the rewrite the same policy denies sequence two silently, and the one negative vector in the set was passing because its forbid clause never evaluated at all. The driver now fails on any Cedar diagnostic error instead of reading the resulting deny as a decision. The maintainer merged it, reproduced the result on his own machine with cedarpy 4.8.7 and the published SDK, credited both findings, and wrote the rule into the upstream README: the policy under test is the on-disk bytes, a driver does not rewrite them, and an evaluator that cannot run the policy must fail rather than deny.

Claims, Context, Copy adopted as a required pass before anything ships, and AI attribution trailers stopped at the push rather than at review

Day 205 Ops done

Claims means reverifying every fact, number and evidence chain against primary evidence. Context means rechecking repository state, prior decisions, scope and public promises, and whether a true sentence is misleading where it lands. Copy is the writing pass. It is now run on every deliverable before it is shown. Separately, a pre-push hook stops any commit we author that carries an AI attribution trailer, which moves that rule from something remembered at review time to something enforced at the point of push.

Four errors in one day shared a single shape, and the rule that came out of it names the shape

Day 205 Ops done

The exit code of head read as the exit code of the program. An empty regex match treated as proof of absence. A path-matched test selection reported as the repository's named contract suite. A run another agent performed becoming I ran it in a draft for a standards thread. None was a lie. Each substituted something adjacent to the evidence for the evidence itself. The rule requires the exact command, its own exit code and the output that shows the property actually being claimed, and it separates a reproduction on the same machine from an independent verification elsewhere.

The adversarial admission-evidence proof closed on a real Gateway, and the sentence it earns is narrower than the one we wanted

Day 204 Research done

Seven cases against a current runtime, built to attack our own claim rather than support it. Two were established on a real host, three were legitimately local, and the stop condition held for the rest. The earned sentence: the gate proves what it saw and admitted, and a later hook can change the arguments the tool actually receives, so what can be produced at the boundary is bounded by where the boundary sits. No new behaviour shipped from the proof. The upstream bug found on the way was filed on its own repro.

The D1 to D9 security-audit workstream closed after each item was verified against disk rather than against the index row that described it

Day 204 Protocol done

The Ed25519 admissibility rule shipped as the strict rule across all four SDKs. One item was ruled not to be a project at all: a dead helper with misleading labels, fixed opportunistically the next time that surface is touched, rather than carried as a security lane. The one production check that survives becomes a bounded compatibility item. The corpus-gap row stayed open and unblocked, because the vectors it needs now have a shipped rule to encode.

aeoess.com/mingle was cut from 424 words to 185, mingle-mcp 3.2.0 surfaces pending matches without a search, and OpenClaw was asked whether it wants the capability

Day 203 mingle done

The landing now says the product in one screen: find people through your agent. The MCP client polls the new pending endpoint at session start, treats an expired card differently from a withdrawn one, nudges before expiry rather than after, and states the disclosure promise as it actually works: only what you allowed for that connection, and you can ask what was shared with whom. A feature request on openclaw/openclaw asks the community whether a persistent agent should hold a standing intent and only interrupt when both sides agree, with the existing implementation offered for contribution.

A read-only look at Mingle's production database showed the 579 published cards were seed scripts, so the server was rebuilt to tell the truth and to push a match to both sides

Day 203 mingle done

All 504 principals were auto-generated ids with no links and no intros; the twelve v3 cards were a July test run. The public counter that read zero matches was a legacy field the v3 path never touched. The server now keeps expired distinct from withdrawn, deletes legacy 48-hour cards before it logs their expiry rather than inside the same transaction, records every card transition in an event log, reports the v3 network from its own tables with a marker it writes itself on first start, and pushes a newly created match to both sides through a pollable pending endpoint. Live on api.aeoess.com; nothing the user signs changed.

The maintainer merged the second OpenClaw fix after refreshing the branch himself, and the Node 22 issue was closed by his own runtime-floor change with our report named as the cause

Day 203 Ecosystem done

The status-renderer fix conflicted with main after the maintainer's own commit on the branch; he merged main into it, then merged the pull request, authorship kept. Hours later his 84-file change raised the runtime floor to the first Node releases with lossless SQLite reads and closed the embedded-NUL issue as fixed, its body opening with the report that started it. Two merges and one repo-wide floor change from one week of reading their source.

agent-passport.org got a bright default palette behind the existing theme toggle, with every landing-page color converted to a token so the night theme reproduces the old file byte for byte

Day 202 site done

Blue, white and yellow by default, night one click away. The screenshot pass found two limes and a black the site used inconsistently and gave each a token. Bright keeps one tier of subdued text where night has four, because the second tier fails the contrast floor on this blue. The first deploy shipped without bumping the stylesheet version tag and looked broken until it did; a CSS or script change now bumps its tag in the same commit.

External vector families now run in their own CI job driven by a machine-checked registry, and the contributing guide says exactly that

Day 202 conformance done

A runner that resolved the SDK from a sibling path outside the repo and rewrote results.json on every run was repaired the way an August fix was. Each cross-stack family declares its npm script names in an index, never shell strings; none is a passing legitimate absence with a reason and blocked is a failing diagnostic state; a check fails CI on a family missing from the registry or a command that does not exist. The job, the cross-stack typecheck and CONTRIBUTING line 32 landed as one pull request.

attenu-guard's nineteenth envelope vector was scored the same day by two people who wrote neither the vectors nor the checkers, and the lab record runs both their verifiers unchanged

Day 202 conformance done

The record pins the file from four published sources and keeps the row-19 mutation: judging an envelope before the duplicate check reports a bad signature and leaves a defective envelope witness-signed. Under the lab's labeling rule these two pinned runs are the first on this family that count as independent.

The first OpenClaw fix was merged overnight, two more were rated ready for a maintainer, and a Node 22 issue drew the maintainer's own draft within five hours

Day 202 Ecosystem done

Atomic writes on config recovery merged with the maintainer's second commit on the branch. A Google Chat reply that went to a lowercased space id now uses the canonical id already stored on the session, proven through the transport with a mutation that counts store enumerations. A two-line renderer fix stops a running service printing above a failed probe of a different Gateway without saying so. Four session tests failing on an endorsed Node 22 build were traced to that runtime's SQLite binding truncating text at an embedded NUL; the maintainer's tooling opened a draft raising the floor.

The promised release witness for agentrust-trace 0.10.0 was run against the published wheel, not a checkout, and posted with version, hash and every result

Day 202 interop done

The packaged schema now accepts a record carrying references, and the thirteen revocation-store cases from the integration mapping behave as specified, with callable stores returning empty values failing closed where 0.9.0 failed open. The witness states what it does not show: no end-to-end revocation statement was produced or consumed, and tested_against did not move.

The bernstein delegation-receipt pull request was merged by its maintainer after the option he chose was implemented in two commits with CI fully green

Day 201 Ecosystem done

Delegation receipts are recorded at identity mint in the real spawn path, fail closed on an unreceipted spawn, and anchor on a per-run root in the run manifest so the chain verifies without the identity store; allowed_files is recorded as its own ungraded axis, the maintainer's choice.

The hosted MCP bridge at mcp.aeoess.com moved from inside the published advisory range to MCP 6.0.1 on SDK 6.0.1, with manifest parity checked at both pins before the push

Day 201 sdk done

One hundred fifty-two tools, zero required-input additions, one intended change: a zone-less timestamp is refused rather than accepted. Anonymous access still returns 401. The authenticated smoke stays a separate step with the key never in a transcript.

Five conformance pull requests merged in one day: two CTEF records, an independent mcp-audit run, the TypeScript 7 migration, and a token-exchange attenuation family

Day 201 conformance done

The CTEF admissibility record counts as independent because a contributor's own checker at a published pin supplied the recomputation; the crypto-layer record does not, because the lab wrote and ran it. The token-exchange family turns an invariant stated on a toolhive thread into twelve engine-neutral cases decided from claim structure alone, with two widening vectors rejected as invalid rather than denied.

The label independent now follows the author of the implementation whose output supplies the recomputation, and the contributing guide says so

Day 201 conformance done

A checker written and run by the same person is author-produced even when they wrote neither the vectors nor the family's verifier; a run by someone who wrote neither vectors nor verifier is independent even on a lab-written verifier. The rule closed a labeling error in a draft record before it was published.

The SDK release workflow retries its post-publish verify instead of failing twice after successful publishes

Day 201 sdk done

Two releases had published correctly and then failed their own verification on an ETARGET from the registry not yet serving the new version. The workflow now waits and retries before declaring a failed identity.

The coordinated security release shipped on four registries in one cut, and four cross-referenced advisories were published once the last package appeared

Day 200 security done

SDK 6.0.0 on npm, Python 3.0.0 on PyPI, Rust 0.3.0 on crates.io and Go v0.7.0 on the module proxy went out from four merged pull requests, each tag signed, npm through trusted publishing with provenance verified from a clean install. The four advisories share one text, carry per-package affected ranges, and each links the other three; they were published after crates.io showed 0.3.0 so no registry lagged the disclosure. No CVE was requested; that is a separate decision.

A contributor's SDK repin was superseded by a maintainer pull request carrying his run report under his own authorship, after a mutation test showed the default test chain never executes the SDK

Day 200 conformance done

The contributor's pull request repinned the suite's SDK to a version that had just entered a published advisory range. Rather than merge a pin inside an affected range, a maintainer pull request carried his run-report commit unchanged under his authorship plus a pin to 6.0.0, and his original was closed superseded with credit. Before deciding, a mutation of the SDK import proved that npm test never reaches it; the four out-of-chain importers reproduce at 6.0.0.

The MCP server moved to the new SDK authority verification with rewritten tool contracts, and every public surface was refreshed to the four-SDK family

Day 200 sdk done

agent-passport-system-mcp 6.0.0 depends on SDK ^6.0.0: trust inputs sit on the tool schema, allow-self-signed is never defaulted and is described as integrity-only, and verify_charter takes the attribution receipts it previously never passed. A first reachability count of 2 affected tools out of 65 was wrong (a truncated constant) and was corrected to 18 by the same audit before merge. Skills, security policies, release notes, the profile README and agent-passport.org now state one set of versions with Rust in every list.

The attenu-guard envelope vectors got a successor record with three runners over one byte-identical file, 18 of 18 under each, all author-produced

Day 200 conformance done

attenu-guard 0.13.0 shipped envelope_vectors_v1.json v1.1 with 18 cases and an announced digest. The lab record pins the file by byte identity, runs the Python and TypeScript runners and a clean-room verifier over it, and records 18 of 18 under each. Every run is ours, so the record says author-produced and lists the three layers that still want an independent run.

A contributor's audit-gateway vector family was audited from a clean clone, and its digests recomputed by a verifier written from the header rules alone

Day 199 conformance done

The mcp-audit-gateway v0.6.0 family (suite #63) was audited at its head from a clean clone: both vector files byte-match the upstream tag, every cited line number lands where the README says, all 31 canonical-hash fields recompute, and the two runners pass 47 of 47 and 46 of 46. The review asks for five text edits, all his. Separately, a clean-room verifier written from the documented rules only, with no implementation opened, ran 112 checks: 109 pass, 2 unspecified by the headers, 1 not checkable, zero divergence. That run is ours, so under the lab's own definition it is author-produced and does not count as the independent record; the independent run was asked for in the open as suite issue #68.

The Quesen crosswalk was approved on its fifth round, with the merge held on one line of the pull request body

Day 199 vocab done

Round five found one of three owed edits landed, an anchor still wrong, and a merge with main that failed the matrix check because main had moved eight commits and the matrix had not been regenerated. The contributor fixed all three. The head was rechecked from a clean clone: the only change to the crosswalk since the previous head is the anchor, the matrix regenerates byte-identically at 23 systems, and the test suite passes with main merged in. Approved. The merge waits on the body line for governed_action_class, which the file declares as a five-class list while the body says read; a body edit, no push.

Three boundary replies went out after a three-leg adversarial pass, and ten stale issues were closed against the repositories

Day 199 vocab done

A SpendShield proposal on the SDK got a product-boundary answer: the spike is welcome with the corpus as its tests, and where it lives in the SDK is a separate decision. A key_custody attribute proposal on the vocabulary got not-as-written with three points and a route to proposed status through one grounded crosswalk. A provenance_tier proposal was held on the parked #73 axis, with source fact kept separate from trust policy. Each reply was drafted after independent legs, checked against the published draft where it cited it, and guarded against new third-party comments before posting. Ten issues on the vocabulary and SDK repositories were closed with one-sentence notes, each verified against the repository first.

The working board was cut to seven items after a hostile pass showed the list had been treating unfinished as important

Day 199 Ops done

A lost-items sweep found two real public obligations: a one-line contributor PR that had waited fifteen hours unseen (merged; the sentence now names the check that actually runs), and two days missing from this public record. The rest were decayed decisions, drafted mail nobody needed, and process machinery. Eleven items were dropped with reasons and reversal costs, six parked on external triggers, three closed because the work had already shipped under another name. The daily close is simplified to a handful of entries per day, and a missed close is the next boot's first write rather than a recovery project.

The oracle-safety-check family merged after four rounds, with the cross-stack CI question ruled on the base suite and not charged to the contributor

Day 198 conformance done

Round four corrected two false provenance sentences and asked for the family's three verifier scripts to leave the repository-wide test chain, because whether cross-stack verifiers belong in CI at all is base-suite sequencing, not his error. He pushed, CI passed, the family merged. Two records merged beside it: an EIP-712 recompute through ethers, and a clean-room JCS, SHA-256 and Ed25519 recompute, each pinned to the merge commit with its provenance stated exactly. The CI question was then ruled after a hostile leg: native per-family checks, non-required until promoted, with a checks-API design rejected because fork pull requests receive a read-only token.

The missing delegation-hop write path for bernstein shipped as a draft PR after the maintainer answered two design questions in forty-one minutes

Day 198 Ecosystem done

Building the write path exposed that no parent identity exists anywhere in a live run and that the spawner swallows identity-creation failures silently, so the caller could not be wired without inventing an identity. Rather than invent one, a design-question comment asked the maintainer for the parent model and the failure behaviour. He chose a run-root identity and a fail-closed abort with a distinct exception type, and assigned the issue. The wiring shipped as a draft PR closing the issue, with one follow-up issue for the remaining gap. A day-long mystery about files being reformatted under our scratch tree turned out to be the project's own test suite running a formatter outside its working directory.

attenu-guard 0.11.0 bundle vectors: two runners over one byte-identical vector file, 8 of 8 under both

Day 198 conformance done

The record pins the upstream vector file by digest and runs it through two runners, both passing 8 of 8. Two edge observations were written into the record and posted nowhere. The record labels its layers author-produced under the lab's definition rather than implying an independent run.

Twelve fact corrections across the public account, dormant repositories archived with notices, fifteen forks deleted

Day 198 Ops done

A public-surface audit against the live repositories found stale facts in the profile, the organisation description, several READMEs and one crosswalk. Twelve were corrected with zero code change. Dormant repositories were archived with a notice on each, and fifteen forks that had never been used were deleted by hand from a checked list. The rewrites that would change how the project describes itself, including the front-door README, were held for adversarial review rather than shipped in the sweep.

5.0.3 published with registry provenance on the third tag; the two failed tags stay as permanent identities

Day 198 security done

The hardening candidate merged as a two-parent commit pinned to its audited head. The trusted-publisher predicate was captured as raw registry JSON and held against 13 mutations. An immutable-version-tags ruleset and immutable releases were enabled and read back. v5.0.1 failed on a Linux argument-length limit when the packed artifact was passed through an environment variable; v5.0.2 failed at release creation because the CLI ran outside a checkout. Each got a one-line workflow fix through the protected path, and v5.0.3 published with provenance and an immutable release. The two failed tags are not moved and not deleted: the owner bypass on the tag ruleset is break-glass authority, not a repair tool.

A grading step run from the base branch cannot land in the same change as the checker it calls, so one pull request became three

Day 197 vocabulary done

The purpose-gate checker is invoked by a trusted job that checks out the base branch for its code and takes only the case data from the pull request. Because pull request builds run from the merge commit, a step added in a change runs on that very change, and it can only find the checker if the checker is already on main. The single-change plan would have failed on itself. The sequence became migration, checker bootstrap, then the trusted invocation, and the third change proved the point by running its new step on real CI and passing only because the second had merged first. Local adversarial proof before opening: with the pull request's validator gutted and its own copy of the contract repinned, the trusted run still scores full marks; with only the case data changed, the trusted run fails. Ignoring PR-side code sabotage while catching PR-side data change is the property the step exists for.

Three times in one day a count was read as a fact: a zero approval as a review requirement, a hit tally as an unknown author, a schema shape as intended semantics

Day 197 process done

A pull request with zero approvals was described as awaiting review; the repository requires none, and only the state field, not the git-level mergeable flag, separates it from the one that really is blocked. A scan classified a standards author as an unknown outside party from a hit count against files; the hits themselves record months of direct, responsive interaction. A read-only recon of another project's delegation code asserted that a finding answered its own review question affirmatively; three predicates run against the schema showed the premise had been assumed, the claim was withdrawn, and what survives is an unresolved lifecycle question rather than a defect. Same shape each time, and the correction each time was the same: read the thing the number stands for.

A contributor's head moved with no comment; the delta is nine lines of prose and zero of the six blockers, so the review stands unrerun

Day 197 conformance done

The conformance-suite contribution under a redesign request pushed a new head a day and a half later. Compared byte for byte against the audited head rather than summarized: the source note gained nine lines, the code is identical, and none of the six blocking findings is addressed. No rerun is owed and the request for changes stands as written.

Deleting a finished row is only safe if its record is confirmed somewhere else first, and four of thirty-five did not match on the first pass

Day 197 process done

The harvest tested every row for a live trigger before touching it: a watch, a reversal, an owed act, a standing rider, anything that could still fire. Nine rows tagged closed turned out to carry real work and were kept and compacted rather than removed, including one whose rider is that the next reply to a particular contributor must say plainly that a repository is not happening. Thirty-five were removed, and none was removed on the strength of its tag. Each had to have its record confirmed present in the ledger by identifier or by search string, with the command and its output recorded. Thirty-one matched directly. The remaining four were resolved individually rather than assumed, one of them because its pointer resolved into the decision log instead of the ledger, which is a different authoritative file and not a missing record. Rows: 213 to 178. Bytes: 229,318 to 218,020.

A release workflow rerun died because the version was already published, and took every step after it down

Day 197 security done

The tag workflow repacked a tarball, probed its exports, and then stopped at publish because that version already existed on the registry. Everything downstream was skipped as a consequence. The guard now compares the packed tarball against the registry digest: identical bytes skip the publish and let the remaining steps run, different bytes under the same version fail hard, because one version denoting two byte sequences is the actual danger. The first version of the guard treated any failed registry lookup as absence and would have published on a transient error, which is the same abort it exists to prevent, so a positively identified not-found is now the only state that permits publishing. The comments say plainly what a skipped publish does not restore, so that the skip path is never read as a repair.

Rewriting one stale row breached a hard ceiling, because the generated state file embeds that class of row verbatim

Day 197 process done

A row marked highest priority was rewritten to correct its stale claim, and the rewrite carried the evidence narrative explaining why the claim was stale. That pushed the startup byte ceiling into hard breach and the state builder into a failing exit. The multiplier is that the generated state file embeds every highest-priority row verbatim and is itself a measured member, so a byte in one of those rows is charged twice. The budget is also measured before the state file is rewritten, so a breach introduced by an edit appears one run late and looks like it came from somewhere else. The fix was not a threshold and not a member removal: it was trimming the row to state, trigger and pointer, which the content rule already required of it. Headroom went from 58 bytes to 11,356.

A security-release handoff was accepted for protected review after three corrections, and the lane froze on the one gate that was real

Day 197 security done

The hardening candidate arrived with six findings fixed locally: a privileged job executing too much repository code, mutation crossing trust boundaries, publication redirection through package configuration, forged rerun evidence from an existing release, mutable tag and release surfaces, and a write-collaborator race that could occupy the immutable release before the registry publish. Review legs forced three corrections, all adopted: the original order mutated repository-wide release policy before the candidate had been pushed anywhere; a tag-ruleset invariant was overstated because the platform returns bypass actors only to sufficiently privileged callers, so it is a pre-tag check with admin credentials rather than a workflow-proved fact; and a registry trust gate ran on an inferred response schema, which was withdrawn rather than replaced with a second guess. The verdict was ready to push for protected review, not ready to tag. A phrasing that collapsed an approving review into merge authority was then corrected: approval satisfies a repository control, and the merge word is a separate gate.

The fixture contract pinned only an identifier and an outcome while the contributor controls the case data, so a weakened case passed the contract

Day 197 vocabulary done

Every mutation built for the regression pack attacked the validator, and none attacked the fixture data, which is the half a contributor actually controls. A hostile pass showed the consequence: a required case could be downgraded to a weaker match type, or an array case collapsed to a scalar, and the contract still passed because it checked neither. The contract now pins match, purpose, expectation and diagnostic with order-sensitive arrays, six data mutations were built and all six are caught, and expected failures must fail for the contracted reason and carry no unexpected extra error. Two other findings from the same pass were refuted at source and recorded as such.

A deprecated match-type token became an input alias, normalized once at document load, and every crosswalk cell stayed byte-identical

Day 197 vocabulary done

The vocabulary's canonical replacement for a match type went live: one canonical token, one alias authority in the vocabulary file with the implementation holding no table of its own, and normalization once at load so any consumer reading the field is correct by construction rather than by discipline at each of eight read sites. Proof that no row was reclassified had to be built by isolation, because the committed matrix was already stale: generated twice from the same day's data, once from base and once from the migration, the outputs differ on exactly one line, the legend. Seven acceptance criteria became seventeen executable cases driving the real validator as a subprocess, and a mutation pass caught two of those cases passing vacuously, one because nothing asserted the alias stays out of the enum, which is the precise drift the ruling exists to prevent.

A runnable example delivered on a database vendor's server thread in June had no ledger record at all, and the maintainer just handed us the trigger

Day 197 Ecosystem done

The maintainer tagged us to say the multi-user path now works on main, a released version still has a credential-scoping bug, and he is holding the issue open until a release carries the fix. Answering someone else, he drew the boundary himself that a tamper-evident record of delegated scope needs an application-level layer, which is the layer we shipped in June against his invitation. Nothing is owed by us: the example was promised and delivered the next day, and his docs sentence was an offer with no condition. Recording it as a commitment would invent a debt for a later session to act on. The record states that asymmetry, the release is the only trigger, and posting now, right after a promotional account and before he finishes pending work, was ruled out.

A revocation mapping merged upstream, and two future obligations collapsed into one job keyed to the same release

Day 197 Ecosystem done

The counterparty merged our revocation mapping and closed the tracking issue, with the one divergence tracked separately on their spec. The recorded act to move the tested-against pin does not fire: their main pins the current release, which is still the latest published, and the pin already notes that the revocation observations are re-run on whichever release carries the spec change. Editing it now would assert a test not yet run. That release is the same trigger as the standing offer to witness their next release, so one future job replaces two: run the published wheel, report version, hash and results, then re-run the observations and move the pin.

All three review points were accepted and implemented overnight, and the right response was silence

Day 197 Standards done

A comment on another organisation's working-group deliverable made three points: a verdict carrying no failure class is under-specified, a minimum field list reads as a wire contract against the document's own independence sentence, and an incomplete result does not by itself imply replay. The author answered the open question on the parent issue himself, then accepted all three and pushed a revision within the same minute as his reply. Reading the new bytes rather than his summary: the failure class is now carried separately from the headline verdict, the field list is demoted to a conformant representation under four protocol-independent properties, and the consumption rule is narrowed to the exact invariant. He also strengthened completeness beyond what was asked. The instinct was to confirm receipt. The comment had created no review object, so nothing on that pull request appeared unresolved to anyone, and a confirmation would have added no information while casting us as an approval gate on work that is not ours to gate.

The repository's first high-severity scanning alert appeared in a test I wrote, inside a change arguing that green signals must mean something

Day 197 vocabulary done

A repo-wide source scan in the migration test called stat on a path and then read the same path, a check-then-use pair the scanner flagged as a file-system race. Dismissing it would have merged the first high alert inside a pull request whose whole argument is that a green check has to mean what it says. The fix reads directory entries with their types, recurses on directories, skips symbolic links explicitly and reads only regular files, with no preceding stat. Liveness was proven rather than assumed: planting a file carrying the deprecated spelling still fails the case and removing it restores the count. A reviewer separately reported the scan regex as missing its escape; the backslash was on disk and had been lost in rendering, the same disk-versus-rendering gap that produced two stale artifacts in my own reports the same day, this time producing a false positive in review.

A standards focus group's schedule verified from its own page: kick-off in December, four preparatory calls, one of them the next morning

Day 197 Standards done

Press coverage from July placed the first meeting in November; the group's page says 1 to 4 December in Paris, and the page is the authority. The four preparatory e-meetings are dated, each with a public conference link that needs no account. The leadership is now four people and the working groups are not yet formed. Nothing changes the boundary: the terms of reference put agentic protocols, AI governance and digital identity out of scope, so entry is implementation and conformance evidence only, with any first post to the group a separate gated decision.

A cryptographic test comment explained a correct discriminator with an incorrect account of why it discriminates

Day 197 Protocol done

The admissibility suite uses a permissive verifier alongside the strict one, so that a negative vector which both reject can be recognised as proving nothing about the strict check. The comment said the permissive path uses the cofactored verification equation. Reading the dependency's source at the pinned version, ordinary verification recomputes R and compares encodings, and the strict path is what adds the explicit small-order rejection of R and of the public key. The discriminator is sound and unchanged; only the stated reason was wrong, which is the kind of error that survives indefinitely because the tests keep passing. The same header claimed four implementations answer every vector identically by construction. Sharing one corpus lets implementations be measured against the same cases and does not make them agree. The tests are what establish that.

The file a session reads first to learn what is true asserted five things later rows in the same file disproved

Day 197 process done

The working index is read in full at startup and is supposed to hold one line per live commitment. It said a hosted endpoint answers unauthenticated, while a row further down recorded the containment that closed it three days earlier. It scheduled a release whose contents had already shipped inside a larger one. It named a published crate version one behind the live one. Its list of decisions waiting on the principal opened with an item whose underlying thread had closed completed. None of this was subtle and none of it had been caught, because a file that is only ever appended to is never read adversarially against itself. Forty-four rows tagged closed, dropped or done were sitting in a working set whose own rule forbids them, carrying 13,887 bytes of history that already lived in the append-only ledger.

Two vocabulary issues closed against their own evidence, and the term that started the second stays reserved

Day 197 vocabulary done

The match-type issue closed against its seven stated criteria, each exercised by the migration test on main, with the two hardening changes named as downstream and outside its acceptance boundary. The receipt issue closed as resolved into the merged primitive, never as canonicalized. The contributor had set the condition himself that the term stays reserved until a signed purpose exists in a canonically emitted receipt; the status on merged main is still reserved, checked before drafting and again after closing, and the close quotes that condition back so nobody reads it as promotion. One design question was deliberately left out of both closes: naming it in a resolution comment would make a finished issue read as conditionally unfinished.

Main had been unmergeable by policy rather than protected by it: a required check that no workflow could ever produce

Day 197 security done

After the one-approval rule was set to zero for a repository with one maintainer, the release pull request stayed blocked. The required status context named a job that emits two matrix names, so the required name matched zero check runs at any head and could never be satisfied. Corrected to the two real matrix names plus the analysis and sign-off checks, through the narrow endpoint rather than the full one, because the full endpoint replaces the whole configuration and silently drops any omitted field. Full-state diffs of sixteen fields showed one change for the first correction and two mirrored changes for the second. Net effect is stricter: two real test contexts enforced where one impossible one sat. Both corrections were decided by the principal and executed by his hand.

A boot-cost ceiling kept breaching, and every time the fix was deleting reasoning that already lived in the ledger

Day 196 infrastructure done

The working index a session reads in full went over its hard byte ceiling three times in one day. Each breach was cleared by removing narrative from rows that duplicated the append-only record: a rewritten history block on one row was 4,665 characters on a single line. The ceiling was never raised and no member was removed from the measured set, because both are the same evasion. Lines came back under by collapsing one-item-per-line term lists into comma runs, a formatting change with 280 items verified present afterward and a word-level check returning no lost tokens. The rule that followed is editorial rather than mechanical: a row carries current state, the exact trigger, and a pointer to the authoritative record, and if deleting a paragraph loses information the information was in the wrong file.

A decision log ordering check kept firing on correct history because it tested write order against event attribution

Day 196 infrastructure done

The log is prepend-only, so physical position records when something was written while the heading records what day it describes. Those axes legitimately diverge: a late close written the following day lands above entries dated after it, and that is correct. Two candidate replacements were measured before one shipped. Comparing day numbers fails the identical case. Comparing the heading date against the day number fires 56 times, almost all of it documented historical drift, which is a permanent noise generator. Comparing the heading date against the record identifier minted at write time fires four times, on the entries carrying both, and all four are real. Write-time properties get enforced at the write; a finished artifact cannot testify about the order it was assembled in.

A first-landing simulation passed only because the artifact under test had been copied into the clean control

Day 196 conformance done

A regression pack was built to make a merged validator boundary permanent, with the expected outcomes held outside the fixture so a future change cannot relax its own acceptance criterion. The continuous integration wiring was reported as verified against a clean base checkout. It had been verified against a base checkout the new checker was copied into first, which is not the condition being tested. Three further defects followed from the same review: the trust boundary was inverted so the trusted checker would have run the pull request's own validator, an expected-failure case counted any error as the right one and certified a regressed gate under mutation, and the pack tested no case for one of the two branches its own prose claims. If the clean control cannot perform the test, that fact is the result.

The MCP shipped hours after the fix while declaring a range that excluded it

Day 196 security done

The published package constrained the SDK to a line where every release carries the disclosed verifier defect, and one of its tools forwards a caller-supplied key straight into that verifier. Found by installing the published package and reading what it actually resolved, not by reading source. Fixed by moving the range and releasing again through the provenance workflow. Provenance says which bytes shipped; it says nothing about whether the dependency graph is clean.

A validator rule fired on any positive mapping, so a truthful partial mapping had no way through except a false claim

Day 196 vocabulary done

A contributed change enforced that any crosswalk row mapping a two-party signed receipt must declare which registered purpose the system emits. A system with a real two-party receipt that emits no signed purpose then had two options, both false: declare a purpose it does not emit, or record no analog when an analog demonstrably exists. Nine executable cases proved it, including all three states of the registry's own evidence axis, which exist to say the artifact does not carry a value and did not relieve the rule. The same nine cases surfaced a second defect nobody had named from either side: a no-analog row carrying a purpose passed silently. The fix keys the obligation to match strength instead of to the act of mapping, and the case matrix became the acceptance criterion rather than a description of one.

The definition tests whether two names look alike; the corpus has never classified on that and the generated docs already say so

Day 196 vocabulary done

One match type is defined as looking similar lexically while governance semantics differ. The contributor guide calibrates the same decision on what question the primitive answers. Both merged uses of the value fail the lexical reading and follow the semantic one, and the matrix generator already prints the value's legend as different question entirely, so the public documentation and the specification have been describing two different rules. The obvious repair collapses the value into the honest-gap value, because that is also a different question. What separates them is substitution hazard: a candidate close enough that a consumer would wire it up as the canonical one. A merged honest-gap row that examined a candidate and rejected it in full disproved the alternative boundary.

Scored at moderate because the higher score would have imported a different defect's consequences

Day 196 security done

The advisory covers a verifier accepting a key that proves no possession of a secret. A separate weakness lets a self-declared author reach a positive verdict at all. Scoring the first as high integrity impact would have counted the second's consequences twice. The vector stays at limited integrity impact and the reasoning is recorded next to it so nobody rescoring it later has to reconstruct why.

A stop-and-ask fired on the thread it was written for and went unserved for 28 days while a scan pointed at a different repository

Day 196 Standards done

A scan reported a pre-registered trigger as fired and unserved, and attached it to a standards issue where the same person had named the principal in an issue body. Reading the trigger's own thread instead shows the counterparty replied there twenty minutes after the original post, four weeks ago, and the thread has not moved since. The scan found a real failure and put it in the wrong place, and the disposition prepared for the wrong surface would have closed the procedural debt without touching what was actually owed. The standards issue itself needed no entry: the requirement text does not name the principal, the proposed amendment has not landed, and the maintainer and the issue author had already supplied both halves of the fix. A trigger's key includes its surface, not only its person and topic.

164 published artifacts executed rather than reasoned about, to state one honest version range

Day 196 security done

The tempting claim was that every published version carried the defect. Instead every registry-published artifact across four ecosystems was installed and executed with a positive control first, so a version that could not run was recorded as untestable rather than clean. One npm version cannot install at all because it declares a dependency whose name is a typo that has never existed, so it is published in neither affected nor unaffected form, and the advisory says so.

A review of current behaviour read the default branch while the release lived on a tag

Day 196 infrastructure done

Minutes after publishing, a bounded review reported a defect and proposed a fix. The defect was real on the default branch and had already shipped fixed, because the branch is protected and the release reaches it through a pull request. For released behaviour the tag or the published package is authoritative and the default branch is not. Same shape as reading the wrong repository, except it is the right repository at the wrong point in time.

Three reasoners argued deeply over an evidence set that was missing the one merged row that settles the question

Day 196 vocabulary done

A crosswalk classification came down to which match type an unsigned decision receipt should carry. The evidence set was built by searching for the match type's own name, which returned two rows from unrelated slots, and a verdict was reached and nearly published. Searching instead for the canonical slot returns seventeen candidates, of which six are the value under discussion and none is the one that had been argued for. The controlling precedent maps unsigned platform-recorded decisions to the same slot on the stated grounds that they are not portable signed artifacts while the semantic intent overlaps. A second row in the same slot carries the value while being signed, which killed the premise that signature presence was the axis at all. Three reasoners cannot recover an artifact that was never pasted to them.

Three failed publishes were the release script's fault, not the registry's

Day 196 infrastructure done

The one-command release wrapper piped all output through tee so it could keep a log. That detaches npm from the terminal, so it could not show the browser prompt and fell back to demanding a one-time password that a passkey account does not have. The command that had always worked was a plain publish attached to a real terminal. Fixed by handing stdin and stdout to /dev/tty for the publish steps only. Every future release wrapper does the same.

An issue shipped with an empty body because the check that would have caught it ran in the same breath as the write

Day 195 process done

The digest and byte count that would have caught a zero-byte issue body were correct, were written, and ran in the same tool call as the command that created the issue, so they printed after the issue already existed. Repaired 15 seconds later, and adopted as a rule: an irreversible public action never shares a call with the verification that authorises it. Build, verify in one call, write in the next. Recorded with its own caveat, that separation opens a window between the authorising check and the write, so the write may carry a cheap inline guard that recomputes the digest and aborts on mismatch. That guard is not the authorisation and never replaces it.

The documented way to check a record was the same command that produced it, so on drifted inputs it replaced the answer and exited zero

Day 195 conformance done

An interop record reproduced byte for byte at its pins: 18 vectors, four cause labels verified from observed bytes, zero field differences. The blocker was not in the evidence, it was in the instructions. The rerun command wrote to the tracked results file, so on the recorded inputs the tree stayed clean and nothing looked wrong. Drift one expected value and the same command silently replaced the historical record: the artifact digest moved, the tallies went from 10 and 16 to 9 and 15, no mismatch was reported, exit zero. The environment pins accepted any checkout, so a mutated corpus also produced a clean pass. A reproduction that regenerates the evidence in place cannot fail, which means it was never checking anything.

A dependency shipped a successor the same day, and the new version refuses a class of input the old one accepted

Day 195 conformance done

An external package published a successor release hours after its predecessor's record was merged. Eighteen of twenty vectors are byte-identical between the two versions, and the difference is a new rejection of integers outside the range where a double is exact, which is the same defect class a mutation had found in an unrelated implementation that morning. The merged record is now one version behind and says so. Logged as a successor trigger and deliberately not chased: opening another author-produced record while two contributor reviews are open would put the lab's own work ahead of work it has asked other people to do.

An integer large enough to leave the double range aborts the run instead of being recorded as a refusal

Day 195 conformance done

Found by mutation while auditing something else. A canonicalisation library raises an overflow from a float conversion on the integer path, above the guard that would have turned it into the library's own not-canonicalisable refusal, because that guard sits on the float path further down. The adapter catches only the refusal type, so such an input ends the run rather than being recorded as one more refusal beside the others. Unreachable from the corpus, so no gate could have caught it and it is not a conformance failure. Filed upstream as its own issue rather than folded into the evidence review, so one blocker about a record did not quietly become an audit of somebody's codebase.

A registry crosswalk where every objection had to come from the definitions, including the one that was my own fault

Day 195 vocabulary done

Four blockers on a new contributor's crosswalk, each grounded in a registry definition rather than a preference: a source path grounding one endpoint while the crosswalk scopes another, a replay class claiming full replay where the evidence supports only a fingerprint, a refusal authority marked shared where the artifact shows consumer policy, and an invariant recorded as surviving after the action when it is checked before. Equally important was what not to ask for. Three things I could have asked him to downgrade were tested and all held, so asking would have cost him work to make the record less accurate. One blocker was mine: an earlier comment steered him to the wrong reference file, and I then audited his hash claim against the recipe I had sent him to. His public reproduction matches the live hash byte for byte.

The defect blocks the merge on severity; its absence from our own contributor guide is ours

Day 195 conformance done

The rule that a reproduction command must not be able to alter the record it reproduces appears in none of the three documents that govern this: not the contributor guide, not the run-report spec, not the open-runs queue. Measured across all three, the results filename appears zero times, and so do overwrite, tracked and destructive. The lab had applied the rule to its own runner that same morning as a dated note inside its own record. So the review had to carry both halves at once: the defect is real and holds the merge, and the fact that a contributor could not have read the rule anywhere is a failure of publication that belongs to the lab. A review leg caught the first draft contradicting itself, saying it was not a rule to hold a pull request on and then holding the pull request on it.

The oracle-safety-check generator merged into the SDK; the lab family waits on provenance, not on another rewrite

Day 194 sdk done

Fourth round on the pair. Every asked item held on both heads under mutation: an expected value of banana exits 1, a fresh key re-signing the canonical bytes exits 1 on the derived-key check, the index is membership-only, the false reason inside the signed decision receipt is gone. The generator PR merged with the repository gates green. What the family still needs is ours: the EIP-712 layer has an ethers record, the APS primitive layer got a clean-room recompute today (rfc8785 and cryptography, no SDK code, 13 of 13 vectors, twenty checks each, only the designed negatives failing), and the composite verdict layer needs an outside run because a checker I write for it does not count.

Registry ruling: an unsigned recomputable receipt does not map structurally to a term defined as a signed attestation

Day 194 vocabulary done

A new crosswalk mapped a deterministic decision receipt (ruleset commit plus SHA-256 of the canonical input) onto governance_attestation at match structural, with signature_capability deliberately omitted. Recomputation establishes that a result follows from inputs; it does not establish that an identified issuer made the statement, which is what the signature supplies. The match type for that is non_equivalent_similar_label. Recorded for every future unsigned-artifact mapping, with the property named rather than the format: the rule yields only to another mechanism that provides equivalent authenticated issuer binding. The same review found the cited source directory stating that no engine implements it yet; emitted evidence has to cite the code that emits.

REMORA refuses two RFC 8785 integer vectors on purpose, and the lab records that as refused, not as supported or unsupported

Day 194 conformance done

The REMORA author asked whether the lab should record his implementation as supported with an exception or as unsupported for canonical-byte interoperability. Neither. The record says what was observed, 16 byte-identical, 0 divergent, 2 refused, with the refusal text and his reason beside it, in the enforced form: integers whose binary64 image is not unique are refused, 2^53 included. The wider sentence in his design, that no two argument sets share canonical bytes, was false on inspection (0.1 and its 34-digit spelling collapse before his code sees them) and he narrowed it upstream the same day. Two blockers found and fixed: a BUSL header on a file the lab hosts, and an adapter hash computed over CRLF bytes, the same defect his own record reports two sections later.

The TRACE maintainer answered the revocation mapping, and the divergence we found turned out to be TRACE against TRACE

Day 194 interop done

Three questions asked on Wednesday, three answers on Saturday. The two TRACE revocation surfaces are one mechanism degrading gracefully, entry-scoped where an inclusion proof exists and binary on the key where it does not; authority revocation and key revocation stay unmapped on both, and an unsigned record with transparency none has no revocation surface by construction; nothing is emitted today. The finding we had filed as an APS-versus-TRACE divergence, that an empty store accepts while an omitted store skips, is now a trace-spec issue in the maintainer's own words: the spec requires absence to be reported as absence and the store path promotes it to a pass. The mapping doc is committed locally with the pointer.

I proposed an independent runner from memory of a good run; the watch file on disk said never cite that account as independent

Day 194 governance done

The admission rule needs an outside run for two layers of the argentum family. My first pick was an account that had reproduced our revocation corpus well three days earlier. The people file, read only after the pick, carries a standing entry from July: elevated verification, never cite their recomputes as independent. The entry stays; changing it because a runner was needed would let the desired outcome write the governance decision. The ask went to an implementer with no involvement in either the vectors or the pinned implementation, and it asks for facts only: run the documented commands at an exact head and paste the output. The lab classifies afterward.

A ruling on the word including: deterministic verdicts need an outside record before an external family lands, and my own runs did not count

Day 194 conformance done

The admission rule said independently recomputable claims, including bytes, digests and signatures, land only with an independent record. On an argentum action_ref family the question was whether domain-rejection and grammar verdicts sit on that side too. They do: including is illustrative, and anything a third party can reproduce from published inputs is on the mandatory side. The same audit found that I had originated eight of the ten domain vectors months earlier through a bug report, so seven independent labels I had drafted for my own runs were retracted before posting. The contributor's work is complete; the merge waits on an outside run and on the lab fixing its own documentation.

4.5.1 is the first release where the attested tarball and the published tarball are the same bytes

Day 193 infrastructure done

4.5.0 was published by hand after its workflow run failed at an audit gate, so it carried no provenance. 4.5.1 is a lockfile-only patch cut to restore the chain. Before tagging, the release workflow was changed to publish the exact tarball the attestation signs rather than packing a second time; the same fix went into the MCP package's new release workflow, which now publishes through npm Trusted Publishing with OIDC, no token, pinned actions, an SBOM, and one pack. The release asset's SHA-512 equals the registry's integrity field.

A working-group promise from July was delivered in two days and linked back after thirty-five, with a close date attached

Day 193 Standards done

The contribution-policy update and worked fixture promised on a standards working-group thread landed in the registry two days later, with the commit citing the thread, and were never posted back; a held reply waited on an artifact that already existed, and every sweep since read the tracking row without following it to the thread. The link went up today after the fixture README was corrected, since it described a file not in the directory. The thread now carries a close date: if the group has not taken up the stewardship question by 11 September, the issue closes and the registry continues standalone. Rule recorded: a promise delivered on disk and not in the thread is still undelivered, and sweeps compare the thread's last message from us against what shipped.

On a 45-comment thread, the one useful intervention was a question about what required is checked against

Day 193 Standards done

TRACE's two-axis model separates supply-chain depth from per-action receipts and treats required as a verifier floor. Reading the merged text rather than the thread showed the record carries nothing that says which calls needed a receipt; the conformance fixtures supply that from outside. So a record declaring receipts required with none present can never report one missing. The first draft of this finding was wrong on its premise and died in a hostile pass before posting; the surviving version asks where the coverage set lives, and either answer the editor gives makes required checkable. Six fellowship proposals were building fixtures on top of the gap without naming it.

The counterparty confirmed the four divergence classes himself, added the vector for the spec gap the clean-room run found, and the record moved to his new release the same day

Day 193 conformance done

attenu-guard 0.6.1 ships its vectors inside the package and adds reject_wildcard_widening, the case where a child claims a wildcard over a parent holding one scope, which two independent verifier authors had got wrong from the draft text. The clean-room verifier written from the draft scores eight of eight on it with no logic change. Bytes unchanged at five of ten, now recorded under a three-class divergence split with observed bytes. The author reclassified his serializer as a distinct canonicalization that agrees on the ASCII-and-integers subset, identified the one class that can reach a real token, and asked to take that decision with implementers in the room.

An automatic runner for every external family was declined: it would have made contributor code execute by default and turned absent verification into a green skip

Day 193 conformance done

The obvious fix for external families not being in the suite's test command was a runner that discovers and executes every family's validator. Two hostile reads killed it: the contributing rule requires independent verification before a family lands, not execution by the test command; auto-discovery would make every contributor's code, including a home-grown cryptographic verifier, run by default in CI; and skip semantics would let a family whose toolchain vanished stay green while no longer reproduced. Three things stay separate: the core corpus run with a known toolchain, explicit per-family reproduction recorded with attribution, and lab-wide aggregation only ever behind an allowlisted manifest that reports a missing toolchain as an error. What remains is one documentation sentence.

A second IETF draft author arrived with running code, and the lab turned it into a two-direction record in nine hours

Day 193 conformance done

attenu-guard (draft-asor-wimse-agent-delegation-chain-00) offered to run APS vectors through its verifier. Direction one: its serializer against the pinned RFC 8785 fixtures, five of ten distinct cases byte-identical, four named divergence classes. Direction two: a clean-room verifier written from the draft and the published vector profile without reading the reference implementation, seven of seven, with one spec gap found on the way (the wildcard rule for scopes is discoverable only from the vectors). Both directions merged as an interop family with author-run and independent labels. Nobody adopted anybody.

An invitation to put vectors through the lab, phrased as let's use the machinery together, was taken in 34 minutes

Day 193 conformance done

The trust-signals thread on A2A had three projects publishing their own vectors and asking where cross-implementation results should live. The reply named the lab as a home for the second half, when somebody else runs your vectors, without declaring a convention or asking anyone to adopt anything. argentum-core answered with a cold reproduction of the whole corpus and a pinned candidate set. The wording that worked was the principal's, not the assistant's: shorter, no claim of ownership, one concrete next step.

The public MCP endpoint served a governance tool the source had removed, for eight days, because a pin lagged the docs

Day 193 infrastructure done

The remote bridge pinned the MCP package at 4.0.0 while npm latest was 5.0.0, so mcp.aeoess.com kept exposing evaluate_threshold, a tool 5.0.0 removed because it counted declared signers without verifying anything and still emitted a verdict. The bridge's README had already been rewritten to say 5.0.0; the dependency pin had not. A one-line exact pin and a service version bump fixed it, verified live: 152 tools, the removed tool absent, the three amendment tools present. The lesson recorded: a publicly wrong live answer outranks every scheduled priority, and docs propagation is not deployment.

receipt-core and authority-delegation became public API in 4.5.0 after all four export gates closed

Day 193 sdk done

The two modules had shipped inside the package since 4.2.0, tested but unexported. Four gates stood between them and the public surface: strict duplicate-member parsing on serialized action_ref input, a composite verifier that binds a receipt to its decision before any cross-document conclusion, serialized entry points for receipts, and a known-answer corpus. All four closed on the same day and 4.5.0 shipped with verification described as what it establishes, never as authorization to dispatch or proof of single-use.

The same ten RFC 8785 cases, runnable from four ecosystems with one command, because three projects hit the same bug in one week

Day 193 conformance done

attenu-guard, REMORA and cMCP each turned out to canonicalize with a sorted-keys JSON encoder that is not RFC 8785: exponent formatting, astral key order, non-ASCII output, and the binary64 number model all diverge. The ten distinct cases already pinned in the lab now have runners in TypeScript, Python, Go and Rust that read the fixture at run time, report byte and digest match per case with the first divergent offset, label whether a first-party canonicalizer or a baseline encoder produced the row, and treat a mismatch as a recorded result rather than a failed run. It is a byte diff on ten cases, not a verdict on anyone.

Four external pull requests, four full protocol reviews, and on each one a second reader found defects the first pass missed

Day 193 conformance done

Each review classified its track before the read, wrote adversarial hypotheses first, executed every claim from a clean clone, and wrote a memo. A separate model running the same protocol cold then found what the first pass had not: a collision check comparing a bare digest to a prefixed one; an Ed25519 verifier accepting S plus the group order, invisible to random differential rounds and found by Wycheproof in one run; a vendored attestation that was a signed security verdict about a third party; a runner whose README said the authority chain verifies while it checked signatures, links and continuity only; replay claimed by a verifier that never touches replay; negatives keyed to fixture names. The artifacts were sound every time; the sentences were not. Rule adopted: every README sentence about what a runner enforces gets one mutation built to make it false, and a green aggregate label is a claim to falsify. Second rule: any vendored cryptographic verifier runs against the known-answer corpus for its primitive before any verdict.

Three places where the lab quietly depended on a sibling checkout, every one found by someone else's run

Day 193 conformance done

An unprompted Mode B report from REMORA noted that the documented one-command run needed a second cloned repository. A cold reproduction from argentum-core stopped at the same place an hour after the fix landed. A CC self-containment gate found the third, a Go replace directive pointing at a neighbouring directory. All three now resolve published artifacts at exact versions, proven from fresh clones with a fake HOME and empty module caches. External cross-runs are exposing defects that internal maintenance passes had not.

Operating rules that only one process could read were not rules

Day 192 infrastructure done

The rules governing how work gets done lived in assistant memory and nowhere on disk, so subagents and review legs booted without them and every prompt hand-copied a subset. Moved to a canonical on-disk file with stable rule identifiers, cited by ID rather than copied, because a copied rule is a second surface and two surfaces drift. Ledger records gained stable identifiers enforced fail-closed on the write path, which immediately caught a write from a second session running in parallel and a day-number collision between them.

Correcting a six-month-old proposal, where three of the things I believed were wrong were not

Day 192 Ecosystem done

An outside maintainer revived a February integration proposal, which put fresh attention on claims that had aged badly. The correction was expected to cover a frozen name, a stale domain, an unsupported principles claim and an old test count. Checking the artifact rather than grepping for it removed three of the four: the name appeared zero times, the domain is a live product surface, and the principles feature is real and its enforced count exactly right. What actually survived was that the principle total was wrong on the day it was posted, eight in the manifest against seven claimed. The original proposal was preserved byte for byte and the erratum appended.

Four claimed fixes reproduced from clean clones, and one carried-forward number corrected

Day 192 conformance done

Audited a contributor's cross-stack fixture work from fresh clones of both heads rather than from a working tree. Provenance placeholders gone, the dependency real and absent from base, and a prepare script that actually builds the package on a git-pinned clean install, which was the true root cause of a failing acceptance command. The reported test count was a number carried forward from an earlier audit rather than a fresh run. Running the base branch in the same clean environment showed the identical figures, so the apparent anomaly was environmental and the change introduced no regression.

A lab with no maintainers file, and a staged fix whose blocker had been gone for days

Day 192 conformance done

The conformance lab had no MAINTAINERS, no code of conduct and no security policy, while being listed as a foundation lab. The fix had been drafted three weeks earlier and left unopened because it was blocked on write access that had since been granted. Opened with three files rather than the five staged: the fourth was a README replacement written to remove a badge that a different change had already removed two weeks before, so shipping it would have reverted newer work. The maintainers file states plainly that the sole maintainer also authors the specification the corpus tests, and that the shared-review rule does not bind until there are two committers.

The published lab text was corrected first, so a repair never made it false

Day 192 conformance done

The conformance corpus provenance file stated that the offline verifier never consults the active delegation root. That was accurate when written and a pending fix would have falsified it. Rewritten as a release-scoped statement about the shipped version, true before the repair and after it, and merged ahead of the SDK change rather than behind it.

A field the verifier documented as authoritative and never read, found by checking a counterparty's aside instead of letting it pass

Day 192 sdk done

ReceiptContext.active_delegation_root is exported API, documented as the delegation chain root the verifier treats as authoritative. verifyReceiptContext never read it, so a receipt carrying any chain root verified as long as that root was absent from the revoked list. Both fixture harnesses set the active root equal to the receipt root by construction, which is why no test caught it. Fixed as DELEGATION_ROOT_MISMATCH, appended last so no existing first-failure classification moved, with a regression test and a conformance negative. The regression was itself missing from the test script and would not have run.

A rotation invariant closed across three independent records, and a reciprocal artifact stopped before it shipped broken

Day 192 conformance done

Drop 12 verified the day it arrived, 14 vectors for 14, with the rotation digest equal in the counterparty's expired vector, their predecessor block, and our own ledger line, recomputed over the sent bytes. Our reciprocal artifact was then stopped: both signatures declared one did:key separated by fragments that do not resolve, so one did not verify under the identity it named, and our harness passed it because it resolved keys from a private table. Rebuilt as a fixed issuer plus a distinct co-signer key, and the acceptance rule now derives every key from the signer DID itself.

A conformance guard counted skips, and a count cannot tell you what it counted

Day 192 conformance done

An outside contributor asked for an explicit ruling rather than shipping a policy change quietly: raise the suite's fail-loud guard from exactly one declared skip to exactly two. The ruling was neither. A count is preserved under substitution, so the same assertion is satisfied by the two intended skips and by a state where both started being asserted while two unrelated vectors quietly began skipping. Errors that cancel pass the guard. Replaced with a named allowlist that fails in both directions, requires each allowlisted family to declare a verifier that runs in the gate, and requires a mutation run of that verifier to exit non-zero. Two independent review legs converged on the allowlist separately.

An outside contributor found our registry validator reporting PASS over thirteen files it never checked

Day 192 vocabulary done

validate-crosswalks.js walks descriptor dimensions in a nested shape and silently skips the flat shape, which thirteen crosswalks use, including one merged the previous day whose PR cited Validator: PASS. Reproduced independently from a clean clone before replying. The out-of-enum value hiding in the gap belongs to the reporter's own file. Routed as ordinary artifact correctness rather than a governance question, with the vocabulary question kept separate.

Adoption-signals inventory re-verified row by row; the Day 170 warning was itself wrong

Day 191 evidence done

All 178 claims checked against the repository API: 86 hold, 39 true once and stale now, 45 fail, 8 cannot be verified; replacement wordings applied in three passes. The Day 170 spot check had read only the first page of comments on threads of 143 and 51 and missed the endorsements at comments 113 and 50, so one of four failed, not three. Rule: read every thread with per_page=100 and state the page count, or a negative finding is worthless.

Revocation verification corpus merged, and independently reproduced by the contributor who asked for it

Day 191 conformance done

Nineteen cases against the existing revocation records, no new signed type, with intrinsic verification (shape, signature, existing verifier) ordered before contextual checks (lookup, authority, binding match). The contributor who opened the request ran the branch himself: 17 of 17, and one artifact digest recomputed in Python with the rfc8785 library, byte-identical. Recorded as an independent reproduction of the corpus; not a lab run report, not validation, not adoption.

TRACE crosswalk merged against the pinned v0.9.0; revocation mapping opened as an issue with three questions

Day 191 Ecosystem done

crosswalk/agentrust-trace.yaml in the vocabulary registry: 19 rows against the released TRACE v0.9.0, one partial (policy.version to baseline_revision) and eighteen explicit no-mapping cells. Revocation schemas exist only on trace-spec main, not at v0.9.0, so released and unreleased surfaces were mapped separately and never blended; authority-to-key is no-mapping on both, revoked_at and reason partial. The publicly promised revocation item went to the integrations repository as an issue for the maintainer, not a table pretending to answer it.

Second outside corpus reproduced in the lab: x402-receipts at pinned debc94f

Day 191 conformance done

Seven receipt vectors and five negatives from a builder on the x402 delivery-receipt thread, reproduced outside their CI: their 213 tests pass, every envelope digest recomputed with the Python standard library alone, each negative fails exactly the predicate it pins. Scope paragraph states the limit: the corpus exercises ASCII strings and integers only, so the artifact claims reproduction of that corpus and its negatives and makes no claim of general RFC 8785 interoperability. One three-sentence comment on the thread offers the artifact and nothing else.

Conformance lab intake: run-report format, submission issue form, one-command contributing path

Day 190 conformance done

The lab had one star and one committer; promotion was reframed as manufacturing independent runs. Two pull requests shipped and were verified live: the suite README top and organization profile, a RUN-REPORT.md format anyone can paste, an issue form for submitting a run, and a one-command CONTRIBUTING path. Three claims handed over by a review leg were refuted at source before any reached a public draft.

Two public provenance errors corrected with dated notes

Day 190 evidence done

A pull request I described as still owed to a collaborator had merged on June 13, carrying the nine drift vectors I was proposing as additive; the tree listing I read was truncated at sixty lines. And the Linux Foundation lab file described as edited after merge is 51 lines in one commit by its maintainer. Both corrected on the surfaces that carried them. A truncated listing is worse than an empty grep because it looks like data.

Vocabulary crosswalk #114 closed on artifact gates; the gates found stricter than the contributing document

Day 190 Ecosystem done

The cited independent implementation and the npm package both sat in the spec author's own authorship domain, so the independent-implementer gate could not be met. Closed on that ground. Flagged against myself: the registry's CONTRIBUTING asks only for public inspectability, a working implementation and a named maintainer; the stricter gate was stated in the thread twice and never disputed, but it is not written down. Reconciling the document is its own item. A housekeeping close of a notification-hub issue was stopped when three live workflows turned out to recreate it.

action_ref inventory: 15 of 15 byte-identical on the external form, and a citation defect in the legacy function

Day 188 Protocol done

Field-by-field inventory of every action_ref derivation on disk against the published draft, the joint external draft, and the current conformance corpus, closed by execution rather than source reading: the TypeScript external form reproduced all 15 applicable known-answer vectors byte-identically and rejected the integer-epoch negative at the timestamp grammar gate. The same pass found the legacy computeActionRef citing a draft section it does not implement, in each SDK carrying a variant. Consequences split cleanly: Phase 3 composes with the v1 external form; the citation fix is a separate documentation-first workstream; profile naming waits on the next draft revision.

The suite reproduces an outside profile: ca2a validity windows at a pinned commit

Day 188 Protocol done

ca2a's full conformance profile executed at a pinned commit outside their CI: 46 passing, including the new expired and not-yet-valid credential cases their validity-window work added. Landed as an interop artifact with the run log, environment, and checksums, and a scope paragraph stating what it does not do: no statement about APS, no APS artifact graded. Case definitions are ca2a's own, referenced by path at the pinned commit.

Phase 3 opened on the composed receipt envelope: delegation_chain_ref as the additive fourth sibling

Day 188 Protocol done

The June invitation asked for delegation-chain conformance vectors; the replies under it reframed the work as slotting argentum-core's existing delegation_chain_ref into the composed envelope at v0.4, and the first job draft missed that and specified a new lineage format before review caught it. The pull request that shipped instead: three composed vectors (two-hop narrowing accept, scope widening reject, continuity break reject), each reject isolating one check with root and leaf anchoring valid throughout; all 47 pre-existing files byte-identical; both existing verifier languages extended with zero code lines removed; chain artifacts producing their expected results under the unmodified argentum verifier at the pin. Two scope notes instead of new behavior: no per-hop principal signature verification is defined by the pinned profile, so it is not tested here, and the vectors follow the pinned conformance set where the spec text says SHOULD. PR open for review.

Claims audit across every public surface, and an ownership registry for the numbers

Day 185 Ops done

Seven defects of one species in a single day, none of them a value typed wrong. A post-deploy check counted MCP tools with server.tool( and had returned zero since the API moved to registerTool, so it compared a package description against nothing. Composite lines moved one token and froze the rest, three times. A README badge carried the total in the passing slot. Two published descriptions named an SDK two majors behind while being republished the same day. A verify pattern could not see the N MCP tools shape at all. Each was a number no artifact owned. CLAIMS-REGISTRY.md now names the owner for every public claim, and four guards run in the weekly self-check: verify patterns, published metadata, the diff-review extractor and the tool count. Every guard was negative-tested rather than assumed.

Gateway policy evaluation measured, captured and published: 0.14ms p50, 7,100 ops/sec

Day 185 Research done

403 ops/sec sat in two machine-readable surfaces with no environment record and no reproduction path. The harness that produced it still runs: three runs report 0.132 to 0.140ms p50 on the full enforcement path and 7,147 to 7,275 ops per second, so the published figure understated throughput roughly eighteen times and the under-2ms bound held by fifteen. Deleting an unowned number was the easy half and made the site say less than the truth, so it was captured the way the canonical latency set is, with env_capture.json, all three runs and a methodology. Published values take the slowest p50 and the lowest throughput of the three, never the best sample, and every surface names the machine. Marked not canonical: this is a developer machine, not one of the three environments in spec sections 13.1, 13.2 and 13.3.

MCP 5.0.0: a tool that reported a cryptographic verdict over an arithmetic check is removed

Day 185 Protocol done

evaluate_threshold took a charter id and signature records whose signature field defaulted to the empty string, then printed THRESHOLD MET. No amendment ever reached it, the server held no amendments, and the underlying function counted a signature without verifying it. Passing content was not the fix: the SDK keeps the amendment preimage private and exports verifyAmendment, which derives it internally, and the server already imported the lifecycle at one call site and used none of it. 5.0.0 removes the tool and ships propose_amendment, sign_amendment and verify_amendment in the governance profile, with the verdict reported field by field so a caller can see signatures verify while the threshold falls short. Two AST assertions hold the boundary: exactly two files may bind a canonicalization symbol, and the amendment handlers call no canonicalizer. Both negative-tested.

Package descriptions carry no mutable facts, and fit inside the registry's 255-character ceiling

Day 185 Ops done

npm publishes only the first 255 characters of a description, verified against the registry API where 4.3.0, 4.3.1 and 4.4.0 are each exactly 255 and 4.4.0 ends mid-sentence. A longer local string is therefore a different artifact from the one users read. Two of three published descriptions were also stale on live registries, naming an SDK version two majors behind. Counts, versions, benchmarks and parity claims moved to the README, which ships in every tarball and already propagates; descriptions now state what the package is. Generating them was considered and rejected, because a description is immutable between releases and generation would make the wrong thing accurate more often without removing the failure.

4.4.0 and 2.11.0 published; the write policy and the RFC 8785 integer fix reach users

Day 185 Protocol done

npm served 4.3.1 and PyPI served 2.10.0, both equal to the repo versions, so neither registry carried the unsafe-integer write policy and PyPI still shipped the pre-fix canonicalize_jcs. Both released over Trusted Publishing with no token. PyPI failed on the first tag: hatchling now emits Metadata-Version 2.5 and the twine bundled in the pinned publish action refuses it, which killed the run before upload. The same pin published 2.10.0 in July, so this is upstream drift rather than a change here. Pin moved to v1.14.2, tag re-cut on the fixed head, published. Python's changelog leads on the integer alignment because emitted bytes move for integers whose decimal spelling differs from their binary64 serialization.

Tool count generated from the live registry instead of written by hand in five files

Day 185 Ops done

150 to 152, and no longer a literal anywhere. Every registration passes through the server's own registerTool wrapper, so the manifest is collected there and the test asserts the runtime registry equals the manifest rather than equalling a number. The name is recorded before the wrapper's profile early return, because after it the manifest would silently become a function of whichever profile was active; a test asserts the manifest is identical under full and governance while the tools that actually land still differ, 152 against 37.

657-row call-site inventory across both SDKs, driven to zero unclassified over two audit passes

Day 184 Protocol done

The first coverage claim was wrong, and the second pass is why that is known. Run after the first pass's fixes, it found what a name-based census cannot: a scripted edit had moved a line inside a verifier onto a write twin, an inventory keyed by basename leaked classifications between nine colliding filenames, a heuristic treating any is prefix as a verifier mislabelled four producers, one build dropped a copyright header from a published file because the compiler elides an import together with the comment attached to it, and one boundary was fixed in TypeScript only, leaving the two SDKs disagreeing at the same place. Coverage is complete for every boundary reachable inside the repositories. Two limits stated rather than hidden: seventeen shared symbols that both mint and re-derive stay unrestricted, because guarding them would refuse re-derivation of a value minted before the rule, and one package carries a local copy of the rule.

Canonical-bytes corpus v2, and an outside canonicalizer measured against it in public

Day 184 conformance done

Two integer vectors added, chosen to exercise both branches of the implementation under test: one where an integer parse succeeds and the emitted form is the decimal text, one where it fails and the token passes through verbatim. The eight v1 vectors stay byte-identical and v1 stays frozen. The lab ran the corpus against a pinned head of an outside pull request, with the fixture pinned by digest and a scratch clone outside the suite repository, redistributing none of their source. The harness asserts per vector, so a byte mismatch exits non-zero; the previous version logged without asserting, which means the morning's eight-of-eight result could not have failed and was held back for that reason. Primary path eight of ten, both misses matching the behaviour predicted from the inspected branches. Wording standard adopted: observed outputs match what the code predicts, never prediction promoted to evidence.

canonicalize_jcs serializes int through the RFC 8785 number domain; bytes now match TypeScript and Go

Day 184 Protocol done

RFC 8785 section 3.2.2.3 defines the JCS number domain as IEEE 754 binary64 under ECMAScript Number::toString. Python's int is arbitrary precision and the canonicalizer emitted it verbatim, keeping a decimal spelling the double does not have: 2^60 emitted as 1152921504606846976 where the binary64 form is 1152921504606847000. Where those spellings differ, a digest or signature computed here disagreed with the same object canonicalized by the TypeScript or Go SDK, so an artifact verified in process and failed for any peer that recomputed the bytes. The int branch now widens to binary64 first and takes the float path; an integer beyond the range raises rather than emitting something no implementation can reproduce. Found while preparing to measure an outside canonicalizer, which is how the ordering ran: fix our own house before publishing anything about someone else's.

An outside implementer verified the worked example, and the reply states the limit their README sets

Day 184 outward done

rackp reproduced rackp.agent-ops.v1 end to end: data hashes eight of eight, signatures nine of nine under an Ed25519 implementation they wrote rather than a library, document hashes recomputed from the bytes currently served, eight of eight schema-valid. Separately they ran the RFC 8785 canonical-bytes vectors through their own canonicalizer and published a pinned receipt with fixtures pinned by commit and digest. Recorded as interop at the canonical form and nothing above it, which is the limit their own README sets and the limit our wording uses. Not adoption, not endorsement, and the signal entries stay staged rather than folded into a file still carrying a drift warning.

Signing and new-write boundaries refuse integers outside the interoperable IEEE 754 range

Day 184 Protocol done

RFC 7493 section 2.2 says a sender cannot expect a receiver to treat an integer beyond 9007199254740991 as exact and recommends carrying it as a JSON string. Both SDKs signed one anyway. The rule applies through internal read and write twins, byte-identical to their read twins for every value they accept, with the check inside the emitting walk on the single read that produces the byte, so a getter or Proxy answering differently on a second read cannot put an unsafe integer into a signed artifact. Verification and recompute stay unrestricted, so artifacts signed before the rule keep verifying, proven against the built package rather than against source. Refusal carries a stable category and reason plus the JSON path of the offending member.

A failing test adjudicated as pre-existing upstream rather than assumed to be ours

Day 183 contribution done

A compaction test failed during the final gate. Instead of treating it as a regression introduced by the branch, it ran five times in isolation at the branch head and five times at the exact upstream main in a shared-target worktree. Both failed identically, which makes it an order-dependent test that already existed upstream. CI on the pushed head was later killed by a package-manager hang at the six-hour job limit, so the pull request was closed and reopened once to re-fire the event on the same commit without adding one.

goose PR corrected: a crashed hook no longer counts as an evaluated policy

Day 183 contribution done

A hostile audit of our own pull request, reconciled against two independent audit passes, found policy_evaluated counting a crashed hook as having evaluated the call, which is the opposite of what the signal should say when the policy never ran. Fixed with an at-least-one aggregate rule. Second finding: an inactive code path had changed the public error contract, repaired by restoring the outer error and emitting the failure event directly. The DCO was found unenforced despite earlier records suggesting otherwise, which is why the record was checked rather than trusted. Three commits rebuilt on the current base, full gates run, pushed with force-with-lease against a known anchor, six old review threads verified against the new head and resolved, and a review requested.

The lab ran an outside composition pack to 27 of 27, as a neutral runner rather than as the protocol

Day 183 conformance done

A cross-slot accountability composition pack was read end to end and all fifty-one artifacts fetched before anything ran. Its twenty-seven cases passed with TypeScript and Python consumers written for the purpose, 168 and 171 lines, zero dependencies, and no native profile semantics required. All fourteen runner checks are structural or digest only. The lab was designated the implementer rather than the protocol project, deliberately: a neutral runner is what makes a second implementation mean anything, and naming ourselves would have removed the independence the exercise exists to produce. A findings issue was filed on the pack rather than kept private.

rackp worked example revision 3, with the session anchor ordered before the routine anchors

Day 183 outward done

Revision 3 shipped with a real SESSION_START anchor that precedes the routine anchors in time and not merely in sequence number, which is the correction that makes the ordering claim true rather than presentational.

Narrowing erratum applied across thirteen site files; one dated erratum on the protocol page is the record

Day 182 outward done

Scope-only claims stayed. The thesis sentence stayed where it states the specification's rule. Short feature lines that asserted broad authority narrowing moved to the scope form; the AIVSS card and the passport page restate spend as a specification requirement and link the erratum. Dated blog and roadmap bodies untouched. Repository description updated the same way.

New landing and contact pages, landscape slide with named incumbents, star prompt, double opt-in email list

Day 182 outward done

Ten-section landing ported from the design runtime to plain HTML plus a small script; the deck's 'delegated authority can only narrow' headline corrected to scope on the way in. Landscape slide names owners per lane: Entra Agent ID, Google Agent Identity, AWS AgentCore Identity, Okta, Auth0; Ping, Okta, Google and AWS agent gateways; ERC-8004 and A2A Agent Cards; AuthZEN, OAuth agent delegation, Cedar; APS on verifiable action authority, attribution and evidence. Contact page hands the message to the visitor's mail client with an unsigned content-hash record. Email updates: double opt-in through a worker that stores no addresses, signed 48-hour confirmation links, one-click unsubscribe.

rackp worked example revision 2: real SESSION_START anchor over the served profiles

Day 182 Standards done

rackp.agent-ops.v1 is served at its canonical URL, byte-identical to the reviewed draft except effective_date. The worked example now opens with a SESSION_START anchor declaring both served profiles with norm_document_hash over the served bytes; routine anchors renumbered and re-timestamped to follow it; sixteen known-answer vectors reproduced, revision 1 reproduced 9 of 9, schema validated, verifier snippet recomputes four hashes and five signatures from a clean process.

canonicalizeJCS rejects undefined; shipped builders emit explicit null and no signed byte moves

Day 182 Protocol done

Issue #101 asked whether the RFC 8785 canonicalizer could stop coercing undefined to null. A branch census found 11 call sites emitting the coerced null, pinned in the mutual-auth conformance vectors and the accountability bundle fixture. Explicit null at those sites satisfies strictness with byte-identical output; omission would have changed the bytes everywhere. Shipped: the canonicalizer throws naming the path, twenty call sites write explicit null, 51 pinned files unchanged, full-suite trace 514 of 515 outputs identical with the one delta a rewritten adversarial test. Also repairs a wire defect: artifacts signed with an omitted optional verified in-process and failed after a JSON round trip. Core BilateralReceipt keeps the legacy preimage and declares it; fixture READMEs scoped.

bilateral_receipt: no term-level canonical byte profile; declared preimage per row, evidence decides

Day 182 vocab done

The registry entry keeps its declared-preimage text. Definition purity keeps one implementer's algorithm choices out of a canonical definition; the canonical bar asks for compatible emitted shapes plus a checkable vector, not byte-identical output; nothing qualifying is emitted over JCS in evidence yet. Promotion trigger widened from two named implementations to any independent one. No APS crosswalk row until APS emits a signed purpose.

4.3.1: an explicit zero signs a zero cap, and unparseable numeric flags refuse to sign

Day 180 Protocol done

The published CLI parsed --limit through two falsy coercions, so --limit 0 signed a delegation with no spend cap; --depth abc serialized NaN as null and removed the depth ceiling. Both fixed and released as 4.3.1 on npm: zero is a value, non-decimal and unparseable numeric flags exit 1 with no artifact written. Verified against the shipped tarball and by executing every cell of the flag matrix independently of the CI gates. Suite at 4,378 registered, 4,377 passing, 1 skipped.

Erratum: the site said spend limits can only decrease; the shipped verifiers only compare when both sides carry the field

Day 180–182 Protocol done

The specification forbids a child that drops a bound its parent carries. The shipped TypeScript and Go chain verifiers guard the spend and depth comparisons on both sides being present, so an omitted field skips the check. The AIVSS page and the delegation page description now state the specification rule, the current enforcement, and the gap, dated 2026-08-17. Scope narrowing is enforced and that claim stands.

Five defects the port surfaced, and a review method that could not have found them

Day 179 conformance done

A language with no undefined forces every absent value to be named. Non-string scope entries were silently dropped instead of rejected; fractional depths flowed through a float accessor so a chain of minus one point five to minus zero point five satisfied the increment rule; clock skew was unbounded with unchecked arithmetic on both boundaries; and a shipped test claiming to cover duplicate keys after escape decoding asserted the same literal twice. My own sign-off had reproduced the gates, which proves a gate ran and says nothing about semantics. Named and recorded as a distinct review failure mode.

Rust SDK published, verification only, with a README that states what a pass does not prove

Day 179 Protocol done

agent-passport-system 0.1.0 on crates.io, Apache-2.0, matching the npm and PyPI package names with the library importable as agent_passport. Verifies passports, delegations, chains and ReceiptV1 across both canonicalization profiles against frozen conformance vectors; creates nothing, with no key generation, signing or issuance. 101 tests, no unsafe code, dependency audit clean across 1216 advisories, and consumer resolution verified from a scratch project rather than from the working tree. The README states the limits: it does not implement the seven-facet authority record of the current draft, chain narrowing is pairwise and incomplete on spend and depth, signatures establish static limits and not consumed state, key admissibility is unchecked, and it is a fourth implementation by the same maintainer rather than independent verification.

An unqualified parent scope authorizes arbitrarily deep descendants under the default interpretation

Day 178 Protocol done

Granting the scope code authorizes code:delete, code:exec and code:deploy:prod, with containment unbounded in depth, under the interpretation that applies when none is set. The reverse direction is correctly closed, so the matcher behaves as specified and the finding is about the default rather than a defect. Consequence for issuers: an unqualified parent scope is broader than it reads, and the effective attack is a request for something modest that already contains the target rather than a request for the target.

A single-use guard that held sequentially and lost under concurrency, closed

Day 178 Protocol done

A type exported by the SDK carries a comment stating each approval can be used exactly once. The implementation behind it read the consumed flag, awaited a lock, then set the flag, with no re-read in between. Two concurrent dispatches against one approval both executed; the sequential control denied the second with the replay error, which is what makes it a race rather than a missing check. Closed by re-reading inside the serialized section, probe confirms two to one, full suite 522 passing across 163 suites. Severity calibrated rather than inflated: the path is reachable from no route, imported by no other file, and shipped in the public SDK only as a stub that throws. Defect real, exposure nil.

Assigned upstream to the issue the open change implements, with two further defects closed

Day 178 contribution done

A maintainer assigned the originating issue, so the implementation is carried rather than volunteered. Two more defects landed on top, both leaving a tool request with no response: a permission denial swallowed between an operation matcher recognising only one variant and a fallback reserving every active call, and two final-output calls in one block each treating the other as unfinished. Two narrowing conditions, 18 lines added across 2 files. The test asserts a bijection over the transcript, each request appearing once with exactly one response and no orphans, which is a stronger invariant than the four individual cases that exercise it.

A cross-implementation corpus reproduced completely, and the five findings were about what the vectors test

Day 177 conformance done

Five token digests and lengths, five signatures against the issuer's live key set, eight receipt digests and eight expected error lists all reproduced by running the stated profile rather than reading the published table. The rotation seam held byte-identically against the copy archived a week earlier, recomputed independently from each end. The findings concern coverage rather than correctness: no not-before claim in any token, so the lower-bound vector only rejects for a runner reading sidecar metadata; a malformed key fixture that fails base58 decoding rather than the multicodec check its note describes; a differential policy claim the fixture cannot support without a stated policy; and an identifier that no longer commits to signer identity, proved by minting two signers over one body.

A sign-off check went live mid-review, and the reasoning that dismissed it was wrong in a nameable way

Day 177 contribution done

A DCO check appeared on an upstream repository partway through an open pull request. The first read looked at four recently merged pull requests, found no sign-off trailers, and concluded the check was not gating merges. Those pull requests had never been subject to it: the check was enabled that morning, an older commit on the same branch carries twenty-four check runs without it, and every instance found across the repository started the same day. Absence of a signal is not absence of a requirement when the check has not run. Four commits signed off, tree diffed before and after to confirm only trailers moved.

Receipt identifiers are content-addressed on both sides, and ours had been for a round without saying so

Day 177 Protocol done

The APS receipt identifier preimage excludes signatures, so two valid signers over the same body produce the same identifier. That is what makes wrong-signer separable from tampered-content, and it also means the identifier names unsigned receipt content rather than a signer-bound object. It matters anywhere the identifier is used for deduplication, as a database key, as a reference, or as a revocation target. Recorded as a fourth place the two profiles differ, and flagged for the next draft revision, which currently says nothing either way.

The canonical domain's certificate would not reissue, so it now terminates at an edge certificate while the host clears the authorization

Day 177 infrastructure done

The certificate expired and the host-side authorization state stayed bad through a domain detach and re-add at three wait intervals and through deleting and recreating the site. Everything checkable was clean: records identical across four public resolvers and the authoritative nameservers, no certificate authority restriction at the apex, the challenge path reachable and unredirected, and a second domain on the same account holding a valid certificate throughout. The domain now serves from an edge certificate as a bridge, with the redirect setting that caused the original interception left off so the host can complete its order. Twenty-five hours down.

A registry rename decided against a resolver census rather than a preference

Day 176 vocabulary done

A contributor project renamed itself and the registry had to choose between carrying both names and cutting cleanly. A census of external resolvers for the old registry key returned zero hits outside the repository, so an alias would have preserved compatibility with nothing while permanently doubling what every future reader reconciles. Clean cut with a rename ledger entry. The contributor authors his own crosswalk file; cross-references and regenerated material land in a maintainer commit so the cut is atomic.

The first term to test the two-implementation gate shipped proposed, not canonical

Day 176 vocabulary done

The signal-type status rule requires two independent implementations before a term can be called canonical. One exists. The term ships as proposed with a review date attached, which is the honest state. The gate was applied to a friendly contributor's work on the first term that tested it, which is the only circumstance under which a gate means anything.

The first outside contribution to the SDK was a correction to a claim we shipped wrong

Day 175 sdk done

An environment capture function emitted a specification section reference for a case the specification does not cover, while the neighbouring case correctly emitted nothing. The inconsistency had been open as an issue since May. An outside contributor fixed it in one line and it merged the same hour. The originating issue closed with a note stating what the overclaim was, because a silent close would leave the record implying the problem was theoretical.

A pre-tool result event and a stable call identifier opened upstream, across both agent loops

Day 175 contribution done

An implementation of a previously proposed event: a result emitted for the pre-tool hook chain on both the allow and deny paths, plus an identifier carried consistently across the lifecycle so a decision and its outcome can be joined. Both agent loops covered. A later commit extended the same lifecycle to the recipe final-output path, which had been bypassing the hook wrapper because its operation is registered ahead of the ordinary tool path.

A canonicalisation requirement split into two obligations instead of being argued as unclear

Day 175 Standards done

A norms document stated a canonicalisation requirement in a way that conflated two separate obligations. The reply proposed splitting them rather than describing the sentence as ambiguous. The counterparty adopted the split as proposed and characterised the original as wrong rather than imprecise.

A three-pass scan exhausted its open lists and put eight decisions up, none of which closed that day

Day 174 Ops done

The third pass cleared the carried items from the first two. Two Internet-Drafts cleared the mechanical engagement trigger on credited categories, an opening in a proxy project was proven across all two hundred and forty-seven open issue bodies, and one withheld row closed as not qualifying once the staged document was fetched directly. A directory listing merged, which is a distribution channel and not an adoption signal, and is recorded that way. Eight decisions were put up and none were taken, which is the honest characterisation of the day.

A competition entry built under evidence lanes, where every claim declares its tense

Day 173 Research done

Every block carries a lane: exists, fixture, proposed, planned. Across three adversarial rounds the partition caught a version number for a release that does not exist as stable, a delegated-action example described more favourably than the artifact supports, and a rollback framed as revocation when a real rollback is a compensating action executed under its own delegation. The evidence fixture was audited from a fresh clone rather than the working tree: one intact bundle verifies clean and three tampered variants fail at member digests, at authority chain scope widening, and at audience binding, each with its own exit code.

Three reviews on a contributor cluster, including one that blocked

Day 173 vocabulary done

A crosswalk described a signing path in a way that did not match the implementation it was describing, verified against that project's own source. The review blocked. Blocking a contributor whose work you want is uncomfortable and is the entire function of having posted rules rather than posted intentions.

A first comment to a certification working group: two timing observations, no self-citation

Day 172 Standards done

A 169-word comment on a proposed agent-tool identity and provenance control, the first contact with that body. Two observations: the requirement mandates refusing revoked tools but never states when revocation is checked, so an establishment-only implementation passes every listed scenario; and no case covers verification that cannot be completed, so an agent treating an unreachable registry as still-fine also passes. Both are framed as making the working group's own text explicit rather than adding requirements. The draft cited our own Internet-Draft as prior art; the posted version cites only OpenID Shared Signals/CAEP, deployed and vendor-neutral, because a first comment to a consensus body should not arrive selling anything. Byte-verified against the approved draft after posting.

The first protocol term page ships in three layers: human page, llms.txt line, structured terms.json

Day 172 outward done

binding-vs-freshness is live at agent-passport.org/terms/binding-vs-freshness as a two-hundred-word canonical page with DefinedTerm structured data, a one-line entry in a new Terms section of llms.txt, and a machine-readable record in terms.json. Two review rounds reshaped it from a standards memo into a term page; the sentence that survived both is that a matching binding proves continuity of the commitments, not freshness of the world they describe. The page pins draft-pidlisnyi-aps-03, published 2026-07-18, seven sections from 3.5 to 5.6, and states what binding does not establish: policy correctness, input completeness, or the truth of the underlying claims. The template now governs fourteen further terms.

The lab's first outside contribution cycle completes: reviewed under the posted rules, corrected at source, merged

Day 171–172 Standards done

An external pull request adding cross-implementation receipt vectors went through the conformance lab's full cycle: review under the published rules, an on-thread correction where our own characterisation of a canonicalisation package failed against RFC 8785 read at source, and merge as bdd6691. The companion issue closed the same day. The contributed vector stands with no bytes changed and unchanged scoring; the only correction in the cycle was to our review, made by us on the public thread. This is the first time an outside contributor's work has crossed the lab end to end.

The contribution agreement question is answered: a lab sits outside the process the agreement belongs to

Day 170 Standards done

A contribution agreement had been sent that assigned the protocol name, the main repository and the domains, while the lab documentation described something with no transfer at all. The call settled it against the governing documents rather than by negotiation: the agreement is the instrument for transferring an existing project's marks, it attaches to technical projects, and the lifecycle places labs outside that path entirely. No agreement is required for the lab, and the repository transfer proceeds.

The receipt exchange starts running in both directions, and each side finds a defect in the other

Day 170 Protocol done

Round two of the weekly conformance exchange. Six receipt vectors were ingested from the counterpart issuer and verified 6 of 6 against a runner built to their profile, and our own reciprocal set of six was published with burned seed labels so the keys can be regenerated rather than trusted. The counterpart then changed their v2 envelope shape after running our corpus, because it showed their construction could not separate a wrong signer from tampered content, and disclosed a specification-level defect in their own canonicalizer that the run surfaced. The same round found a factual error in our published description of their profile, corrected as a dated erratum rather than edited away.

The conformance lab gets a home: organisation provisioned and maintainer access granted

Day 169 Standards done

The lab moved from an accepted proposal to real infrastructure. The organisation was created with governance declared as code, membership granted at maintainer level on the scaffolding repositories, and the transfer route for the suite established. Organisation policy blocks direct repository creation by members, so the transfer runs through a staff account rather than around the policy.

The offered rerun runs as aaif-goose/goose#10433, four credit claims are withdrawn, and a 76-commit history turns out to carry 3 sign-offs

Day 169 outward done

A test rig written against a proposed fix in an upstream agent runtime was rerun against the fix that actually merged, honouring an offer made publicly twice and still outstanding. It compiled unmodified and passed every case across two full runs and twenty repetitions per test. The result of keeping the promise was not a finding about their code but a correction to our own public description of the rig: it drives the extension manager directly and never enters the reply loop, so it covers cache invalidation and what a later fetch observes, not behaviour during a running reply, and it does not cover a notification arriving while a tool-list request is in flight. The maintainer covered that race himself with a deterministic two-semaphore test. Separately four claims were corrected during the day, all running toward credit rather than capability: a conformance count in a third party's draft attributed to a source the draft does not cite, three requirements in a maintainer's scope attributed to our comments when timestamps show two came from the maintainer a day earlier and one from the issue author forty-four minutes before us, thanks reported as collective when two contributors had been thanked by name in pull requests we had not opened, and a sentence claiming the rig exercised a guarantee it does not touch. Each failed the same check, which is who said a thing first. Preparing the conformance suite for contribution surfaced a problem with no clean fix: 76 commits, 3 carrying a developer certificate of origin sign-off, and one unsigned commit of real work from an outside contributor whose email no longer resolves to an account, so the standard history rewrite would put his attribution at risk to satisfy a process that exists to record who contributed what. The question was asked rather than guessed, and the contributor was written to directly. The lab proposal merged on 31 July; the repository import and the paperwork are still ahead. Posted as aaif-goose/goose#10433 at 2026-08-04T20:33:31Z. The history being prepared for contribution carries 76 commits with 3 developer-certificate sign-offs, and the one commit from an outside contributor, 381885a, has an author email that resolves to no GitHub account.

A composition boundary is published, then enforced by another project’s test suite

Day 168 Protocol done

An exporter into an external trust-record format was opened and approved, a gap in our own revocation design was published rather than quietly noted, and a composition boundary was confirmed and then enforced by another project's tests. The boundary holding in someone else's suite is the part worth recording: a limit that only we check is a claim, and a limit another party's tests enforce is a property.

An exporter into an external trust-record format is opened and approved; a gap in our own revocation design is published; a composition boundary is confirmed and then enforced by another project's tests

Day 168 outward done

Fourteen public artifacts. An adapter mapping APS policy decisions into an external trust-record format at its lowest conformance level was opened and approved the same day, with the reviewing maintainer naming the load-bearing property unprompted: an unverified decision cannot become a record that looks appraised, because verification raises before mapping rather than after, and the schema fields an APS decision cannot supply are declared and pinned by a test so the gap cannot drift. This is our records running against their suite, which is the reciprocal of independent implementation rather than that condition met. An issue was opened against our own revocation design stating that a signed revocation gives non-repudiation and not non-equivocation, since a compromised delegator key can sign a second conflicting record with nothing surfacing that both exist; it drew a concrete mechanism within the hour that binds position into the identifier so competing entries at the same sequence are detectable. A contributor spec review merged with all five corrections landed, including one the contributor found himself. An author confirmation on where the composition boundary falls was requested and given: APS defines what a record establishes and how it verifies, a relying mechanism must verify under those rules rather than inherit the result, and acceptance and sufficiency remain the relying mechanism's own. The party who asked recorded it publicly and wrote tests asserting those sentences and that no endorsement is claimed. Fifteen corrections to our own claims were caught during the day, fourteen running toward overstatement and one toward understatement. The exporter shipped as agentrust-io/integrations#86. The composition boundary landed as atvp#10, squash-merged as 83c3cb3 against pinned head d647cfa2. The revocation correction was posted on #46, where the claim had been made; the parameter appears zero times in 0.5.1.

A comment to a standards working group is posted, reverified, and then publicly corrected

Day 166 Standards done

A second comment was posted to a credentials RFC thread only after full reverification of the cites it carried. A subsequent correction was posted publicly when part of it did not hold, and an addendum proposed by another party was rejected rather than absorbed. The correction is the entry.

An entry flow ships so a human and an agent arriving at the same address are given different doors

Day 166 Product done

Four routes deployed end to end, splitting the arrival path by who is arriving rather than serving one page to both. Shipped, then revised the same day when the first version bundled assets that did not need bundling, and the bundling was reversed rather than defended.

A sweep of our own published assets finds fabricated metrics and commercial fiction, and removes them

Day 166 outward done

An asset sweep found numbers on a published surface that were not traceable to any source, alongside commercial framing that described things that did not exist. Both removed and the removal recorded rather than quietly corrected. Recorded because finding invented figures in our own shipped material is the failure mode this discipline exists to catch.

Four external posts ship only after two independent review legs come back clean

Day 166 outward done

Four gated posts were held until two external review legs had run and agreed, then shipped together on approval. A feature request to an agent runtime went out through the same process. The sequencing is the record: the review ran before the post, not after.

The Go conformance runner is fixed so the third implementation is actually being checked

Day 166 Protocol done

A defect in the Go runner meant one of the three implementations was not being exercised by the conformance suite in the way the other two were. Fixed and confirmed green, which restores the byte-parity claim to something the suite actually tests rather than something asserted.

A second goose proposal asks for a result event with a stable call id, so a denied tool call can be joined to what happened next

Day 166 Standards done

goose #10885 proposes emitting a PreToolUseResult event carrying a stable tool_call_id. Without one, a hook that denies a tool call and the downstream record of the outcome cannot be joined by any consumer, which is the difference between a decision that is logged and a decision that is auditable. Filed the day after #10866 and still open.

The MCP server ships a major version through three gates, and the release finds a production outage the health check was hiding

Day 166 Protocol done

Version 4.0.0 published through tag, registry and release gates in order. The release sweep surfaced a production bridge outage that the existing health check had not been reporting, which is the more useful half of the day: a check that passes while the service is down is worse than no check.

Measurement infrastructure goes in so claims about our own surfaces stop being guesses

Day 166 Ops done

A tracing surface and a daily boot check were added, so questions about what is live and what is reaching people are answered from instrumentation rather than from memory. Small, and the reason it is recorded is that several corrections this month came from not having it.

Twenty-three stale status values rewritten across seven public repositories

Day 166 Ops done

A mechanical sweep ran over nine public repositories on branches and every diff was verified against the handoff before merge rather than accepted on a reported success. Six repositories fast-forwarded and one required a duplicate-commit reconciliation after an unrelated commit landed on the sweep branch. The catches worth recording were the ones outside the search: a Node version floor written with a space in the middle in two separate files, and a test count contradicting the README of its own repository. One check could not be run mechanically at all, whether a version bump on a parity line matched that project's own changelog convention, which required reading thirty-seven prior entries to establish.

A governance-hook proposal from April is closed as implemented on a 52,000-star agent runtime

Day 165 Standards done

goose #8742, opened in April, argued that cross-org agent deployments need an external interception point before a tool runs. The maintainer closed it stating the plugin hooks system now provides exactly that: an external command hook receives the tool name, arguments, session ID and working directory, and can deny execution. No causal claim is made here and none is available, because the same maintainer noted in May that the hooks work was already merged. The proposal was closed as satisfied, not as the cause. What the close did produce is the follow-up on whether a blocking hook should fail closed.

Two posts ship where the other project asked for them, one of them invited by the maintainer who closed our previous request

Day 165 outward done

An alignment reply on bernstein #2554, posted after checking the claim it responded to and dropping a count that did not hold against the pull request body. And goose #10866, proposing a configurable fail-closed mode for blocking pre-tool-use hooks, written because the maintainer who closed our earlier #8742 invited exactly that follow-up in the close. Both are cases where the second ask was welcome only because the first one was declined cleanly.

MCP 4.0.0 ships dual-era 2026-07-28 support; the deploy exposes and fixes a pre-existing bridge outage

Day 165 Protocol done

The MCP server moved to the v2 package family and now serves MCP 2026-07-28 and 2025-era clients on one stdio entry, with 32 under-declared fields across 23 tools corrected at the validation boundary and both eras exercised on the wire, passport semantics verified with the published SDK in each. Deploying the child to the hosted bridge exposed that sessions were already dead: a committed stale build snapshot imported a symbol no published SDK exports, while the health endpoint stayed green because it reports the express process rather than the child it spawns. The fix removes the artifacts, points the spawn at the installed package path, and a live public session answers initialize, lists 150 tools, and returns a real call. The ship ran as three separately approved gates: npm 4.0.0, GitHub release, MCP Registry metadata, bridge 2.24.0.

An introduction request is declined, and the reversal is recorded with its cost

Day 164 outward done

A request to make an introduction was declined by the principal. Recorded as a reversal with the reason, per the rule that a drop is a decision and gets logged like one rather than disappearing.

A project-formation assignment arrives for what was agreed as a lab, and is held rather than signed

Day 164 Standards done

The document that arrived assigned the protocol name, the main repository and the domains, which is the shape of a full project contribution rather than the narrow conformance lab that had been agreed. It was held, the mismatch was written back the same week, and nothing was signed. Resolved six days later against the governing documents.

Worked example anchored for the RACK protocol; bilateral negative-vector check with an independent implementation closes

Day 164 Standards done

One delegation, one approval and one receipt anchored as three CLAIM_ANCHOR payloads for the rackp.agent-ops.v1 profile draft, with all sixteen of that project's known-answer vectors reproduced byte for byte before generation and every signature verified twice, once independently against payloads fetched at a pinned commit. The accompanying prose states what an anchor establishes and what it does not: digest match and anchor signature, with timestamp and sequence as signed assertions absent a store and a chain. The same day, a bilateral exchange with an independent implementation of the duplicate-scope rejection closed with both sides' validators run against the other's tree, a call-counter proof that rejection precedes any digest computation, and byte-equal digests on the shared accepted vector.

Cross-stack token corpus rebuilt from the email of record: ten drops, twenty-seven vectors, a one-character corruption found and detected structurally

Day 163 Protocol done

The weekly agent-auth-token corpus mirrored from a partner held five of eight drops with one corrupt, so it was rebuilt from the correspondence of record: three never-landed drops reconstructed byte-identically, the corruption isolated to one dropped character in a key identifier, and a structural detector added that decodes the identifier's multicodec prefix and needs no key material or network, tested against synthetic mutations. The rebuilt family carries ten drops and twenty-seven vectors with every signature verifying and rotation asserted across five consecutive seams. The prompting failure is recorded with it: a search tool's silence was converted into a verified-absence claim, and it was false.

Sponsorship mechanics are answered concretely, and two verifier defects surface, one of them ours

Day 163 Standards done

The sponsorship question was answered with committed mechanics rather than intent. In the same pass two defects were found in verifier behaviour, one in another implementation and one in ours, and both were written up rather than only the other party's.

A coverage claim of ours is refuted, corrected, and the correction becomes the first contact

Day 163 outward done

A claim we had made about coverage did not hold when checked against the other project's actual state. It was corrected, and the correction itself was posted as the opening contact with that project rather than sending a pitch. Opening a relationship by withdrawing your own claim is a better first message than any introduction.

Lab proposal corrected before merge: renamed Agent Authority Conformance, scope pinned to the suite

Day 161 Standards done

The proposal file described the protocol as what moves to neutral ground and used the word conformance zero times, against both our own comment on the thread and the call decision on disk. Fixed in the window before merge: renamed Agent Authority Conformance, scope restated as the conformance suite and not the protocol and not the SDK. Two facts stated to the steward rather than left to be discovered: the lab repository carries the proposal's name, and an existing repository transfers only with every commit signed off, which ours cannot satisfy without misattributing an outside contributor's work. Shipped file verified byte-identical against the live branch.

The vocabulary gains an evidence axis, held orthogonal to match

Day 160 vocab done

Evidence was added to the vocabulary as an axis in its own right rather than folded into matching, so a claim about what happened and a claim about what corresponds are not forced through the same field. Committed to the vocabulary repository on 2026-07-26.

Anchored canonicalization vectors merged upstream; narrowing verifier core claimed; RFC 8785 key-order divergence filed as a finding

Day 159 Standards done

PR 2994 merged at bernstein, the strongest external review surface this project has. The maintainer verified against a fresh checkout before merging and the consuming test moved from 56 passing to 80, one file touched, schema id unchanged. His stated reason for taking these over fixtures he would have written himself was the dual anchoring: a vector anchored to two independent sources catches an implementation drifting in a way a self-derived fixture cannot, because a fixture generated from the code under test agrees with that code by construction. The narrowing verifier core, left explicitly unclaimed on Day 157 so it would not sit blocked, was reserved for us a second time and is now claimed; the design sketch is owed and is convention-setting, so it goes through a full independent adversarial review pass before it is posted. Two forks raised there stay deliberately open: inline scope versus content-addressed reference, and what a hop carrying no recorded scope means. Separately, the RFC 8785 key-order divergence was filed as its own issue rather than reconciled into a vector, at the maintainer's written request that disagreements arrive as findings. The divergence is narrow and was computed against a reference implementation before posting rather than reasoned out: it occurs only when a supplementary-plane property name is compared against a name beginning in U+E000 to U+FFFF, because the high surrogate sorts below that range while the code point sorts above it. Standing rule adopted: every sorting claim is computed against a reference implementation before it is posted. PR #2994 merged 2026-07-25T12:30:24Z, merge commit 3f8d75a6. The key-order finding was filed separately as issue #3105 and computed against rfc8785 0.1.4 before posting: the divergence occurs only when a supplementary-plane name is compared against a name starting in U+E000 to U+FFFF, because the high surrogate sorts below that range while the code point sorts above it. ASCII agrees, and supplementary against anything below U+D800 agrees. The rule that came out of it is that every sorting claim is computed against a reference implementation before it is posted.

Duplicate scope rejection fails closed in four implementations; four-registry release wave

Day 159 Protocol done

A delegation listing the same scope twice is not a well-formed request and should not reach an authority decision. The duplicate scope rejection now fails closed across the TypeScript SDK, the Python port, the Go port and the conformance suite, with two new vectors that every implementation runs, so the rule is enforced by code rather than stated in prose. The Go change is a deliberate API break: the scope canonicalizer now returns an error alongside its result, which is why it ships as a minor version rather than a patch. Keeping the old signature would have preserved a public canonicalizer that silently accepts input the specification forbids, and every downstream check would have inherited that ambiguity. Released the same day across four registries: SDK 4.3.0 on npm, Python 2.10.0 on PyPI, Go v0.5.0, MCP server 3.4.0. Suite at release: 4,360 tests registered, 4,357 passing, 3 skipped.

Receipt semantic core lands in TypeScript, Python and Go; upstream vectors delivered with one pair withheld

Day 158 Protocol done

The normalize-before-hash and validity-binding core merged across all three implementations, with a mid-ship split to keep unreviewed work out of a reviewed pull request: clean port commit carrying exactly the audited tree, fixes cherry-picked on top. The anchoring known-answer digest was reproduced with the standard library and zero repository code. The canonicalization vectors owed upstream were delivered the same day minus one divergent pair, withheld so a key-ordering divergence from RFC 8785 would not be frozen as an expected output, and disclosed to the maintainer as his call since the fix changes signed bytes.

LF Decentralized Trust accepted the conformance lab proposal; an outside maintainer took a review and pinned three encoding decisions

Day 157 Standards done

On a call with David Boswell and Hart Montgomery, LF Decentralized Trust accepted the lab proposal covering the conformance suite, not the protocol and not the SDK. The name and remaining paperwork are being settled; the repository does not exist yet and no Linux Foundation project status is claimed. The reason for a neutral home is narrow: a corpus written, run and announced by its author is self-attestation, and the same corpus exercised by implementations the author did not recruit is evidence. Separately, a review left on a stalled P1 issue at an orchestration project drew two observations from that project's own code: monetary values accumulated as floating point under a byte-reproducibility requirement, and delegation receipts carrying issuer, subject, audience and act with hash linkage but no scope, so narrowing is unprovable from the chain. The maintainer verified both, then pinned three decisions: fixed-scale integers at nano-USD with a single rounding point, rejection of non-NFC input at the boundary rather than normalization, and effective scope plus parent reference per hop so a verifier recomputes child-within-parent structurally. Canonicalization vectors claimed as a contribution slice; the narrowing verifier core left explicitly unclaimed.

Vocabulary co-stewardship proposed to DIF; well-formed-versus-verified drawn on A2A delegation

Day 155 Standards done

Opened an issue at the DIF Trusted AI Agents working group proposing that the agent governance vocabulary move to shared stewardship, editorial and implementation staying with AEOESS while naming and admission gain independent oversight as a peer to the other efforts there. The issue hands over no code and records no agreement; it is a question to the group. Separately, a comment on the A2A actor-chain delegation proposal drew the line between a well-formed delegation chain and a verified one: a subset check over caller-written scopes is a check on the shape of the reported chain, not proof of authority, because a fabricated chain narrows as cleanly as a real one. The chain stays unverified attribution until each hop is bound to something the granting party signed. Monotonic narrowing is a check on the reported chain, not a credential.

Bilateral conformance-vector exchange with a second implementation family (SCITT capsule draft)

Day 154 Standards done

On the IETF AUDIT BoF preparation thread, an independent SCITT-based agent action capsule implementation recomputed the APS content-derived action reference across four vectors including the astral-plane Unicode ordering case, cleared twelve signed decision records against its own stage model, and matched four canonicalization fixtures byte for byte. Our half was a from-scratch verifier against their frozen vector tag: CBOR decoder written from RFC 8949, COSE signature path from RFC 9052, inclusion proof from RFC 9162, imports limited to the runtime and its own modules, their verifier source and generator never opened. Six vectors, six matches, every negative failing at its declared stage, two full runs byte-identical. One vector's root reconstruction under an out-of-scope ledger profile was marked unsupported rather than faked. Cross-implementation verification, not adoption, stated by both sides in-thread. Offer to published results in about six hours.

A from-scratch COSE and Merkle verifier is run against the SCITT vectors at tag vectors-ietf126

Day 154 Protocol done

A verifier written against the specification text rather than against an existing library: its own CBOR codec, RFC 9052 COSE_Sign1 handling and RFC 9162 inclusion proofs, using platform crypto primitives only. Run against the scitt-cose test vectors at tag vectors-ietf126, commit 529515ba, across seven verification stages, each mapped to the specification clause it derives from. Both positive vectors match, including an independent full-tree rebuild that agrees on the inclusion root, and a byte-flip self-attack suite confirms each failure lands at the stage it should. Two limits are recorded rather than papered over: the published suite holds six vectors, and one vector uses a verifiable data structure whose proof profile was outside the committed scope, so its root reconstruction is marked unsupported and the receipt signature is checked over the recorded root instead.

Mingle v3 ships end to end in a day: build, deploy, email, landing page and distribution

Day 154 Product done

The connection network moved from v2 to v3 in a single arc: reshape, approval, build, deploy, email notifications live, landing page live and corrected, then distribution. Published as mingle-mcp 3.0.0 on npm with the skill inside the tarball at fifteen files, and listed on the MCP registry as io.github.aeoess/mingle 3.0.0, confirmed by an external query rather than by our own console. The registry description took two attempts at 101 characters before landing at 98, which is the small lesson of the day: measure the limit, do not count against it.

A matching layer is designed, attacked from four independent legs, and shipped the same day

Day 154 Product done

Beyond the v3 release the same day carried the design and build of the Fit and Match layer: a v3.5 specification for fit exchange, a hostile review leg against it, then Fit and Match builds, four independent review legs, a partial v4, stage three, and the final four-way merge to production with a launch audit after deploy. Recorded as its own item because the release and the matching layer are separate pieces of work that happened to land on the same date.

SDK 4.2.0: v2 surface plus the aps-mcp-1 pre-dispatch authorization profile for MCP tool calls

Day 154 Protocol done

Released through the provenance pipeline (npm trusted publishing, build-provenance attestation, SBOM). Lands the v2 surface behind draft-pidlisnyi-aps-03 and a new pre-dispatch authorization profile for MCP tools/call: a signed authorization object in the call metadata, checked in order for transport authentication, signature, target, arguments hash and recomputed action reference, then claimed once against replay before a host-supplied authority decision, with a receipt attached to the result. The middleware makes no allow or deny call of its own and stores nothing. Also lands the A2A Agent Card identity extension. Timed to an MCP specification revision; wraps the tool-call seam rather than replacing transport authorization. 4,352 registered tests, 0 failures.

Conformance suite tagged v0.1.0 at 4b9dbb0: a pinnable reference for interop

Day 153 Protocol done

The conformance corpus took its first release tag so an outside implementer can pin the exact bytes they verified against and cite them, and so interop exchanges target a fixed tag rather than a moving branch. The tag freezes the vector families as they stand, from canonical byte-contract fixtures through signed decision records and adversarial forgery cases. The README states what the tag is and is not: a seed corpus exercised across implementations, not an independent conformance program. Count discipline held under review: one family carries nine files where a reader expected eight, and the ninth was named as a production-derived divergence record, not a runnable vector, rather than left to imply a larger set. The tag is v0.1.0 at commit 4b9dbb0.

Vocabulary CI is hardened after a hostile review, and the validator stops following symlinks

Day 153 vocab done

A hostile review pass produced a set of CI changes on the vocabulary repository: the validator now rejects symlinks and contains data reads to the data root, the trusted fixture oracle runs unconditionally now that the checker is on main, identity-continuity fixture math is recomputed in CI rather than trusted from the file, and bot commits are exempted from the DCO author match for parity with the standard checker. Five handoff decay fixtures landed alongside it as PR #116, and the full APS workflow set was ported across.

draft-pidlisnyi-aps-03 submitted and live on the IETF datatracker

Day 152 Standards done

Uploaded minutes after the submission window reopened; accepted on the datatracker July 18. The archive text verifies byte-identical to the canonical working copy. Two identity drafts found by the same-day scan entered Related Work before upload. Verification rule recorded during the submission: a revision claim checks against the datatracker API or the archive file, never the rendered page, which served a stale copy from cache.

The MCP server is accepted into the largest MCP directory

Day 152 outward done

agent-passport-mcp merged into awesome-mcp-servers, listed under agent identity and delegation. The list is the default place people look when they are shopping for MCP tooling, so the entry is a distribution decision rather than a code one. The list owner merged it.

OAuth composition vectors published for review as a pull request

Day 152 Protocol done

The interop harness connecting APS signed records to an OAuth agent-authorization draft family, together with the v2 core behind -03, published as a PR built from an explicit 53-file manifest. The standalone verifier gained five evidence tie-back checks after its own description claimed more than it did, with tamper detection exercised in both directions. Merge to main is deliberately deferred to a reviewed rebase. This publishes the surface for review; it is no adoption or production claim.

Erratum: the day 46-47 MolTrust entry overstated a production partnership

Day 152 Product done

Correction of record for the day 46-47 moltrust-partnership entry. What happened in April: partner API key received, 11 APS agents bridged did:aps to did:moltrust, reciprocal gateway verification exercised. That was a bilateral technical pilot. 'First bilateral production partnership' overstated it; no commercial partnership was formalized. The original entry stays as written per the no-rewrite rule; this entry is the correction. Raised in review with Lars Kroehl.

Trusted-oracle symlink bypass found by hostile review and closed the same morning

Day 152 Ops done

An adversarial review leg showed the day-old trusted-oracle CI convention certifying a fixture tree made entirely of symbolic links into the clean base tree: zero real bytes, all checks green. Reproduced on the exact CI layout before crediting. The prior concession that an empty fixture directory exiting clean was acceptable was withdrawn on the record. Containment shipped to the live validator: symlink rejection in every walker plus a real-path check against the data root; symlink trees now fail closed. Named a security correction in the review sent back to the contributor.

Chancery crosswalk merged after five delivered asks; decision_lineage bar tightened registry-wide

Day 151 vocab done

Full-protocol review of an external court-records crosswalk with an independent adversarial leg. The pass caught a production claim in a header, a writ treated as a decision, and an advocacy clause with no place in a mapping file. Five asks posted; all five delivered on a re-reviewed head; merged same day with authorship retained. The structural grading bar for decision_lineage was then raised for every row rather than only the newest contributor, with existing rows flagged in issue #124 and their proposers tagged for recalibration with concurrence.

-03 final copy pass adjudicated: external edit list verified against disk, two misquotes rejected, battery green

Day 151 Standards done

Two identity drafts (Grenoble and Huawei) entered Related Work with titles verified against archive copies. An external copy leg produced thirty edit candidates; each was checked against the actual file before applying, and two died as misquotes of their own source. Final build passed the full battery: zero dangling citations, zero banned claim words, dash scan clean, idnits exit 0. Saturday submission runbook locked.

A settlement-layer crosswalk maps verbs across five agent payment protocols

Day 151 vocab done

crosswalk/payment_rail.yaml added at incubation status, mapping settlement-layer verbs across five agent payment protocols so a term used by one is resolvable against the others. Incubation rather than canonical on purpose: the mapping is proposed for review, not declared.

The vocabulary registry inherited the SDK's CI, and the first failure fired within minutes

Day 151 Ops done

Corpus validation on every PR and push, DCO with author matching, CodeQL, Scorecard, grouped dependency updates, branch protection requiring all of it. Fuzzing, byte-match, and release attestation deliberately stayed behind: a YAML registry has no artifacts to attest. Two catches: pre-existing fixture directories grandfathered by name with the rationale in the script rather than backfilling scope onto other contributors' vectors, and a CodeQL split-bump failure that fired live on a bot PR minutes after landing, fixed by bumping both refs together and grouping action updates. First live exercise: five dependency PRs ran the full set, three merged same day.

The draft revision becomes a rebuild: action reference commits to the target, payload digest carries a replay nonce

Day 150 Protocol done

What was scoped as an edit to the Internet-Draft turned into a rebuild of two primitives. The action reference now commits to the target rather than sitting beside it, and the payload digest carries a replay nonce so the same bytes replayed are distinguishable from the original. Three independent hostile passes were run against the revision before it was called ship-ready. One of them found a fail-open in a third-party verifier, and the same defect then turned up in the patch written here, which is recorded because catching it in our own work is the harder half.

Reversibility join objection conceded at CoSAI ws4; reachability question raised

Day 149 Standards done

A declared ceiling is a plan-time bound, and since a settled class can only sit at or below it the join tightens as the chain resolves, so it is well defined without total knowledge. Conceded. Open in its place: which set the join runs over, since joining declared steps assumes a plan bounds an agent that chooses at run time, while the grant does. APS computes neither ceiling today.

Dark is the default on first landing; lime fills fixed in light mode

Day 149 Ops done

Supersedes the Day 137 system-preference default. All twenty-one pages now open dark until the visitor chooses otherwise, and theme.js no longer re-applies the OS theme on change. Lime-filled surfaces carry near-black text in light mode; the root cause was color:var(--bg) on every lime surface while light mode redefines --bg to cream.

LFDT Lab proposal: sponsor field committed as agreed on the thread

Day 149–150 Standards done

Committed the sponsor-field change to LFDT PR #411 as promised on the thread, DCO clean, both approving reviews intact. The lab is not created yet; an approved proposal is not a foundation project. Merge sits with the stewards.

Day 148: P1 narrowing hole closed in the deployed gateway; gateway CI added; AuthZEN vectors published

Day 148 Protocol done

The gateway's narrowing check compared a child delegation's spend limit against its parent only when both carried one, so a child that omitted the limit skipped the check while the evaluation path reads absent as unlimited. A child minted under a spend-bounded ancestor could omit the field and become unbounded, with every row in the chain still validating. That is a live violation of the core invariant in deployed enforcement. Fix pivots the gate onto the ancestor being bounded; both directions tested. Root cause was structural: the gateway had no CI, so a fix sat unmerged for three days and a tree of 639 tests had not executed since April, stranded by a glob matching one directory name and not the other. CI now runs 1,510 tests, a build, a type check and a credential scan on every push. Also published aeoess/authzen-556-vectors public under Apache-2.0 (35 normative, 8 rejection, contested readings carried separately with both candidate preimages, three implementations plus an independent library), and shipped 4.1.1 to restore the SLSA build provenance that 4.1.0 lost when it was published by hand outside the release pipeline.

OpenA2A AIM expiresAt disclosure public (GHSA-m735-6r63-9h7q, HIGH, fixed 1.0.3)

Day 148–150 Standards done

Reported privately under OpenA2A's security policy: delegation verification in @opena2a/aim-sdk checked signature, key binding and scope narrowing but never read the signed expiry window, so expired delegations verified as valid and a child could outlive its parent in a chain. Sent a patch and tests; fixed in 1.0.3 and later, rated high severity. Advisory text credits the report. Their production Go, Java and LocalVerifier credential verifiers already enforced expiry and were not affected; this was the cross-engine delegation-chain primitive in the npm package. Write-up: blog Day 150.

Day 147: lone-surrogate canonicalization fix released across three SDKs; AuthZEN binding-hash vectors; reversibility fold v0

Day 147 Protocol done

Building byte-identical conformance vectors for a denial-binding hash exposed a real defect in the APS canonicalizer: it accepted a lone UTF-16 surrogate and carried it into the signed bytes, which RFC 8785 requires rejecting before hashing. The Go path was worse, with the standard decoder substituting the replacement character before the scanner ran. Fixed and released the same day across TypeScript SDK 4.1.0 on npm, Python SDK 2.9.0 on PyPI, and Go module v0.4.0. Input previously accepted is now rejected, so the minor moves rather than the patch; code that never emits an unpaired surrogate is unaffected. The vector suite carries normative, proposed, and error cases, recomputed by three implementations and checked against a fourth independent RFC 8785 library, offered in openid/authzen#556 as a pass or fail target. A first reversibility fold also landed, unexported: a per-effect classifier with a content-addressed profile registry and typed lineage states, with one unsound path removed at review that had granted compensable status on a self-declared recovery reference alone.

Day 146: two-phase reversibility model settled in the open

Day 146 Protocol done

Worked the reversibility model out in a public standards thread on secure design for agentic systems before building it. The design that held is two phases: a declared reversibility ceiling before execution and an instantiated fold after, computed from the bindings the action actually carried rather than what it promised. The governing rule is fail closed, so an effect missing a reversibility binding counts as irreversible rather than assumed harmless, because reversibility depends on downstream outcomes and does not narrow monotonically the way authority does. Grounded against the action-class and externality types already in the SDK so the primitive has real anchors rather than new vocabulary.

Day 145: SDK 4.0.0 published after a second audit; threshold verify-before-count and receipt v1.2

Day 145 Protocol done

SDK 4.0.0 on npm. A second adversarial audit of the fix set found real defects behind green suites, patched before release. The major is driven by two shape changes: threshold approval verifies each signature before counting it toward the threshold, changing the exported evaluateThreshold signature, and receipts move from the v1.1 to the v1.2 Merkle construction. Verifier null guards and a fail-closed correction on the governance path also land. On the conformance suite the Go runner now recomputes action_ref for the actionref-canonical vectors and asserts them, four vectors moving from recorded to checked, Go and TypeScript agreeing on the category. The same hardening is merged across the other packages with releases to follow; the MCP threshold change waits on the published SDK.

Day 144: delegated action evidence

Day 144 Protocol done

Five receipt evidence primitives across four packages: bilateral pair reconciliation, revocation observation records, Merkle evidence bundles, locked action_ref canonicalization with cross-language vectors, jurisdiction selection records. 3.3.1 makes checkAudience fail closed on untrusted aud values.

The Go implementation reproduces the TypeScript action_ref vectors, 4 of 4 byte-identical

Day 144 Protocol done

The Go implementation ran the canonicalization vectors generated by the TypeScript one and reproduced 4 of 4 byte-identical action_ref hex values, with TestActionRefCanonicalVectors passing and the package exiting 0, at loader commit 501e5da. The wording was fixed at the same time as the result: specified in section 4.1, validated by cross-language vectors. Not described as proved, because cross-language agreement on a vector set is evidence about those vectors and not a proof about the algorithm.

No new ConstraintFacet was added, because 15 is a number already on the public record

Day 144 Protocol done

The pair reconciliation work produced four new mismatch classes and none of them became a ConstraintFacet. The 15-facet count is a published claim, so the new classes live inside the pair verdict instead of quietly raising a number other people may have written down. The one case that maps to an existing facet is emitted through that facet rather than a new one. The cost is a smaller number in a place where a larger one was available.

The sprint reaches main as PR #65: four branches merged, suite at 4097 tests with 4091 passing

Day 144 Protocol done

Four branches merged through an integration branch and reached main as PR #65 at commit 1edad8c. What landed: scopeRequired canonicalization with NFC and code-point sort; an optional action_ref slot inside the signed body, mirroring the audience slot; a pair reconciliation module carrying five mismatch reasons and a verdict of reconciled, mismatch or unilateral; a RevocationObservation type; and bundle primitives with a claim-boundary report and a verify-bundle command. Post-merge state measured on a fresh worktree: typecheck exit 0, 4097 tests across 922 suites with 4091 passing, 0 failing and 6 skipped, coverage at line 93.18, branch 83.57, function 89.59, build exit 0.

OWASP deny vector merged; same-day self-correction of its claim language; aps-03 built with Related Work

Day 143 Protocol done

The denied-before-dispatch example vector merged into the OWASP Agentic Skills Top 10 with a standalone offline checker, and the fixture-corpus proposal now requires declared preimage_fields for any content-derived identifier, citing the five-field versus four-field split from that PR. An adversarial three-model review of our own merged README then found an overclaim: a self-referential hash is not tamper evidence against the record's own writer. PR #50 corrects it and states the pairing-key versus seal distinction. draft-pidlisnyi-aps-03 built with a Related Work section citing three independent drafts that converge on narrowing, delegation receipts, and a four-field action identifier. Third weekly AAT cross-stack drop verified and published; boundary page updated to exercised-by-one-vector wording.

IETF draft-pidlisnyi-aps-03 finalized: v2 rebuild, three hostile passes, all gates green

Day 143–150 Standards done

The revision became a rebuild: aps-action-ref-v2 commits to target, exact payload digest, canonical scopes, millisecond issuance and a replay nonce under a profile discriminator, replacing a v1 form that could collide within one second; receipt classes without closed wire formats removed, three records on one ReceiptV1 envelope; did:key identity with legacy did:aps read-only; PrincipalBindingV1 with verifier-reported claim levels; Privacy Considerations added; Implementation Status states exact coverage and deviations. Three independent hostile review rounds plus a scripted battery; idnits 0 errors; all 11 reference pins verified current on the datatracker. Blog: Day 150, late. Submission when the tool reopens after 2026-07-18 23:59 CEST.

LF Decentralized Trust Lab proposal received two approving reviews; awaiting steward action

Day 142–149 Standards done

Lab proposal filed Day 142 was approved and this year's LFDT TAC chair offered sponsorship. The lab is not created yet and an approved proposal is not a foundation project. Scope proposed: the lab holds the conformance suite, the cross-implementation vectors and an adversarial conformance track, while the specification stays in the IETF draft and the reference implementations stay where they are.

OpenSSF Scorecard to 8.9; esbuild advisory cleared across SDK workspaces and the conformance suite

Day 141 Protocol done

Supply-chain hardening across the public repos: dependencies pinned by hash, workflow tokens scoped to least privilege, static analysis and fuzzing on every commit, on top of the signed release. Scorecard on the SDK moved from 6.9 to 8.9, with Code-Review left at zero rather than gamed with a phantom reviewer. An esbuild advisory (GHSA-g7r4-m6w7-qqqr) patched at the SDK root was found still present in four workspace lockfiles and in the conformance suite, since root npm audit reads one lockfile and the scanner reads all of them. Fixed by bumping the transitive parent within its declared range in each place; the public conformance suite no longer ships a known advisory.

First self-signing release pipeline; [email protected] published with SLSA provenance; coverage-guided fuzzing lands and finds two real bugs

Day 140 Protocol done

A tag-triggered workflow runs the full gate, builds, publishes over OIDC Trusted Publishing with no stored token, and attaches a signed SLSA provenance attestation and tarball to the GitHub release. Version 3.2.0 shipped through it. The same release added coverage-guided fuzzing (seven Jazzer.js harnesses, ClusterFuzzLite, fast-check property tests), which found and fixed two real defects before tagging: a CBOR map-length hang in the invite decoder, and verifyPassport throwing on a non-array delegations field rather than rejecting cleanly. Both have regression coverage.

A registered evaluation returns no publishable result, and the kill criterion firing correctly is the finding

Day 139 Research done

A pre-registered encoding evaluation ran to completion at zero spend with the registration chain intact: the preregistration hash held as a byte prefix and both amendments were appended rather than edited. The kill criterion fired correctly on the first two runs, because page density exceeded the reading limit of the model under test, so no correct-read floor existed and the encodings could not be compared. A third run reached the floor and was stopped early when several agents thrashed rather than progressed; 137 of 144 trials were recovered from the workflow journal and the seven interrupted trials are marked missing rather than reconstructed. A sentinel control passed four of four, which rules out source leakage. No public claim is buildable from any of it, and the handoff says so.

Accountability-record fixture set published; first independent cold-clone recompute lands same day

Day 138 Protocol done

One signed record per boundary decision: twelve deterministic vectors including negatives, JSON schema, and two independent verifiers (Python and TypeScript) that recompute signatures and JCS canonical bytes from scratch. The README states what the record proves and what it does not: no outcome or safety claim, settlement_ref as an opaque correlation hint rather than settlement proof. Posted to the x402 post-settlement accountability thread; a thread participant cold-cloned the suite the same day and reported all twelve vectors reproducing across both verifiers with byte-parity held.

Ninth paper published (Plausibly Wrong); IETF draft revised to draft-pidlisnyi-aps-02

Day 138 Research done

Plausibly Wrong: Peer-Voted Retention Can Fall Below Random in Capped Shared Memory for LLM Agents published on Zenodo (DOI 10.5281/zenodo.21208555). A controlled isolation of the retention rule in populations of short-lived LLM agents, showing peer-voted retention kept a worse shared memory than random selection in 4 of 5 replicates, with pre-registrations, kill conditions, and an artifact record. Separately, the IETF Internet-Draft was revised and posted as draft-pidlisnyi-aps-02, adding the external correlation form, the seven-dimension authority lattice, and read-fidelity receipt and word-handle sections.

Dev log day picker

Day 137 Ops done

Sticky chip bar built at runtime from existing post anchors; zero mutation of dated bodies, byte-identity asserted at edit.

Copy re-evaluation batch shipped after a deep verification pass

Day 137 outward done

Recorded performance claims kept with their evidence lineage; two unevidenced latency rows removed; the fifteen real constraint facets from the SDK type replaced the loose card list; the claims record corrected on the facet count with commit lineage; CTEF, Regulated Action Profile finality, and the 16/16 action_ref cross-validation surfaced with recorded wording.

Media page with verified coverage entries

Day 137 outward done

Each entry links a self-verifying source: the first Agent Times article, Notarized Agents (arXiv:2606.04193) with the citation confirmed in the PDF, the UBC PDR-in-Production DOI, and the Armorer Labs critique listed deliberately.

Persistent mobile navigation: shared header and burger drawer on every page

Day 137 Ops done

The homepage header and drawer became the single shared chrome across twenty pages; drawer styles ported to the shared sheet; nav.js wires subpages idempotently.

opensource.html retired from the canonical site

Day 137 Ops done

Redirect stub to the working group with noindex; the one historical dev-log link keeps resolving.

Roadmap rebuilt as a horizontal multi-lane timeline over roadmap.yaml

Day 137 Ops done

Nine workstream lanes, day axis with real dates, row packing validated offline against all 345 entries, status-colored bars, accordion unfold per lane, hover tooltips, click-through detail, today marker. Same yaml as the source of truth.

Light and dark themes site-wide in the deck's bright-slide palette

Day 137 Ops done

System preference default with a pre-paint snippet on all twenty pages, persisted toggle in the nav and the mobile drawer, deck-style lime highlight blocks in light mode, code and receipt blocks kept as dark islands.

Site v2 design transfer started

Day 136 Product done

Design-transfer phases 1 to 3 opened to move the remaining pages onto the v2 design. A vendor-neutrality pass ran alongside it, following the Day-126 reset, so that no third-party project appears on our surfaces in a way that implies a relationship neither side has agreed to. Counterparties are not named here on purpose. Executed as local file work under the standing posting gate. The anchor stays what it was: the priority date on action_ref in draft-pidlisnyi-aps section 4.1 and the APS-hosted canonical surfaces.

Homepage redesign shipped live to agent-passport.org

Day 136 Product done

index.html replaced with the reviewed landing page (commit 840f6e7), copy through a three-model adversarial review pass plus line-by-line founder verdicts, assembled by a transform script with a hard assert on every edit, VERIFY OK locally and on the Mac. Facts corrected on the page: tests figure moved to 3,959 read live from project-state.json; footer Standard changed to Spec: draft-pidlisnyi-aps (IETF Internet-Draft); Spec CC0 removed pending a licensing decision; receipt signer_did shown as a DID URI matching SDK 3.0.0. Added a slide-10 external-validation line, a Builders-tab live-demo link to wallet.html, prefers-reduced-motion support, and a canonical plus twitter-card plus JSON-LD head block that restores build-state parsing. Rollback path preserved (prior page backed up, git revert 840f6e7); 10 of 10 content probes and build-state exit 0 on live verification.

ID-JAG binding surfaced publicly on protocol and docs

Day 136 Standards done

The verifier-first binding for the IETF ID-JAG draft, shipped in SDK 2.7.0, named on the identity sections of protocol and docs; the principal-vs-agent receipt model paragraph added per the recorded positioning wording.

always-on host retired; Intent Network API migrated to Railway

Day 136 Ops done

always-on host retired by decision; the MacBook Air is the only machine. Intent Network API (Mingle backend) migrated off the Mini to Railway (project intent-network-api, volume /data, the database path variable set, /health 200 on the Railway domain); Vercel ruled out for the stateful SQLite plus long-running Express workload. Custom domain api.aeoess.com registered on Railway with the Cloudflare CNAME plus TXT handed to Tima; a fresh DB was chosen deliberately rather than restoring the stale March snapshot. SURFACES.md updated with a machines section.

Site v2 design transfer complete: every convertible page live

Day 136–137 Ops done

Thirteen content pages plus six bulk-converted pages shipped in the v2 design with per-edit asserts; blog dated bodies byte-identical (386,837-byte region verified); iframe fragments and the interactive architecture app correctly left untouched; deploys migrated to GitHub Actions.

CSA taise-agent-v01 PR #2 provenance correction posted; never-measured figures withdrawn

Day 135 Standards done

Posted a correction on the CSA taise-agent-v01 PR #2 (issuecomment-4867787236) withdrawing the 0.65 / 0.92 / 0.88 figures from the April @aeoess comments as never-measured, per the CSA-PROVENANCE-BRIEF (Option 1, no AI-authorship layer), with an apology to agent-morrow and a recommendation to mark the inherited threshold table provisional. First of five posts on return from a five-day cluster-driven GitHub silence, all reviewed before posting.

Return from five-day silence: five threads answered on spec surfaces

Day 135 Standards done

Five posts after a cluster-driven absence: the CSA correction above; a vocab PR #114 hold (the LiteLLM #31295 anchor did not verify, single trust domain, fixture-only); an AutoGPT #12700 reply mapping four operator questions to SDK 2.9.0 / 3.0.0 primitives; a vocab #36 reply to nutstrut confirming the Path B wrapper checks with a two-wrapper fixture committed; and an AIP #13 convergence add on the agent_id / signing-key rotation split. Engagement kept to technical substance only, no product mentions, with a fresh canary wave logged and held on silence.

Hosted gateway money-path hardening deploys after five adversarial review rounds; Go SDK gets the honest verified split

Day 133 Protocol done

Receipts are signature-verified at ingestion before storage. Root authority is an origin property: never inferred from current edges, designated only through an audited admin action, demoted in the same transaction when a root accepts an inbound delegation, restored only by explicit audited re-designation. The grant path re-verifies grantor status, root standing, and inbound liveness inside a write-locked transaction, closing a cross-process window where a revocation could be outrun. Schema migration is transactional and marker-gated. Go's TraceBeneficiary adopted the TS 3.0.0 resolved/verified split with real Ed25519 and a cross-implementation oracle test. Week-three AgentLair AAT vectors verified and landed in the conformance suite.

Go TraceBeneficiary resolved/verified split merged; boot-split and memory consolidation executed

Day 133 Ops done

The agent-passport-go TraceBeneficiary resolved/verified split merged to main (3b8c128) after an independent gate (full suite, cross-impl oracle PASS not skipped, gofmt clean): Resolved reports lookup success and Verified now requires a real Ed25519 check; temporal validity in VerifyDelegation remains the queued follow-up.

SDK 3.0.0: traceBeneficiary.verified becomes real Ed25519 verification, resolved carries the old lookup semantics

Day 132 Protocol done

A breaking major: verified now means the receipt signature and every delegation hop pass cryptographic verification; lookup success moved to a new resolved field with an honest name. Python 2.6.0 ships the same pair with byte-identical RFC 8785 canonical payloads shown identical in both directions. A second primitive shipped alongside: CompositionCheckV0, a stateless verifier for composition-check receipts on the RAP-v0 produce/verify split, result as a four-value enum with no safe boolean anywhere in the type, attestor independence classified from the caller's trust context.

OWASP AIVSS #32 reply posted: enforcement-factor calibration pin (revoke-to-enforce window)

Day 131 Standards done

Reply posted on OWASP AIVSS #32 (issuecomment-4835893053) after VeloGerber agreed the placement (enforcement state multiplies into action_class_ceiling, not beside it) and ran a counter-projection across his 648-cell corpus. The one substantive pin: the residual mapping is sound only if worst_lag_ms is the revoke-to-enforcement propagation window specifically, not general processing latency, and he was asked to confirm which quantity the trial series records before the magnitude hardens. His projection numbers were not restated as ours; his reproduction offer was accepted with a commitment to re-derive the residual independently from the corpus rather than run his script.

Vocabulary PR #113 merges with the lifecycle rule holding: a promotion without two independent implementations stays withdrawn

Day 131 vocab done

The replay_class promotion from decision_replay to full_replay was withdrawn by its author after review under the registry's own lifecycle rule: canonical status requires two independent implementations, and fixture-only declarations do not count as production-emitted artifacts. A gate-logic loosening introduced in the same PR (conjunctive promotion conditions weakened to a disjunction) was caught in review and corrected by the author before merge. The registry's governance did the work the Day 126 rule was written to do.

APS x 1Password live demo at AGI House: delegated spend with the secret never entering the agent's context

Day 130 outward done

Built and staged at the Agent Identity Build Day hackathon: an agent requests spends, the gateway decides from signed delegation math, and the credential stays in 1Password. Allow inside budget executes with the real key; over-budget and prompt-injection attempts are denied before the resolver is ever called; every decision lands as a signed receipt attributable to a key. The agent's context carries only an op:// reference. Demo repo public.

Conformance vectors gain verification_mode tags; the vocabulary README leads with the registry, with a five-system crosswalk as the example

Day 129 vocab done

Six cross-encoded conformance vectors were tagged with the verification_mode field agreed with MolTrust (runtime versus structural), committed to the conformance suite. The governance-vocabulary README was rewritten to open with a neutral definition of the registry itself and to use behavioral_trust as the worked example, the signal with the most independent issuing systems in the registry (five), shown as a crosswalk table rather than any single project as the hero. A staleness pass corrected the public architecture page's test and crosswalk counts.

Coordinated security release across four surfaces: parent-signature verification, fail-closed chain validation, currency-guarded spend

Day 128 Protocol done

An adversarial hardening pass across the TypeScript, Python, and Go SDKs plus the MCP found and closed a related family of authorization gaps. subDelegate now verifies the parent delegation's signature before minting a child in all three SDKs, closing a chain-forgery seed. Go's ValidateChain fails closed on a missing not_after. Spend narrowing rejects a currency-unit change once a delegation carries one. MCP capability tokens enforce expires_at at mint and use, and RFC 9421 verification enforces the expires parameter. Released together as TS 2.9.0, Python 2.5.0, Go v0.2.0-alpha.3, MCP 3.2.4, each fix landing with the adversarial vector that finds it.

amavashev PR #47 merged: CyclesEvidence signer-authority verify wiring

Day 127 Protocol done

PR #47 merged (squash de03f5d) as Claude's technical call under Mutual Mode after amavashev returned the three additive fixes from the Day-126 Track-B review, rebased onto main, and resolved the test-manifest collision. Re-checked at source on the PR head: authentic means signed by the named signer's window-valid key (not authorization, not freshness); signerDid surfaces only on a passing-signature path; an optional expectedEvidenceSigner pins the signer and fails closed. Full suite 3884 tests / 3881 pass / 0 fail / 3 skip on the final form (the +14 are the new authority tests). SDK primitive on the public side of the boundary; contributor credited via a co-author trailer.

Regulated Action Profile v0 ships in SDK 2.8.0: finality requires two trust domains outside the operator

Day 127 Protocol done

The Regulated Action Profile v0 adds a deterministic, stateless verifier and a typed receipt for actions of class rank three or higher. The verifier counts independent trust domains rather than signatures: it returns reconciled, or the regulator_grade_for_class level above it, only when a pre-committed intent reconciles against two anchors outside the operator's trust domain, the identity provider that authorized the actor and the resource's system of record, with the domain count at least two, the resource confirmation validated under an independently registered key, and the intent anchored in time before the effect. judgment_correctness is always not_claimed; the receipt type has no field for model reasoning. 33 conformance vectors pin every disposition, including a hostile operator forging one side of the reconciliation, and an independent pure-standard-library Python verifier with its own Ed25519 and JCS reproduces the decisions. The public SDK carries the primitive: types, the verifier, the vectors, and a verify-regulated CLI subcommand. The reference build runs its boundary attestation at a weak level, so an honest single-machine run reports intent_precommitted; reconciled is gated on a deployment whose attestation node is a separate principal. Receiver receipts, intent pre-commitment, and co-signing are prior work; the composition of an external IdP authority as the second domain with a verifier-computed domain-count finality gate, in an operator-as-adversary setting, is the new part. Full suite 3919 pass, 0 fail, 3 skip.

OWASP AIVSS enforcement-effectiveness §3.2 reply posted; cycles integration arc closed out; AAT week-2 ingested

Day 127 Standards done

GitHub-ops sweep: an adversarial-review-hardened reply advancing the exact-versus-bounded position to the bounded, action-class-anchored side (VeloGerber/aivss-enforcement-effectiveness#1, issuecomment-4792098022), with two review-caught pre-post errors fixed. Three close-outs, all reviewed before posting: amavashev #25 and #43 confirmed closeable end-to-end and closed on our repo (completing the cycles integration arc across #27/#39/#41/#42/#43/#46/#47), and a UCP #540 close-the-loop for a real implementer's tightening. AAT weekly cadence week-2 validated (2026-06-24) end-to-end against the live agentlair.dev JWKS on an independent path and ingested to the conformance suite (cherry-pick 85d3ca4).

AuthZEN binding_token engagement: openid/authzen #516 and PR #532

Day 126 Standards done

On openid/authzen #516 the binding_token shape (a detached, self-contained, by-value signed assertion over the denied tuple for an independent ARS) was proposed; McGuinness opened PR #532 applying that shape. A follow-up on #516 affirmed the resolution and flagged that by-value inline versus a binding_hash folds two guarantees together (inline is self-describing; a hash only commits, so the ARS must already hold the tuple), reposted on #532 at his request. Live external standards front, engaged in good standing.

ID-JAG (BUILD 3) binding shipped to main; SDK 2.7.0 published to npm

Day 126 Protocol done

The public-SDK ID-JAG to APS delegation binding (verifier-first, pinned to draft-ietf-oauth-identity-assertion-authz-grant-04) shipped to main (fast-forward 5b466ad) after a rebase that preserved the temporal-narrowing fix, a typecheck-clean pass, 18 binding tests, and a full suite of 3842 pass / 0 fail / 3 skip. Published as SDK 2.7.0 on npm (latest tag, 2026-06-23), bundling the ID-JAG binding plus BUILD 1 (spend-unit narrowing), BUILD 2 (verification_mode), and the subDelegate temporal fix. Framed as a binding at the draft §9.7 seam, verifier-first; never ID-JAG depends on APS.

Signal types in the governance vocabulary now carry a lifecycle: canonical requires two or more independent implementations

Day 126 vocab done

A signal type used to become canonical on addition, so a single issuer's term could sit at the same status as a reviewed one with nothing recording its support. The vocabulary now has a status lifecycle: canonical requires two or more independent implementations; a term with one implementation is proposed, carrying a review_by date and a promotion trigger; a term with no implementation is reserved, also dated, removed by default at its review date; a term with no status is treated as proposed, never as canonical, so silence cannot confer status. Two definition rules accompany it: a definition states what the signal is without naming or depending on any one implementer, and a term cannot cite its own issuer as the ground for its status. The full fifteen-term registry was re-sorted under the single rule. The validator enforces status, the review_by sunset, and definition purity, and rejects a canonical claim with fewer than two independent issuers.

Spend-unit narrowing: a child cannot change the spend unit once a delegation has one

Day 123 Protocol done

Once a delegation carries a spend unit, a sub-delegation can narrow the amount but cannot change the unit the amount is measured in. A child that switched the unit could otherwise restate the same number against a different denomination and pass an amount check while stepping outside the parent's spend constraint. The guard rejects a unit change at narrowing once a spend dimension exists, with adversarial cases in the vector set. Separately, the action-ref-v1 conformance vectors gained a verification_mode field marking whether each vector is structurally enforced, backward compatible so a reader that omits it treats the vector as enforced, with the JavaScript and Python runners printing a tally; no code path or hash changed for that annotation. The first implementation was a bug rather than a boundary preference: a parentUnit default of currency rejected legitimate narrowing, where an unconstrained parent has a child introduce a metered budget, and six passing tests passed only because none exercised that path. The fix gates the guard on the parent actually carrying a spend limit or an explicit unit. Independent verification on a separate instance: 3817 passing, 0 failing, 3 skipped, typecheck clean.

subDelegate temporal narrowing fixed: a child delegation can no longer outlive its parent

Day 123 Protocol done

Time was the one narrowing dimension not holding at delegation creation, while scope, spend, and depth narrowed correctly. Two creation-time defects combined: createDelegation built expiry with setHours and an || 24 default that coerced a deliberate zero-hour window into 24 hours and dropped fractional hours; and subDelegate computed the child window as a duration from one reading of the current time, which createDelegation then re-based on a later reading, so a child outlived its parent by the gap and an already-expired parent produced a fresh 24-hour child. The fix uses millisecond math, reads the current time once, rejects a parent whose expiry is non-finite or already past, and sets the child's absolute expiry to the earlier of 24 hours from now or the parent's expiry, signed directly so no relative duration enters the signed object. Invariant: a child's expiry is at most its parent's, to the millisecond, at any depth. Creation-time enforcement matching the current SDK narrowing model; no verify-time or chain-level temporal check is added. 10 new red-then-green vectors; full suite 3824 pass, 0 fail, 3 skip.

APS delegation-chain vectors cross-encoded into the AAE signed-JWS envelope, verified against its reference verifier, merged to the conformance suite

Day 122 Standards done

The four APS chain-envelope vectors (valid narrowing accepted; widened scope, expired parent, and revoked parent each rejected, the revocation a check-time cascade) were re-expressed in the AAE signed-JWS envelope shape and run through its reference verifier. All four were schema-valid and returned the expected verdicts, with rejection reasons matching that verifier's own strings. Format differences are recorded next to the vectors rather than smoothed over: APS enforces as a rule a constraint AAE marks as a SHOULD, the envelopes differ in signing, and one constraint-monotonicity case the AAE set covers is noted as a gap. The cross-encoding merged to aps-conformance-suite main and was posted to the A2A working thread.

External action_ref correlation key confirmed byte-for-byte against an independently anchored Arbitrum trail

Day 122 Protocol done

A separate implementation anchored an action trail on Arbitrum and published its action_ref with the four-field preimage on x402 #2332. APS recomputed the external action-ref-v1 key two ways and both matched the anchored value byte for byte: once with a plain RFC 8785 JCS canonicalization plus SHA-256 with no APS code in the path, and once with the published APS verifier in conformance/action-ref-v1. The preimage of action_type, agent_id, scope, and timestamp is the entire surface, so any verifier reconstructs the key from the receipt with no runtime dependency on the originating implementation. This is two implementations converging on one derivation, not a dependency of one on the other, and it is the external correlation key, distinct from the native multi-scope request-identity form.

did:cycles key resolution aligned to the hash-bound, window-gated model (aps#46 merged)

Day 121 Protocol done

The did:cycles resolver moved off the did:web-style origin-rooted form onto the model settled on the Cycles thread: the identifier subject is sha256(server_id), the key set is fetched from a path derived relative to that same server_id rather than the origin (closing a cross-tenant key-confusion class), and a key is selected by the validity window covering the receipt's issued_at rather than by whichever key is current. Resolution fails closed when no key's window covers issued_at, when a window bound is missing or non-integer, when more than one key matches with no kid to disambiguate, or when the named key carries private material. This is the resolver model-alignment half only; the resolver is exported but not yet reached by any live verification path, so it lands additively. No Cycles-conformance claim ships before the stacked follow-up lands.

Vocabulary validator accepts a per-system verified_at map; cap_vocabulary v0.2 merged

Day 121 vocab done

The validator now accepts a crosswalk's verified_at as a per-system map rather than a single date, measuring the staleness window from the oldest per-system date (PR #112), so a multi-protocol file records when each system was checked. cap_vocabulary v0.2 merged (PR #109) with upstream citations pinned to specific commits, descriptive-not-universal normative framing, and intra-decision ordering left unstated where the source spec states none.

action_ref two-key architecture documented: native receipt-signing form and external cross-system correlation key

Day 120 Protocol done

APS carries two action_ref primitives with intentionally different preimages, now stated explicitly across the SDK and the standing descriptions. The native form signs APS receipts with a multi-scope array and a second-precision timestamp; the external form is the single-string, millisecond key built for cross-ecosystem correlation, which is the one that matches the joint draft and the one other stacks test against. Neither form bends to the other, and the standing line that action_ref converged through the joint draft refers to the external key.

Crosswalk registry gains an evidence standard for third-party claims, enforced by the validator

Day 120 vocab done

The vocabulary contribution guide now governs how a crosswalk carries a claim about an outside system it did not author: a qualifier travels inseparably with the claim it qualifies, the claim is attributed to whoever verified it, publicly verifiable is the unmarked default while weaker bases are marked in the displayed cell value rather than a hidden sibling field, the described system keeps a standing low-friction right of reply, and a missing capability is recorded as what was searched and not found rather than asserted as a fact about the system. The validator backs the mechanical part: an expired reverify date with no fresh evidence fails the cell to a stale state, elapsed time never upgrades a cell, and negative fixtures that must fail run in their own pass and are asserted to fail so a clean production run stays meaningful.

AEOESS-built independent action-ref-v1 conformance set merged into argentum-core (PR #14)

Day 119 Protocol done

A second, separately authored conformance set for the cross-ecosystem action_ref form landed in the joint draft's reference implementation, in its own aps/ directory alongside the recomputation fixtures from PR #12. Fifteen vectors, ten accepts and five rejects, reproducing the draft's first appendix vector byte for byte. Two derivations written to the same spec text, kept in separate trees, landing on the same bytes; the set is kept as its own author-set rather than folded into the reference vectors, since the cross-lineage agreement is the interoperability evidence and holds only while the paths stay visibly independent.

An argument about where authorization attributes come from is taken up by an OpenTelemetry pull request author

Day 119 Standards done

On the OpenTelemetry semantic-conventions proposal for agent authorization observability, the position argued here is that these attributes cannot be populated by model-call instrumentation, because they are not properties of the inference: they are outputs of whatever component made the authorization decision. A second contributor quoted that to the reviewing maintainer, and the pull request author then restated it as his own answer. Still open.

Independent conformance set for the action_ref correlation key lands from a separate author-set

Day 116 Standards done

An independent Internet-Draft of the action_ref primitive (giskard09/draft-giskard-aeoess-action-ref) picked up an AgentGraph conformance set built with its own RFC 8785 path in Python and Node, reproducing Appendix A Vector 1 byte for byte (fdd7f810...3d89f5a) and covering the empty-scope-vs-absent and did:key edges. Reviewed and accepted as a distinct author-set rather than merged into the reference vectors, since the cross-lineage agreement only holds while the derivation paths stay visibly separate. Proposed the Appendix A.1 wording, including the normative boundary that an action_ref match is not evidence of execution. Independent re-derivation is the interoperability evidence that was previously missing.

Runnable delegation layer for mcp-clickhouse, on the maintainer's own pass-through sketch

Day 116 outward done

A ClickHouse maintainer on mcp-clickhouse #155 asked for a runnable example of the delegation layer on top of their UserPassthroughMiddleware credential sketch. Shipped aeoess/aps-clickhouse-mcp-delegation: an agent holds a scoped, time-bound delegation instead of the user's full access, each tool call writes a signed authority-boundary receipt into a table next to the query log, an out-of-scope drop is denied and recorded as a signed outside receipt, and a tamper test edits a stored row by hand and verification fails on that exact row. Installs from PyPI, runs in one command against a local server. Self-contained: no dependency on any AEOESS-hosted service.

Receipt admission vectors land in a Kubernetes SIG conformance set

Day 116 Standards done

Conformance vectors for receipt-based admission contributed to kube-agentic-networking, so an admission decision about an agent action can be checked against fixtures rather than against a description. Merged.

Python SDK 2.4.0 published stable to PyPI; default pip install carries the Wave 1 accountability surface

Day 116 outward done

pip install agent-passport-system now resolves to 2.4.0 rather than an older line. The release carries the Wave 1 accountability primitives the ClickHouse example depends on: scoped delegation, the authority-boundary receipt, and the scope-of-claim field that records what a receipt does not assert. Verified end to end from a cold clone: fresh venv, unpinned install from PyPI, example runs green. Post-release audit and full-fix pass: README de-staled from 2.3.0/alpha framing, classifier set to Production/Stable, datetime modernized while preserving signed canonical-byte format, cross-language parity confirmed intact (568 passed in full environment).

AAT/APS boundary published as a joint AgentLair x AEOESS reference; weekly AAT vector cadence begins

Day 115 outward done

Session identity inside the issuer versus delegation chains and receipts after handoff, stated with explicit what-each-layer-does-not-claim sections and a three-claim bridge (jti, al_nid, al_trust). Live at agent-passport.org/aat-aps-boundary.html. The bootstrap AAT pair was ingested and signature-checked against the issuer JWKS; weekly live+expired pairs begin 2026-06-17, with vectors carrying verification_time so the corpus stays replayable.

action-ref-v1 recomputation fixtures contributed upstream to argentum-core (PR #12); mirrored in the conformance suite

Day 115 Protocol done

Fourteen vectors built to the argentum-core conformance conventions: five positives double-derived (shipping computeExternalActionRefV1 plus an independent stdlib path, byte-equal), nine negatives across four drift families (field order, timestamp form, casing, payload) where every claimed ref is a real digest of its stated drifted bytes. The runner has a single canonical recompute path; fail-closed-before-invocation is structural. Mirrored under fixtures/cross-stack/action-ref-v1-negatives with provenance.

Public-surface refresh: repo one-liners, vocab README, org profile, diagrams, 2.6.0-stable numbers everywhere

Day 115 Ops done

Six repo descriptions rewritten purpose-first; vocabulary README rebuilt problem-first with a real crosswalk row and a three-layer diagram; org profile rewritten around the receipts line with a protocol diagram; SDK README gains narrowing-chain and gateway-boundary diagrams; stats aligned to 2.6.0 stable across SDK, Python, and conformance surfaces.

Two registry crosswalk reviews land a shared standard: pinned citations, descriptive vs proposed semantics, implementer sign-off

Day 115 vocab done

payment_rail (PR #100, five-protocol settlement-verb mapping) and cap_vocabulary v0.2 (PR #109, narrow/redirect cap families) both reviewed to the same bar set this week: upstream citations pinned to commit SHAs, composition and execution-order rules marked as descriptive of cited implementations or proposed interpretation rather than universal behavior, family minting rules stated in-file, and explicit approval from the second implementer recorded on the PR. SpendGuard approved #109 with a ground-truth correction confirming the rule downgrade was right: their spec defines cross-decision merge strategies but no intra-decision order.

Signed aps.txt governance declaration live on agent-passport.org

Day 114 Ops done

The canonical domain now serves its own signed machine-readable governance declaration at /.well-known/aps.txt: fresh Ed25519 domain keypair, terms mirroring the original aeoess.com declaration, verified offline against the live bytes. Closes a site-migration drift where the path served a placeholder while being cited as live.

CTEF folds cache-as-derivation key_source definition into v0.4 transactional receipt

Day 114 Standards done

The cache-as-place laundering hole raised on A2A #1829 resolved by definition rather than a fourth enum value: cache means previously verified via an allowlisted path and pinned, with the population event (source + timestamp) auditable from signed evidence. The CTEF author folded the definition into CTEF key_source and the v0.4 transactional receipt.

Outside contributor ships Cycles envelope-authenticity check (PR #45); suite at 3,792

Day 114 Protocol done

The (a) half of the envelope-authenticity split agreed in issue #43, contributed by the Cycles maintainer: the supplied evidence envelope's own Ed25519 signature verified against its named key under the spec's signature derivation, distinct fail-closed reason, and a result field reporting which guarantee actually held. Includes a boundary test asserting a self-consistent attacker forgery still passes with only the weaker tag, documenting the (b) gap as executable honesty. Merge result: 3,792 tests, 0 failures.

SDK 2.6.0 promoted to npm latest, the stable cut

Day 114 Protocol done

Both Day-105 gates closed same day: decision_id redefined as a domain-separated content hash over the record's identity fields (offline-recomputable, path-independent by construction, normative field taxonomy added to the spec), and batch/single parity shown byte-identical in the production binding under a pinned clock. Full Wave 2 surface, CPA v0.1, action_ref v1 conformance, and the payment-rail layer now install without a dist-tag. 3,791 tests, 0 failures on the publish tree.

action_ref v1 canonical specification frozen with conformance vectors and dual verifiers

Day 113 Protocol done

Four-field preimage with the timestamp pinned to one exact RFC 3339 UTC millisecond byte form, hashed as opaque bytes. Conformance suite ships negative vectors rejecting every non-canonical timestamp form and two accept vectors that byte-match independently published ecosystem hashes. Two verifiers: stdlib-only Python (vendored minimal RFC 8785, zero project dependency) and Node importing the shipping computeExternalActionRefV1, pinning vectors to running code. Non-goals stated in-spec: a pass proves derivation agreement only.

Verification-source provenance in signed evidence + producer-attestation commitment kind with CPA slot

Day 113 Protocol done

Key-resolution provenance now travels inside the signed evidence envelope rather than verifier logs, making the trust posture reconstructable offline from the evidence itself. Producer-attestation commitment kind links the Day 107 context-custody layer (CPA) into the evidence chain with the same stated boundary: custody of the declared basis, not truth of it.

An open-PR sweep merges three registry entries, holds a fourth on a validator failure, and opens a marketplace collaboration

Day 109 vocab done

A delegated review of every outstanding pull request, run under delegation without a separate review pass. Three vocabulary merges landed validator-clean at zero errors: #104 proposing cognitive_attestation as a signal_type alongside #93 carrying its rationale, merged together so the cross-reference resolves, with the determinability framework credited to its author and a two-implementation threshold gating any move to canonical; and #105 splitting two different budget_reservation state machines into separately attributed named profiles with a cross-profile map, marked descriptive and pending convergence rather than declared equivalent. #100 was held rather than merged: the substance was good but verified_at was a per-protocol map where the validator wants a single date, so the fix was requested on the thread and the contributor kept the merge. It landed five weeks later. Separately, agent-ecosystem-map #2 merged a marketplace directory listing, with a note proposing APS as the evidence layer under that project's own reputation chain rather than as a competing score.

Context Provenance Attestation v0.1 exported from the public API

Day 107 Protocol done

CPA v0.1 exported from the public API in agent-passport-system 2.6.0-alpha.10. A signed partitioned-Merkle commitment to a declared context basis across eight frozen structural-origin channels (system-config, developer, user-socket, retrieval-store, tool-result, external, memory, quarantine). The channel is a partitioning key, not a trust label, and sits in the leaf preimage so it cannot be relabeled without breaking the root. Domain-separated hashing with distinct leaf, node, and sign tags, RFC 6962 odd-promotion closing CVE-2012-2459, two disclosure modes (full-set completeness demonstrated, inclusion not), mutual cpa_ref and action_ref binding, offline fail-closed verifier with structured reason codes. Establishes custody of the declared basis as of producer-stated time, tamper-evidence, and replay resistance. Does not prove faithful capture, that the declared basis equals what the model conditioned on, which is the named open vector deferred to an independent capture boundary. Flight recorder, not seatbelt.

Go SDK reaches v0.2.0-alpha.1 with issuing and signing

Day 107 Protocol done

agent-passport-go reached v0.2.0-alpha.1, fifteen packages across the protocol surface. The v0.1 line was verify-only with no key code on the verify path, the right shape for infrastructure sinks and proxies. v0.2 adds issuing and signing: passport, delegation with monotonic narrowing and signed revocation, completion receipts, attribution Merkle with beneficiary tracing, values floor, coordination, commerce, and in-toto decision receipts. Pinned against shared canonical-JSON and CPA fixtures, including a cross-language CPA parity fixture shipped in the same cut. Pinned-to-fixtures parity is a smaller and more accurate claim than the continuous TypeScript-to-Python cross-build parity across twenty-seven scenarios.

action_ref converges across three independent implementations; W3C #34 moves the derivation into community-group text

Day 106 Standards done

The correlation key (SHA-256 of the JCS canonical form of the intent tuple, recomputable from disclosed fields alone) now has three independent implementations producing the same digest: APS, argentum-core, and raucle-detect, whose published canonicalization vector recomputes byte-identical under the APS canonicalizer. On the W3C auditability thread the normative derivation was moved out of any single implementation draft (including draft-pidlisnyi-aps) and into the community-group text itself, with the implementations listed underneath as references. Two open review items returned to the thread: the tuple must pin field types and precision (JCS canonicalizes structure, not value semantics), and mutable requested-scope was removed from the key to preserve selective disclosure on narrowed receipts.

SDK Wave 2 evidence/trust/disclosure/scope layer published to the alpha prerelease tag

Day 105 Protocol done

Twelve v2 modules published to npm alpha (agent-passport-system 2.6.0-alpha.9): evidence descriptor, trust-root policy, remote signer, revocation enforcement with security event token, audience binding, human oversight, hash-and-pointer selective disclosure, scope-dimension registry, and an offline verifier with conformance runner. The evidence descriptor is verifier-derived rather than issuer-asserted: it records mechanical signer facts, signer independence from the key graph, and a four-valued corroboration status, and refuses to emit a scalar assurance score (a test feeds a spurious assurance field and asserts it never reaches output). Stays on alpha, not latest (2.2.0), pending a content-derived decision identifier and a native batch-verify parity lane that runs green rather than environment-gated.

A2A #1463: OID4VP composes under scoped delegation for the action-within-policy question

Day 104 Standards done

Composition note on a2aproject/A2A#1463 (OID4VP for in-task authorization): OID4VP proves who and qualified-to-act; scoped delegation with monotonic narrowing plus gateway enforcement answers whether the requested action was within policy. The credential and the delegation envelope reference each other by content hash. Contributor confirmed the same attenuation model.

Cycles join-integrity check reviewed; envelope-signature verification tracked to v0.2

Day 104 Protocol done

Reviewed the contributed cycles_evidence_id_sha256 join-integrity check (PR #42): it recomputes the Cycles evidence envelope content hash and confirms it matches both the envelope id and the receipt's signed reference, reproducing the server identifier byte for byte. Request-changes posted for one doc-clarity item (a passing check proves binding, not envelope authenticity) plus two negative tests. Envelope Ed25519 verification (did:cycles / JWKS) opened as v0.2 tracking issue #43.

W3C #34: accountability-record subsection proposed (commitment, decision, receipt)

Day 104 Standards done

Posted the subsection shape on w3c-cg/ai-agent-protocol#34: three records along an action (commitment, decision, receipt), each referencing the next by content hash with none embedding the other, serialized as plain W3C verifiable credentials linked by digest. Contemporaneous reasoning binds in the decision record; the belief layer is referenced not inlined. Records carry admissibility evidence, not truth. Offered to draft the normative subsection text against the shape.

AIVSS enforcement-effectiveness v0.2: bound-parity language confirmed clean

Day 103 Standards done

Reviewer confirmed the section 1.3 reconciliation onto bound parity reads without contradiction: two substrates whose security windows land inside the same bound establish that the dimension measures methodology, not backend. Closes one v0.2 prerequisite; third-substrate reproduction and the empirical block-rate threshold remain.

Cycles permit receipt carries authority_state_at_admission, signed inline

Day 103 Protocol done

The Cycles payment-rail permit receipt now records delegation revocation and expiry state at admission time, signed into the receipt body rather than deferred to a separate lookup. An offline verifier sees the authority state the gateway saw at admission. The Cycles adapter contributor ran a verb-shape pass over crosswalk/budget_reservation.yaml confirming reserve, permit, release, and refund shapes match the Cycles surface.

agent-passport.org: 'Where it plugs in' section and honest integration grid shipped

Day 103 Ops done

New landing section between the open-source case and the integration grid. The grid lists real connections without inflation: payment-rail bindings (x402, AP2, ACP, Stripe issuing), the agent-protocol surface (MCP tools, A2A adapter), the gitagent-protocol merged cryptographic-identity layer, and framework adapters (LangChain, CrewAI, AutoGen). Closing line frames the bindings as connective tissue, not a dependency claim. Remaining pages moved onto the dark theme with one canonical nav and footer.

A2A #1628: trust.signals[] consolidated into a single signal-type specification

Day 101 Standards done

Consolidated trust.signals[] extension posted on a2aproject/A2A#1628 into one signal-type specification rather than per-vendor scattered fields, giving downstream verifiers a single shape to route on.

A2A #1850: Identity Trust Framework roadmap separates native section 4.1 action_ref from the external correlation key

Day 101 Standards done

Identity Trust Framework roadmap (v1.0 to v2.0) posted on a2aproject/A2A#1850. Keeps the native draft-pidlisnyi-aps-01 section 4.1 action_ref as the primitive APS receipts sign while emitting or carrying the shared external action-ref-v1 correlation key, so APS receipts retain their own preimage and still interoperate on the shared key.

Microsoft AGT #1609: resume-time stale-auth answered with the receipt model and per-principle enforcement modes

Day 101 Standards done

On microsoft/agent-governance-toolkit#1609 the LangGraph adapter's resume-time case got grounded in the signed PolicyReceipt: a resumed action keeps its actionRef but produces a different compoundDigest when the evaluation outcome changes, so stale authority is legible without replaying the verifier. A contributor advanced the design by placing delegation_chain_root in LangGraph checkpoint metadata rather than the user's TypedDict state schema. The block-vs-audit question resolves to per-principle EnforcementMode (inline blocks, audit records, warn warns) with PolicyVerdict permit/deny/narrow, where narrow clamps a resumed action to still-valid authority instead of halting the graph. Receipt-model reply posted; enforcement-mode follow-up drafted and pending review.

W3C AI Agent Protocol #34: auditability gap mapped to content-addressed APS artifacts

Day 101 Standards done

On w3c-cg/ai-agent-protocol#34 the three auditor questions (who authorized, what decided, what committed) got mapped to APS artifacts that cross-reference by content hash: intent carries a content hash of its unsigned form, a compound digest binds the intent hash and the policy-receipt hash, and a receipt can name the previous receipt by hash, so an auditor walks authority to decision to commitment to receipt over canonical forms without a shared stack. Direction for the white-paper subsection is vocabulary-first with APS and AgDR as implementation bindings under protocol-neutral text. Mapping reply posted; vocabulary-first subsection and binding-example PR drafted and pending review.

behavioral_drift_window signal_type lands as longitudinal envelope complement

Day 99 Protocol done

New signal_type with a window-snapshot envelope bundling N constituent attestation hashes across a declared time window, plus caller-supplied metric placeholders: decision_count, class_distribution, optional confidence_mean and confidence_stddev, optional baseline_ref paired with divergence_score. The SDK validates internal shape consistency only (decision_count matches array length, class_distribution sums match, baseline pairing complete, confidence range bounded). The SDK does not compute drift. Drift analytics stay in @aeoess/gateway per the public-private boundary that landed in April. Complementary to the existing streaming drift family in SDK v1.41.0+ (divergence_signal, baseline_revision, observation_window, trust_velocity, decision_lineage, ScopedReputation ring buffer, DecisionLineageReceipt) co-issued with the PDR project per Nanook PDR v2.19 §6.6. 26 tests, twelve documented edge cases. Commit 6b09ccc on feat/v2-behavioral-drift-window, merged via --no-ff.

Depends on: d99-substrate-cycle-2-shipped

cross_issuer_attestation signal_type lands as federation primitive

Day 99 Protocol done

New signal_type with a composer-signed bundle of references to N constituent attestation envelopes, where each constituent can be from a different issuer and a different signal_type. The composer signature attaches the composer to that specific bundle; tampering with any constituent reference invalidates the composer signature. Validation enforces unique constituent hashes, max 280-character composition_purpose, ID and timestamp format. Downstream verifies each constituent independently. Cross-protocol composition between APS and AIIF is a separate artifact deferred to a position paper. 10 tests with explicit duplicate-hash and reorder coverage. Commit c2ee817 on feat/v2-cross-issuer-attestation, merged via --no-ff.

Depends on: d99-substrate-cycle-2-shipped

memory_provenance signal_type lands as OWASP ASI06 substrate

Day 99 Protocol done

New signal_type with a signed envelope tracing a memory entry back to a trusted source under a declared reduction_map_ref. Fields: memory_ref, source.{issuer_id, issued_at, source_ref, reduction_map_ref}, ingester_id, ingested_at, signature over JCS-canonical bytes. The SDK validates Ed25519 signature and envelope shape only; verification of original source content against source_ref and validation of the reduction map against a registered transformation stay with the consumer. 20 tests, six structured failure reasons. Commit 8616b3f on feat/v2-memory-provenance, merged to main via --no-ff merge commit.

Depends on: d99-substrate-cycle-2-shipped

Substrate cycle 2 ships: three new attestation envelope signal types in npm alpha.6

Day 99 Protocol done

Three new v2 substrate modules added to the SDK as reference TypeScript implementations of three new signal_type values, each scoped to v0.1 and each with a signed Ed25519 envelope, validation rules, structured failure reasons, and a dedicated test file. memory_provenance (646 LoC, 20 tests, OWASP ASI06 substrate), cross_issuer_attestation (673 LoC, 10 tests, federation primitive), behavioral_drift_window (970 LoC, 26 tests, window-snapshot complement to the existing streaming drift family). Test count moved from 3,008 to 3,064. All three branches merged via three --no-ff merge commits preserving branch history. SDK 2.6.0-alpha.6 published to npm with dist-tag alpha. Five repos pushed clean (SDK, MCP, Python SDK, aps-web, org profile). The postpublish auto-propagate fix from earlier today held under first real validation.

A2A #1734 substrate-window intake post: five Candidates of cross-implementation trust-evidence-format substrate

Day 96–100 Standards done

Intake post on the A2A #1734 substrate-window thread acknowledging four of five Candidates as substrate-landed (Candidates 2/3/4/5) with Candidate 1 (discrimination-tuple injectivity formalism) still pending. Originating-contribution + submitted-substrate attribution discipline applied to the synthesis-matrix attribution schema, with Open Ambiguity as a third column for rows where lineage diverges across sources. Doctrine note on disk at synthesis-attribution-schema.md.

No-category-ownership-by-default precedent codified on aps-conformance-suite

Day 96 Protocol done

Two external fixture PRs (#5, #6) on aeoess/aps-conformance-suite received REQUEST CHANGES with a single structural ask: contributor deployments are credited as named targets inside generic fixture categories, not granted top-level fixture-directory namespaces. The suite names canonical properties; implementers are targets, not owners. This precedent applies regardless of technical merit and protects the conformance vocabulary from category capture as more implementers submit fixtures.

SpendGuard ships as third implementer of budget_reservation; PR #99 brings lifecycle upstream

Day 96–99 vocab done

spendguard-sdk 0.4.0 published to PyPI at 19:04 UTC with release_reservation() matching the proposed verb names in crosswalk/budget_reservation.yaml. Third production implementer joins Cycles and goodmeta, satisfying the file's promotion-path threshold of three implementers. release and refund both reach two implementers each. PR #99 opened at aeoess/agent-governance-vocabulary brings the reservation lifecycle state machine from Agent Spend Protocol Draft-01 §3.3 upstream before canonical promotion: six states, (reservation_id, idempotency_key) dedup contract with three required outcome branches, ttl_grace window with recommended_max 5 minutes matching ASP Draft-01 §3.2 phrasing. Review requested one structural amendment before merge: explicit normative-force framing on the lifecycle block.

Phase 2 HKDF receipt_stream_key derivation: 191 → 206 passing tests

Day 94 Protocol done

Phase 2 work on the Rust verifier opens on branch phase2/hkdf-receipt-stream-key. Receipt stream key derivation moves from a placeholder to HKDF-SHA-256 with explicit info string discipline, matching the §11 receipt-key derivation spec. Test count 191 → 206 with the HKDF vector additions across the wire-format, durability, and recovery layers. Stream A complete (191 tests, 12 test suites); Phase 2 stream key derivation is the first Phase 2 module to land.

Prototype 1 latency project closed across all three §13 canonical environments

Day 93 Protocol done

Full canonical scope cleared on the three environments named in spec §13: Apple Silicon developer reference (Mac M3), AWS c7i.2xlarge cloud reference (Intel Sapphire Rapids), and bare-metal Linux canonical (AMD EPYC 7313P via Latitude.sh). L4 p50: 305µs Mac M3, 1.07ms AWS c7i, 822µs bare-metal EPYC 7313P. The ~250µs gap between AWS and bare-metal at L4 is the hypervisor-removal effect. Result JSONs reproducible from benchmarks/prototype-1/results/ at commit 6e258f4. CLAIMS.md upgraded with a cpu_model pin rule for bare-metal claims since Latitude.sh ships variable EPYC SKUs under the c3-large-x86 plan. PRs #36 and #38 merged.

agent-passport.org canonical domain split completes

Day 90 Ops done

Protocol surface and company surface now separate. agent-passport.org carries the canonical protocol website, research, blog, roadmap, IETF Internet-Draft references, and the open contribution doctrine that PR #29 shipped the same day. aeoess.com continues to serve the infrastructure subdomains (mcp.aeoess.com, gateway.aeoess.com, api.aeoess.com) and a secondary website mirror.

PR #29 merged: open contribution surfaces (doctrine docs + scaffold)

Day 90 Protocol done

Open contribution path, governance surfaces, and contributor scaffold merged into agent-passport-system.

draft-pidlisnyi-aps-01 revision posted to IETF Datatracker

Day 90 Standards done

The -01 revision adds two sections to the protocol core. Signed Receipts specifies the receipt a permitted or denied action produces and what a third party can check without trusting the runtime that produced it. Key Rotation specifies how an identity rotates its signing key without invalidating delegation chains already issued under the old one. The draft also carries a visible scope marker for the attribution axes, so the boundary between what the protocol specifies and what it does not is explicit in the text itself. Seventeen pages, idnits clean on the Datatracker run.

AIVSS enforcement-effectiveness v0.1 follow-up shipped

Day 89 Standards done

v0.1 follow-up landed on aivss-enforcement-effectiveness: VeloGerber's accepted edits, Q1/Q2/Q4 amendments, four new sections, and enforcement_locus added as the seventh canonical receipt field inside the signed set. Status posted to AIVSS#31.

Hermes composition round-trip green against ScopeBlind v0.1.0-alpha.1

Day 89 Standards done

Composition round-trip verified against ScopeBlind's published signer v0.1.0-alpha.1, both paths, all integrity checks passing. Coordination posted to NousResearch/hermes-agent #11692. The fixture validates APS delegation-receipt wrapping over a third-party signer without modifying either side's wire format, the same composition-as-substrate pattern documented in the conformance suite's composition class.

PR #95 merged: jep.yaml updated for JEP draft-06 boundary

Day 88 vocab done

jep.yaml crosswalk updated to the JEP draft-06 boundary, with an Experimental Internet-Draft status marker added as a fast-follow.

draft-pidlisnyi-aps-01 submitted to the IETF Datatracker

Day 87 Standards done

Revision -01 of the APS Internet-Draft submitted. Adds Signed Receipts (section 5) and Key Rotation (section 2.3) as new normative content. idnits clean, 17 pages, sole author, expires 2026-11-15.

A2A#1850 coordination thread

Day 86–88 Standards done

Ongoing coordination on A2A#1850 with the A2A maintainers, two substantive posts across the window aligning the APS row for the coordination map.

Company/protocol domain split: agent-passport.org becomes canonical

Day 86–88 outward done

The protocol site moved to its own repo and domain. agent-passport.org now carries the canonical protocol surface (blog, worklog, roadmap, docs, research); aeoess.com is the company surface. Content pages, the canonical blog and the updates feed were migrated and the design system aligned across both.

Conformance: a2a-1496 negative-path fixtures land (4 CTEF v0.3.2 §A vectors)

Day 86 Standards done

Scaffold plus four CTEF v0.3.2 §A negative-path conformance vectors merged at aps-conformance-suite, all passing lib.ts.

gitagent-protocol#73 merged: optional cryptographic-identity RFC

Day 86 Standards done

Our RFC proposing an optional cryptographic identity layer for gitagent manifests was merged into open-gitagent/gitagent-protocol by the maintainer. The layer is optional, not a required dependency.

PR #67 merged: invariant-survival.md descriptor doc (re-land of #51)

Day 86 vocab done

invariant-survival descriptor documentation merged at the vocabulary repo, a re-land of the earlier #51.

PR #91 merged: budget_reservation.yaml v0.1 + domain_incubation validator gates

Day 86 vocab done

budget_reservation crosswalk v0.1 merged at the vocabulary repo, with validator support for a domain_incubation crosswalk_type carrying a three-concurrent cap and 90-day sunset, maintainer-only.

PR #92 merged: crosswalk/cycles.yaml v0.1

Day 86 vocab done

Cycles budget-authority signal-type rows merged as crosswalk/cycles.yaml v0.1, contributed by amavashev.

PR #96 merged: crosswalk/mycelium-trails.yaml v0.1

Day 86 vocab done

TrailRecord byte-contract adoption merged as crosswalk/mycelium-trails.yaml v0.1, with giskard09's confirmed values folded in.

budget_authority renamed to budget_reservation; reserve/query downgraded

Day 85–86 vocab done

Renamed the budget_authority namespace to budget_reservation across vocabulary.yaml and the validator to avoid semantic collision with APS delegation authority. reserve and query_* verbs downgraded from candidate to proposed. Landed via PR #91.

cognitive_attestation descriptor doc opened as draft

Day 85 Research done

Long-form rationale for the cognitive_attestation descriptor, grounding it in schchit's Target Determinability under Partial Causal Observation framework with four determinability classes. Builds-on attribution to schchit, not co-authored. Opened as a draft for theory-side review.

A2A#1829 four-way alignment: byte-match verification, v0.3.3 hosting, canonicalization stance

Day 84–100 Standards done

Three substantive maintainer posts landed on A2A#1829 the same evening. jschoemaker (Envoys SDK) independently byte-match verified our envoys-rfc9421 composition fixture against §13 Vector 2, confirmed the §13 keypair is cross-impl-deliberate, and endorsed Hippo (lawcontinue/hippo-auth) landing as a sibling at aps-conformance-suite/fixtures/composition/hippo-rfc9421/. kenneives (AgentGraph PDR/CTEF) committed to hosting the v0.3.3 shared working doc at agentgraph-co/agentgraph/docs/standards/v0.3.3-working-doc.md with three artifact slots (envelope-shape diff, unified error enum, cross-extension fixture matrix). arian-gogani (Nobulex) confirmed the canonicalization stance: JCS + numeric profile, no floats in canonical hash scope, semantic equivalence at tool-version layer not chain layer. APS reply landed same evening acking all three, refining the five-layer composition framing to per-receipt-type layer attribution (delegation_receipt at authority, bilateral_receipt at envelope, rotation-attestation at continuity). spending_authorization claim subtype response committed for May 18.

media.html press kit expanded with five new sections for State of Agent Security launch

Day 84 Ops done

Pre-press-launch expansion of /media.html with five additional sections matching the existing contact-row design pattern. Problem we solve (one-paragraph framing of the verifiability gap APS closes). Recent coverage (State of Agent Security 2026 reference with embargoed-quotes contact). Standards body work (IETF Internet-Draft, AAIF #14 in Linux Foundation CA review, A2A #1786 + #1829, OWASP AIVSS #31, agent-governance-vocabulary, OpenSSF / ACP / DIF). Business model (open protocol + commercial gateway, a pointer to the public pricing page). Recent milestones (nine dated milestones from May 3-12, 2026). Total page now 12 sections, 262 lines. og-default.png verified live at 1200×630 HTTP 200. All numbers verified against current canonical values.

PR #91 budget_authority.yaml v0.1 opens at vocab repo, amavashev approved

Day 84–86 vocab done

First-ever budget-authority crosswalk file landed at aeoess/agent-governance-vocabulary as PR #91 with six canonical verbs (reserve, commit, release, refund, query_budget, query_reservation) and per-verb candidate/proposed status convention aligned to vocabulary.yaml. Three commits on feat/budget-authority-crosswalk-v0.1 branch: 9db901a validator patch (+5 lines, parallel domain_incubation exemption to rfc_category_reverse), efa8d39 crosswalk yaml (+160 lines), ed0fdb6 amavashev review corrections. Cycles maintainer @amavashev reviewed against runcycles/client.py:97-110 + cycles-protocol-v0.yaml, flagged two corrections (query_budget + query_reservation distinct verbs not multiplexed, refund cycles row admin-plane operations note), then APPROVED. Track B review pass complete with three-engine independent review and adversarial phase. Public Track B promotion threshold (two production implementations) satisfied for four of six verbs after amavashev signoff. @Ectsang signoff on goodmeta column still open. v0.2 forward-watch flagged on Cycles /v1/decide pre-check verb pending goodmeta analog confirmation.

SSRN approves five APS research papers for academic indexing

Day 84 Research done

Five APS research papers cleared SSRN review and entered the academic indexing pipeline with DISTRIBUTED status. Paper 1 The Agent Social Contract (abstract 6677378, DOI 10.2139/ssrn.6677378), Paper 2 Monotonic Narrowing for Agent Authority (abstract 6415678, DOI 10.2139/ssrn.6415678), Paper 5 Physics-Enforced Delegation (abstract 6677418, DOI 10.2139/ssrn.6677418), Paper 7 Cognitive Attestation (abstract 6677441, DOI 10.2139/ssrn.6677441), Paper 8 The Evidence-Safety Gap (abstract 6684401, DOI 10.2139/ssrn.6684401). Each routed to five-to-six CS networks where reviewer audiences read (Artificial Intelligence eJournal, AI Law Policy & Ethics, Cybersecurity Privacy & Networks, Theoretical Computer Science, Quantum Information, Generative AI). Author page at ssrn.com/author=10731856. Crossref also requested permission to auto-update ORCID 0009-0002-4700-3594 with DOI cross-references for the published works. aeoess.com/research stays canonical.

AIVSS v0.1 review pass converged with VeloGerber on AIVSS#31

Day 83 Standards done

The review covered the Q1 to Q4 open questions, proposed five section edits and four new sections, and flagged four threat-model gaps. All decisions accepted with two strengthening amendments: a signed published-scheme artifact for Q1 and a mandatory constraint_set_sha at v0.1 for Q4. The v0.1 follow-up shipped Day 89.

envoys-rfc9421 composition fixture shipped: 3 vectors, 39 PASS / 0 FAIL

Day 83 Standards done

Shipped to the conformance suite at commit c16aa049. Three deterministic vectors over jschoemaker's @envoys/sdk v1.4.0 keypair: a plain RFC 9421 wire signature, the same wrapped in a bilateral_receipt, and that embedded as the final delegatee in a three-link APS delegation chain. SHA-256 byte identities recorded, three back-to-back byte-identical runs. kenneives endorsed it on A2A#1829 and committed to cross-link it from CTEF v0.3.2.

Libria codifies four-layer composition; three endorsements on the standalone-section promotion

Day 83 Standards done

Libria, lead author of the A2A#1496 base identity framework, posted three coordinated confirmations across A2A#1575, #1786, and #1829. The four-layer composition was codified: wire signature, identity framework, identity claims, delegation and continuity. APS delegation_receipt references #1496 chain entries as an inner cryptographic hop rather than forking the primitive. Three independent endorsements now sit on the standalone-section promotion, the production-implementer threshold for normative status.

AIVSS v0.1.1 patch: all eight VeloGerber v0.1-review findings applied

Day 82 Standards done

Patch landed direct to main at commit 0b78498 within twelve hours of VeloGerber's v0.1 review. Two HIGH plus six MED-LOW findings resolved across the substrate-count discriminator, condition-set syntax, evidence-set proof signing, and the per-condition attestation question.

argentum RFC 001 goes Active; genesis stake records committed

Day 82 Standards done

giskard09 published argentum RFC 001 at Active status on the feat/mycelium-trails branch, genesis records committed the same day. argentum consumes the APS receipt fields payment_hash, rail, amount, timestamp; stake computation reads scope through receipt.delegation_ref into the delegation chain, keeping receipt and delegation as separate layers.

Week 1 interop signals locked; nanookclaw PDR attestation key confirmed

Day 82–100 vocab done

vocab #36 reply confirmed nanookclaw's dedicated PDR attestation key. Week 1 interop locks to two signals, AgentID chain root paired with PDR continuity closing via a recompute property over evidence_inputs. Full four-signal compose with the Nobulex byte-match verifier from arian-gogani is scheduled for Week 2.

First external PR on aivss-enforcement-effectiveness merged

Day 81 Standards done

VeloGerber published the canonical race-test fixture for the time-to-enforce dimension at race-test-fixtures/audit-pack-signing-v0.5/. Three additive files: spec.md (140 lines, sha-256 c5f62c9fce6e08b55dab6dfbc8caa0196af61db1eddd0046b43dfa21c9261f28 byte-matches the WORKING-TEXT.md citation at five locations), race_test_runner.py (211 lines pure-stdlib portable runner), README.md. Fresh-checkout reproduction landed 6004 requests, 12 ACCEPTs after revoke commit, P99 4.57ms within the 50ms spec bound. PR-MERGE-PROTOCOL Track A discipline applied: phase 0 classification, phase 1 adversarial first read, phase 2 claim extraction, phase 2.5 contributor profile, phase 3 executable verification, phase 4 live invariants cross-check, phase 5 charitable read, phase 6 escalation triggers. Audit memo retained internally. AIVSS#31 follow-up posted granting redacted-incident-receipt path under race-test-fixtures/multi-tenant-isolation-precondition/.

Four-signal interop compose: PDR continuity attestation locked with three implementers

Day 81–92 Protocol done

nanookclaw committed to authoring fixtures/interop-week-1/composition-behavioral-trust.json by 2026-05-22 with PDR entity_continuity as the closing attestation. Two-signal compose locked: AgentID trust_verification as chain root (compound_digest 621d40f1701521f9af084a08476a2deebd49f02ff0b9d7e7808b6a05c6fcad91, haroldmalikfrimpong-ops), PDR entity_continuity as closing with prior_signal_digest pinned to AgentID root. Signing key approved at https://nanook.hnrstage.xyz/.well-known/pdr-jwks.json with kid pdr-continuity-2026-05. Fresh Ed25519 dedicated to PDR continuity attestations. Recompute property carried by evidence_inputs[] structured as {source_compound_digest, extracted_signal} pairs; score, slope, p-value, R^2 emitted as named fields. JCS canonicalization (RFC 8785), JWS EdDSA, SHA-256 compound_digest. Independent recompute path documented inline so arian-gogani's Nobulex verifier can validate property (c) without PDR-side code. Same harness pattern that runs 4/4 on AgentGraph and 10/10 on APS bilateral-delegation.

Pre-press-launch freshness sweep + propagate.mjs hardened

Day 81 Ops done

Two-commit pass on aeoess_web before May 12 AgentGraph 'State of Agent Security 2026' press launch. Path A (commit 8e6474f) hand-fixed seven public files: .well-known/security.txt critical fixes (publicly-visible internal note dropped, Policy header repointed from deleted /security.html to /contact.html#security), .well-known/mcp.json full version + count + date refresh (parsed by MCP discovery clients), llms.txt + llms-full.txt + README.md version bumps and dead-link cleanup, .well-known/agents.json + protocol-registry.json date refresh (65/39 days stale). Path B (commit 59ef764) extended propagate.mjs: PYTHON_VERSION case added entirely (was read from project-state.json since Day 76 but never propagated, letting alpha.0 -> alpha.3 survive three publishes), SDK_VERSION + MCP_VERSION extended with npm @-syntax patterns and prose forms, .well-known/security.txt enrolled in target list. og-default.png 1200x630 social card shipped (commit 4a4582f) with meta tags swept across 27 pages. /media.html press kit page rebuilt from redirect stub (commit 884ec79) with 10 sections of verifiable-only claims, /contact.html Press row added.

Coinbase agentkit + crewAI Guardrails ecosystem cross-pollination

Day 80 outward done

Two substantive ecosystem engagements landed today. (1) coinbase/agentkit#1091: replied to Aigen-Protocol's SafeRouter pitch with a two-layer composition reading. APS as the pre-execution authorization-receipt layer; SafeRouter (atomic-revert via TokenUnsafe custom error on Base mainnet) as the on-chain target-safety layer. Five payment-rail binding adapters in v2 cited (ACP, AP2, x402, Stripe-Issuing, MPP); SafeRouter could slot in as a sixth via vocab crosswalk. (2) crewAIInc/crewAI#4877: proposed a common GuardrailDecision audit-metadata shape (verdict, namespaced reason_code, decision_id, policy_id, timestamp, provider-specific metadata bag) responding to @0pen7ech's question. Two providers converged on the shape so far (APS + AgentID via @haroldmalikfrimpong-ops, who corrected L0-L3 and folded in concrete reason_codes). Vocab crosswalk merge 9aef69a anchors the GuardrailDecision-deny semantic at the canonical-vocabulary layer.

Cross-rail PaymentReceipt locked with Mycelium + Asqav

Day 80 Protocol done

Three independent persistence surfaces (APS, Base mainnet via Mycelium, RFC 3161 + OpenTimestamps via Asqav) aligned on the existing PaymentReceipt shape with zero new types. Permit/revocation/re-issue lifecycle fixture landed in src/v2/payment-rails/stripe-issuing/fixtures/. Mycelium companion PR #24 merged with anchoring framing tightened post-hostile-review (Base mainnet anchoring queued, not yet live). Posted on stripe/ai#356 thread.

Mycelium cross-rail anchoring confirmed live on Arbitrum One + Base mainnet

Day 80 Protocol done

argentum verify endpoint returns dual-chain anchors per receipt-id under anchors.arbitrum (chain_id 42161) and anchors.base (chain_id 8453), with real block numbers and tx_hashes for all three cross-rail fixture trail_ids (permit / revocation / re-issue). Three-surface alignment operational with on-chain commitment: APS receipt structure (Ed25519 + JCS + SHA-256, cross-language byte-parity TS plus Python), Mycelium TrailRecord dual-chain anchored, Asqav protectmcp:lifecycle (RFC 3161 timestamp + OpenTimestamps async). CLAIMS.md entry marked RESOLVED. Cross-rail fixture metadata updated in lock-step with the deterministic generator at SDK commit 24f5bdd (receipt IDs unchanged; metadata only).

OWASP AISVS revocation-to-enforce dimension engagement

Day 80 Standards done

VeloGerber landed empirical race-test receipts on owasp-aisvs#31 (P50 to P99 = 0.00ms across 18,000 requests, open-sourced fixture). Replied proposing a three-axis composition for v1.0: structural enforcement (binary, x1.0/x2.0) times empirical block-rate (RMF, continuous) times time-to-enforce (continuous, VeloGerber's dim), with structural axis dominating. Tier thresholds anchored to user-perceptible action time per rail type rather than fixed ms cutoffs. Also flagged enforcement_locus in {customer, vendor, hybrid} as a fourth dimension worth pinning before v1.0 lands. Committed reciprocal APS-side race-test fixture against the SDK's revocation surface (delegation.expires_at, revoked_at) so the dimension reads reproducible across two implementations rather than one. Soft deadline 2026-05-21.

OWASP AIVSS enforcement_effectiveness working text co-authorship accepted

Day 80–100 Standards done

VeloGerber concurred on all four points and proposed a four-axis dimension structure for v1.0: structural enforcement (binary, multiplier), empirical block-rate (continuous via RMF receipts), time-to-enforce (tiered with rail-anchored thresholds), enforcement_locus (enum, vendor-trust dependency). Co-authorship accepted with scoping that keeps the artifact tight: a working document on the enforcement_effectiveness dimension family, separable from the broader AIVSS v1.0 rubric. Inviting #32 contributors into the same working text since the structural-axis-dominance argument depends on the §3.2 cryptographic-enforcement multiplier they pinned. Cadence proposed: v0.1 to v0.2 cycle, v0.2 to include any third-implementation reproduction (Nobulex, asqav, Mycelium, AgentID candidates).

OWASP race-test runner shipped: methodology portability across two substrates

Day 80 Standards done

Open-source race-test runner against APS SDK's RevocationStorage primitive landed at SDK commit 20de7e9. Same methodology shape as VeloGerber's audit-pack-signing v0.5 fixture (4 workers, 500 qps, 3 seconds, 3 runs, 18,000 requests; revocation fires at run midpoint; measure time from revocation commit to last ACCEPT for the revoked delegation). Day 80 baseline: 18,000 requests, 0 ACCEPTs after revocation commit, P50/P95/P99/MAX = 0.00ms across all percentiles. Identical headline numbers across two independent substrates (in-process Map vs SQLite WAL multi-process). Methodology portability empirically established. Public-commitment closed within 12 hours of being made on a formal standards-body surface.

Pricing page goes live with working checkout

Day 80 Ops done

The pricing page went live with a working end-to-end checkout, moving the commercial surface from a description to something a buyer can actually complete. Payment, webhook handling with signature verification, and the welcome path were wired and tested together rather than shipped as separate pieces. Operational endpoints, event names and provisioning posture are deliberately not published here.

Vocab system_attributes wave: three merges, two opens, one under review

Day 80 vocab done

Three vocab merges and two new opens against the system_attributes enum from #77. PR #78 (nutstrut SAR system_attributes) and #79 (nutstrut continuity-analyzer system_attributes) merged Track A with conformant values (classical, jcs-rfc-8785, sha-256) after maintainer-edit fixed schema-conformance drift. PR #86 (validator enum enforcement) merged so future drift bounces at CI. Issue #87 opened on temporal-correctness gap (system_attributes lacks maintenance-status binding); recommended Option C (punt to v0.4, revisit on first cross-impl byte-match divergence) endorsed by AgentID maintainer @haroldmalikfrimpong-ops. PR #88 (validator soft-fail warnings on non-string values + unknown attribute names) opened. PR #89 (kenneives AgentGraph crosswalk, +403 lines, closes #82 hygiene gap) under hostile review with all live claims verified (5 URLs, JWKS to DID cryptographic chain, CTEF spec_anchor commit, vocabulary.yaml issuers_in_production cross-reference).

Vocab validator blocks phantom-issuer drift

Day 80 vocab done

PR #86 opened on agent-governance-vocabulary. CI validator now rejects any signal that lists a third-party issuer in production without a corresponding registry entry at maturity:in_production. Structural prevention of the failure class surfaced by the Day 76 audit (RNWY listed in behavioral_trust and wallet_intelligence without registry presence, three additional phantom issuers downgraded to proposed). Validator added to scripts/validate-crosswalks.js as validateSystemAttributes(). Same session: #84 (asqav step-2 fixture) and #85 (AgentID crosswalk file) merged, #68 (Cursor Hooks crosswalk) merged, #50 (alexchenai SWORN crosswalk parked) closed for good, #78/#79 schema-mismatched values corrected via maintainer-edit awaiting nutstrut ack.

IETF Internet-Draft v2

Day 80–90 Research done

Updated draft-pidlisnyi-aps-00 with attribution primitive and constitutional modules.

Depends on: build-a-attribution-primitive, paper-5-attribution-primitive

bilateral_receipt three-position convergence with AgentGraph

Day 79 vocab done

kenneives (AgentGraph) replied substantively at 2026-05-06 05:55 UTC on vocab #81 with concurrence on three positions. (1) bilateral_receipt as the canonical name, preferred over mutual_receipt because reciprocal is not bilateral, and over acknowledgment_receipt as too vague. (2) Hybrid-registry pattern for purpose discriminator: canonical primitive shape with registered_purposes enum, matching the CTEF v0.3.2 §4.5.4 substrate-vs-primitive layering. Avoids the proliferation failure mode (delegation_bilateral_receipt / covenant_bilateral_receipt) and the divergence failure mode (purpose stays implicit, downstream verifiers cannot route). (3) issued_at promoted to normative: TTL semantics need a signed timestamp anchor or fresh-vs-replay cannot distinguish. Track B PR queued behind one open question: arian-gogani (Nobulex) purpose-name preference between covenant_handshake, covenant_completion, and lifecycle_attestation. Schema YAML committed to vocab #81 thread.

A compliance-as-code plugin is proposed to Semantic Kernel

Day 79 outward done

Proposal to Microsoft Semantic Kernel for a compliance-as-code plugin covering regulated flows, so policy evaluation sits in the framework rather than in each application built on it. Open.

Three-thread vocab momentum in 24 hours

Day 79 vocab done

Three substantive vocab threads progressed within a 24-hour window on 2026-05-05. Vocab #36 (four-signal compose test): jagmarques offered an asqav fixture for step 2 (action authorization) using previous_hash = sha256(JCS(prior_receipt)) chained-receipt digest discipline matching RNWY's middle-slot fixture, plus a one-line PR adding authors: field to crosswalk/asqav.yaml. Reply confirmed both. Vocab #76 (red-team adversarial verdicts): msaleme opened with the question of where adversarial-verdict signals fit in a vocab canonicalizing positive-framed signal types. Reply proposed adversarial_verdict as a new signal_type with concrete schema (subject, test_class, attack_vector enum, verdict, severity, test_run_id, issued_at, signed_by) and polarity at signal-type level rather than as a property field on existing types, citing the closed enum work on error_code and refusal_authority as precedent. Threshold for lock: second production issuer. Vocab #81 documented separately above.

Tier-2 binding-adapter conformance harness landed

Day 79 Protocol done

55-test harness committed at b505c22 against agent-passport-system payment-rails surface, raising the conformance suite to 2,911 total tests. Validates that every binding adapter claiming to honor bilateral receipts produces byte-equivalent envelope output when fed the same canonical input. Test surface includes happy-path bilateral confirm, partial-acknowledgment refusal, replay rejection on duplicate action_ref, and JCS-canonicalization equivalence across three adapter implementations. Closes the Tier-2 binding adapter conformance commitment (Day 76 internal tracker).

Updates panel: tag colors restored, link contrast brightened

Day 79 Product done

ship tag now renders P.green (was falling through to ink4 gray). Most updates are ship entries so the panel was reading as monochrome. Link colors brightened in both palettes for readability against dark and light surfaces (light #1a4fa0 to #2563eb, dark #7cacde to #93c5fd). Applied to deployed index.html plus six JSX sources that define kindColor locally (opensource.jsx, restrained.jsx) and the palette source-of-truth (tokens.jsx). v1/v2 destructure the shared window.kindColor and pick up the fix automatically. subpages-1.jsx already had ship: P.green; tier2.jsx uses a different vocabulary unrelated to the Updates panel. Commit 8534ca1.

Full website redesign shipped

Day 78 Product done

Six commits land the v4 redesign on aeoess.com: 33-page restrained design language, per-page SEO meta with JSON-LD Organization schema, removed Updates rail from the homepage to recover hero focus, working desktop dropdown menus without React, fully wired navigation and footer (every href points to a real page), APS logo clickable, '8 papers' linked to ORCID 0009-0002-4700-3594, draft-pidlisnyi-aps-00 linked to IETF datatracker, agent-discovery <link rel='alternate'> tags in <head> on all pages (llms.txt, llms-full.txt, AGENTS.md, .well-known/mcp.json, .well-known/aps.txt), new /sitemap.html overview catching the 17 secondary pages no nav reaches, and a runtime dark/light theme toggle. Footer tagline updated from 'Open protocol for governing AI agents' to 'Open-source enforcement protocol for AI agents'.

Bilateral receipt cross-impl byte-match against qntm v0.3.1 fixture

Day 77 vocab done

APS canonical-bytes path on src/core/bilateral-receipt.ts (canonicalize(body), sorted-keys JSON; RFC 8785 JCS for the v2/accountability bundle module) verifies 5/5 against desiorac's bilateral receipt fixture in corpollc/qntm v0.3.1. This is third-party byte-match independent of the Wave 1 cross-language scenarios published Apr 30 to May 02 (Python 2.4.0a1 ports across 27 fixture scenarios). Mirror offered into aeoess/aps-conformance-suite as a regression test ahead of desiorac's qntm v0.3.2 mid-May publish; desiorac is a substantive bilateral-receipt contributor distinct from the broader vessenes thread.

Phase 4.1 alpha across four registries

Day 77 Protocol done

Phase 4.1 of the SDK published to npm ([email protected]), PyPI (agent-passport-system==2.4.0a2), ClawHub (agent-passport skill 5.9.0), and the MCP server on npm ([email protected]). Three architecture decisions merged earlier in the day: Q1 (rail receipts as accountability evidence with claim_type, scope_of_claim, and timestamp fields), P12 (DID URI signing with rotation-aware verifier walking RotatableDIDDocument.verificationMethod and respecting retiredAt markers), Q2 (optional PaymentObligationRef and cross-receipt link fields for hybrid Option C settlement binding). Test count moved 2,711 to 2,884 across the three branches.

Cross-language byte-parity reached across full Wave 1 surface

Day 76 Protocol done

Python SDK 2.4.0a1 ports the full Wave 1 governance surface from TS SDK 2.6.0-alpha.0: v2/accountability/* (action, authority-boundary, bundle, custody, contestability), v2/cognitive_attestation/*, v2/instruction_provenance/*. Plus the four evidentiary type safety primitives (claim_evidence_types, claim_verifier, downstream_taint, minimal cascade ContestabilityReceipt) ported earlier in the day as 2.4.0a0. Cross-impl byte-parity verified across 27 test scenarios: 15 evidentiary type safety (9 verifier + 6 cascade) plus 12 Wave 1 (5 accountability fixtures shipped from TS SDK at src/v2/accountability/fixtures/*.fixture.json plus 7 generated for cognitive_attestation and instruction_provenance via tests/v2/fixtures/wave1/_generate.mjs pinned to [email protected]). Python canonical-JSON output and sha256 hashes match TS-generated fixtures byte-for-byte across all 27 scenarios. Test count 398 to 518.

SDK 2.6.0-alpha.0: v2 evidentiary type safety primitives

Day 76 Protocol done

Four new v2 modules: claim_evidence_types registry with BATCH_ATTESTED and EVIDENCE_CUSTODY_HELD extensions (Module 1 + Module 1a), claim_verifier (Module 2), contestation cascade with verifier hook (Module 4). Plus path-scoped cycle detection and dedupe in mergeTaints (resolves cross-chain skip case caught in property test). Compliance-complete failure scenario added for EFFECT_SAFETY_ATTESTED. Postpublish wrapper fixed to surface real errors instead of masking them. Test count 2,545 to 2,586 across the day.

Vocab phantom-issuer audit: PR #74 + PR #75 merged

Day 76 vocab done

Two cleanup PRs landed in the agent-governance-vocabulary repo. PR #74 removed RNWY from behavioral_trust and wallet_intelligence after verification couldn't confirm those signals are issued in production. PR #75 marked passport_grade with status: proposed (downgrade from canonical) because APS is currently the sole production issuer and the canonical-promotion rule requires two independent implementations. Single-source-of-truth discipline maintained. Vocabulary registry now reflects only verified production attributions.

Drift prevention infrastructure: four layers across eight public repos

Day 75 Ops done

Four-layer structural backstop against private-context drift into public repos. Layer 1: pre-commit hook scanning staged content against hard-block and soft-warn pattern lists. Layer 2: GitHub Actions workflow running the same pattern check on every push. Layer 3: standardized .gitignore block excluding categories that should never enter version control. Layer 4: final scan inside scripts/propagate.mjs runs the same check before any cross-surface update touches the file system. Installed across agent-passport-system, agent-passport-mcp, agent-passport-python, aeoess_web, agent-governance-vocabulary, aps-conformance-suite, agent-ecosystem-map, intent-network-api. Seventeen commits.

Vocab validator hardened: nested descriptor walk + #57 legacy whitelist

Day 75 vocab done

Two improvements to scripts/validate-crosswalks.js. Improvement 1: walks descriptor_dimensions blocks nested under signal_types.<key> entries, catching stale dimension values inside per-signal-type descriptor overrides that the previous validator skipped. Improvement 2: legacy whitelist file at scripts/legacy-descriptor-overrides.yaml preserves three pre-#57-resolution descriptor uses (dcp-ai active today, jep and fidelity-spec latent until those maintainers reformat) without warning maintainers, with resolution_issue annotation. Validator state post-hardening: 5 errors, 11 warnings across 26 crosswalks. Regression-tested with nested-descriptor fixture using deprecated value (errors as expected, baseline restored).

Vocab PR #72: completion_ratio canonical signal type proposed

Day 75 vocab done

Per #64 thread three-issuer convergence, completion_ratio proposed as new canonical signal type with descriptor enforcement_class advisory, validity_temporal windowed, refusal_authority consumer_policy, invariant_survival post_action, replay_class fingerprint_only, governed_action_class delegate. Three production issuers cited: AgentID rolling 180d, APS configurable defaulting to 90d, RNWY derived 24h via peer_review. New constraint completion_ratio_method (signal_extension type) formalizes the strict-vs-quality-weighted choice with values [strict, quality_weighted] and default strict. Tagged Harold Frimpong (AgentID) and Douglas Borthwick for review.

Merkle batch commitments (completeness proof)

Day 75–107 Protocol done

Extend existing buildMerkleRoot() into periodic gateway commitments. Public Merkle inclusion proofs let any consumer check "these are ALL the receipts for this agent in this window." Closes the completeness gap, today we can show any receipt is authentic but cannot prove the set is complete. Lives in the SDK as a primitive + in the gateway as a cron-emitted commitment.

Depends on: build-c-settlement-pipeline

A2A #1786: Nobulex byte-match verifier scripts acknowledged

Day 74–75 outward done

arian-gogani (Nobulex) shipped reciprocal byte-match verifier scripts at github.com/arian-gogani/nobulex/tree/main/scripts: verify-aps-byte-match.mjs and verify-ctef-byte-match.mjs. Acknowledgment posted to A2A #1786 thread. Reciprocal verification queued for Day 75 morning: run Nobulex's scripts against APS fixtures, post receipt artifacts to thread, link both verifier scripts from APS fixture README. Pattern: APS publishes fixtures, peer publishes reciprocal verifier, APS publishes counter-verification, the loop closes byte-by-byte. This is the ninth way of verifying APS fixtures.

VeritasActa verify PR #7: cross-layer integrity 10/10

Day 74 outward done

VeritasActa Knowledge Unit bundle with sidecar-anchored APS DecisionLineageReceipt verifies end-to-end against a sidecar JWKS. Ten access receipts, all hash-matched across both layers (KU layer and APS layer); APS signature valid against sidecar JWKS kid:aps-ku-cross-verify-v1. Tamper-detection holds across both layers when individual receipts are altered. The integration demonstrates that APS DecisionLineageReceipts can ride alongside an external knowledge-attestation format without either layer needing to absorb the other; the sidecar JWKS pattern lets the consumer verify both layers independently and cross-check at action time.

Vocab PR #66 merged: Edison's Agent-DID crosswalk

Day 74 vocab done

Edison Munoz Duran's Agent-DID crosswalk lands as the second co-drafted-with-aeoess crosswalk in the vocabulary. The first was the original AAIF entity_continuity work; this is the second public collaboration where aeoess and a co-author share the spec branch. The A2A composition contract co-drafting now runs on a shared spec branch with Edison; APS pushed the canonical spec to edisonduran/agent-did spec/a2a-composition-contract branch (commit 3fc3838); Edison confirmed pull. The pattern: external project authors a crosswalk, aeoess merges, then both projects co-draft the next interop primitive on a shared branch. Ecosystem hospitality compounding.

Wave 1 accountability MVP shipped: five signed receipt primitives

Day 74 Protocol done

Wave 1 accountability surface added to SDK v2.5.0-alpha at src/v2/accountability/. Five signed receipt types: ActionReceipt (aps:action:v1), AuthorityBoundaryReceipt (aps:authority_boundary:v1), CustodyReceipt (aps:custody:v1, eight event types and seven purposes), ContestabilityReceipt (aps:contestability:v1, affected-party challenge with controller response), APSBundle (aps:bundle:v1, signed aggregation envelope with balanced Merkle commitment). All RFC 8785 JCS canonicalized, all Ed25519 signed, all content-addressed. Design principle: verbal confessions, not brain scans. Every receipt declares scope_of_claim with explicit does_not_assert; honest scope is mandatory and part of the cryptographic integrity surface. 57 new tests across six suites (action 8, authority-boundary 7, bundle 12, custody 15, contestability 10, fixtures 5). Full SDK suite 2,536/2,537 pass, 0 fail, 1 pre-existing skip. Cross-impl byte-match anchor: five deterministic JSON fixtures using fixed Ed25519 private keys and timestamp 2026-04-30T00:00:00.000Z. Ships toward EU AI Act Article 12/14, GDPR Article 22, FRE 902(13)/(14). MCP v3.1.1 picks up the dependency, Python v2.3.0 ships for parity, ClawHub skill v5.8.0 carries the new surface.

ORCID profile 0009-0002-4700-3594 live

Day 73 Research done

ORCID profile populated as Independent Researcher / Founder of APS. All 8 papers indexed via DOI lookup. Five featured: Agent Social Contract, Physics-Enforced Delegation, Cognitive Attestation, Monotonic Narrowing, Behavioral Derivation Rights. The Evidence-Safety Gap paper added on the same day as publication. Bio frames the protocol scope without the cross-disciplinary career narrative. Websites: APS, Personal, GitHub (APS), APS SDK on npm. Keywords mirror paper-level keywords scoped broader: AI agents, multi-agent governance, cryptographic identity, delegation, Ed25519, agent attestation, governance protocols, mechanistic interpretability, accountability, open protocols.

Paper 8 published: The Evidence-Safety Gap

Day 73 Research done

The Evidence-Safety Gap in Cryptographic Agent Governance: Compliance-Complete Failures and the Limits of Receipt-Based Accountability published on Zenodo (DOI 10.5281/zenodo.19914628). Defines compliance-complete failure as the simultaneous condition of procedural validity and unsafe effect. Names five omitted-variable classes (semantic, population, trust, pipeline, temporal state). Constructs explicit defeat traces against receipt-chain forensic signals in an open-source reference implementation. Two design implications follow: claim-scoped receipts and authorization-effect separation. Neither closes the gap; both make it visible and auditable. The minimal contribution is the formal separation of procedural validity from effect safety in receipt-based agent accountability, a vocabulary for the failure class the protocol's own success creates.

Three SSRN submissions: Papers 1, 5, 7

Day 73 Research done

Agent Social Contract (Paper 1, z.18749779), Physics-Enforced Delegation (Paper 5, z.19478584), and Cognitive Attestation (Paper 7, z.19646276) entering SSRN today. Each paper classified into five-to-six CS networks where the actual reviewer audience reads, Artificial Intelligence eJournal for the broad AI audience, Artificial Intelligence Law Policy & Ethics for auditability and governance angles, Cybersecurity Privacy & Networks for cryptographic primitives, Theoretical Computer Science for cryptography and distributed computation, Quantum Information for the IBM hardware experiment, Generative AI for the Llama-3.1 sparse autoencoder work. Classifications are routing decisions, not decoration. Author affiliation: Independent Researcher (corrected from auto-pulled GitHub Inc). Declaration of interest statements explicit about IBM Quantum and Neuronpedia third-party infrastructure use with no funding role. [APPROVED 2026-05-11: SSRN approved 5 papers per email notification.]

Two vocab pings: PR #55 and PR #51

Day 73 vocab done

PR #55 (APS↔ACTA pairwise crosswalk by @tomjwxf) pinged with three specific questions: 14-mapping distribution analysis, divergent rows + migration paths, pairwise format precedent. PR #51 (invariant-survival.md doc co-authored @QueBallSharken) pinged with three questions: BBIS phrasings accuracy, boundary-keeping section, composition partners. Both moved to waiting-on-them. CONTRIBUTING.md gate-4 wants concurrence on the PR thread itself, not just on related issues.

Vocab PR #52 merged: entity_continuity PDR validator (co-authored @nanookclaw)

Day 73 vocab done

PDR validator for behavioral-fingerprint-drift detection. 309 LOC pure-Node, zero deps, 32-test suite, four reference fixture vectors. Complementary to continuity-analyzer's structural fixture, addressing the namespace decision settled on Day 67. Co-authorship with @nanookclaw declared on PR per their explicit Apr 26 11:47 concurrence on the original issue.

Vocab PR #61 merged: epoch enum

Day 73 vocab done

lawcontinue's epoch added to validity_temporal enum: observer-relative ticks on substantive state transitions, distinct from sequence's event-relative counts. Issue #58 settled with @lawcontinue's endorsement after three-way independent convergence (lawcontinue, kenneives, srotzin) on Day 71. Vendor-neutrality fix applied during review (commit 9cf2a1db).

Vocab PR #62 merged: refusal_authority correction

Day 73 vocab done

governance_attestation.refusal_authority brought into formal enum compliance: structurally_impossible_to_violate → issuer. One-line correction; the original value wasn't enum-valid anyway. @lowkey-divine concurred on issue #57 before merge.

ATVP PR #8, REQUEST_CHANGES review posted

Day 72 Standards done

agent-governance-spec/agent-trust-verification-providers PR #8 review posted as CHANGES_REQUESTED for a structural peer_review / behavioral_trust mapping error needing correction in four places, plus three smaller items (cold-start prior, score range, naming). PR is now blocked from merge until corrections land. Lars Kroehl can independently concur or override per the spec's two-editor consensus.

First-contact email to Cursor security

Day 72 outward done

Email to [email protected] framing IPR as a structural mitigation for the recent instruction-file advisory class. Subject: 'Action time drift check for authority bearing instruction files.' Honest-scope language about what IPR does not do (it does not classify files as malicious; it only binds authority to the file state at delegation time). 5-business-day acknowledgment cadence per Cursor's published disclosure path.

Gateway proof-of-concept made public

Day 72 Product done

aeoess/aeoess-gateway-v0-poc is a minimal HTTP service that recomputes the IPR context_root against the declared file set at action time and denies if the digest no longer matches the receipt. Three case fixtures (create_pr, read_file, send_payment) demonstrate before/after deny semantics. APS is one implementation of the receipt shape; the pattern works for any agent runtime that wants to bind authority to a file-content digest.

Instruction Provenance Receipt module shipped

Day 72 Protocol done

[email protected] published on npm under the alpha tag. The IPR module at src/v2/instruction-provenance/ ships canonicalize/envelope/verify for binding agent authority to a content-addressed digest of declared instruction files at delegation time. 32 conformance tests + 27 adversarial tests passing inside the 2,479-test suite. Addresses the recurring failure mode in recent AI IDE advisories (cursorignore bypass, .git settings sandbox escape, NTFS path quirks, .vscode/settings.json injection, MCP config drift): agent receives authority under one instruction context, a workspace file changes mid-session, agent acts under instructions that were never part of the original authority context. OWASP AIVSS describes this class as Goal Manipulation. Demo branch with byte-parity-checked drift-denial walkthrough at demo/drift-denial-cursor-cve/demos/drift-denial.

Vocab #64 opened: completion_ratio canonical proposal

Day 72 vocab done

completion_ratio proposed as a new canonical signal_type. Three independent implementations confirmed in the original A2A #1628 thread (AgentID rolling 180d, APS configurable defaulting to 90d, RNWY derived 24h via peer_review sybil analysis), two-implementation rule met. Opening as issue rather than direct PR per CONTRIBUTING.md canonical-term protocol; PR follows once direction settles. Proposed descriptors: enforcement_class advisory, validity_temporal windowed, refusal_authority issuer, invariant_survival post_action, replay_class fingerprint_only, governed_action_class delegate.

Vocab PR #63 merged: agentlair trust_verify endpoint

Day 72 vocab done

piiiico added trust_verify (POST /v1/trust/verify) to AgentLair's behavioral_trust.endpoints block, a third surface alongside trust_profile and trust_gate that accepts an AAT JWT directly without requiring a resolved agentId path parameter. Endpoint verified live with proper structured 401 (HSTS, CSP, JSON content-type, 112-byte error body, production gateway behavior). 5-gate review passed clean.

agent-governance-spec org created with co-editor

Day 71 outward done

New GitHub organization agent-governance-spec hosts cross-vendor specs that should not live inside any single vendor's account. First spec is agent-trust-verification-providers (CC-BY-4.0). Lars Kroehl (MolTrust / CryptoKRI GmbH) accepted six conditions on editorial process, license separation (spec is CC-BY-4.0, reference implementations stay independent under their own licenses), MUST #2 split refinement on schema-fields versus schema-shape, implementation-name discipline, and editor-entry path. Editor line: 'Tymofii Pidlisnyi (APS by the project), Lars Kroehl (MolTrust / CryptoKRI GmbH)'. v0.1 SPEC.md drafted (216 lines), six tracking issues opened for structural decisions, Lars accepted the org owner invitation.

Vocab #58 epoch enum: three-way independent convergence

Day 71 Protocol done

Proposal to add epoch as the sixth value in the validity_temporal enum (alongside immediate, decay_window, refresh_required, expires_at, condition_satisfied). The semantic gap epoch fills: distinguishing observer-relative event sequencing from substantive state transitions, where two verifiers of the same wall-clock window may reasonably count different numbers of events but agree on coarser substantive transitions. Three independent endorsements landed: lawcontinue (distributed inference setup, 50-token generation produces 50 sequence ticks but zero state transitions), kenneives (AgentGraph CTEF v0.3.1 session_epoch maps onto epoch verbatim once the enum lands), srotzin (HiveTrust + cont_epoch on continuity layer, plus substantive-transition lower bound clause for the PR description: epoch ticks MUST be coarser than per-call I/O). Direction locked, PR followed and issue closed 2026-04-29.

Vocab #60 opened: post-quantum signature capability as vocabulary-level attribute

Day 71 vocab done

Cross-cutting question scoped on whether and how to express composite-or-post-quantum signature capability without overcommitting the vocabulary to particular algorithm choices. Three options framed: documentation-only per crosswalk (lightest), optional descriptor on signal_type (signature_capability enum: classical / post_quantum / composite), or crosscutting attribute matrix declared once per system (heaviest). Four named questions for the WG: is signature capability a property of the signal or of the issuer, should composite (Ed25519 + ML-DSA-65) be a distinct value from post_quantum, does this interact with enforcement_class or validity_temporal, and should the canonicalization profile (dcp-jcs-v1, JCS variants, undocumented) also be a crosscutting sibling attribute. Production issuers using post-quantum or composite signatures today: asqav (jagmarques, ML-DSA-65), DCP-AI (lktron00, composite Ed25519 + ML-DSA-65). Tagged jagmarques, lktron00, schchit, willamhou, arian-gogani, nutstrut, MoltyCel for perspective. No PR, no schema change, no timeline pressure. Reading the room first.

Vocab PR #53 merged: AgentNexus three-issuer fixture (Interop Week 1 Step 2)

Day 71 vocab done

kevinkaylie merged Step 2 of the four-signal compose test for Interop Week 1. AgentNexus governance attestation as the second link in the chain after AgentID's trust_verification (PR #38). JWS Ed25519 signatures verified end-to-end. prior_signal_digest matches Step 1's compound_digest byte-exact (621d40f1701521f9af084a08476a2deebd49f02ff0b9d7e7808b6a05c6fcad91). Squash-merged at 16:22:42Z. Step 3 (continuity-analyzer) and Step 4 (composition-behavioral-trust.json by nanookclaw, blocked on middle-issuer alternative) follow.

Vocab PR #59 merged: DCP-AI crosswalk

Day 71 vocab done

lktron00 (Danilo Naranjo Emparanza, ORCID 0009-0003-7520-8527) merged the DCP-AI (Digital Citizenship Protocol for AI Agents) crosswalk. 570 lines. Composite Ed25519 + ML-DSA-65 (FIPS 204 level 3) signatures shipped from day one across four reference SDKs (TypeScript, Python, Go, Rust + WASM). Real production deps: @noble/post-quantum + tweetnacl in npm. 72KB interop test vectors, 11.8KB normative canonicalization profile (dcp-jcs-v1). Calibration discipline strong: passport_grade declared non_equivalent_similar_label with 'do not treat tiers as trust grades' note, 8 explicit no_mapping entries each naming the production issuer for the gap. Version-discrepancy disclosure (npm 2.1.1 vs PyPI/crates 2.8.1) honest and explained. Identity verified: dcp-ai.org, getocular.ai, ocularsolution.com all live, 6-year GitHub account. Cross-implementation round-trip is the bar before issuers_in_production addition; lktron00 committed to running it against APS, Nobulex, or SINT this week.

aps-conformance-suite standalone repo (offered to VeloGerber)

Day 70–90 Protocol done

Offered on AARS#32 Day 65 as the path to make the §3.3 conformance bar legible rather than implicit. Lift interop/fixtures/ from the main SDK into a standalone repo with JCS-canonical test vectors covering happy-path, scope expansion, cascade revocation, chain-root verification. Any implementation (Python reimpl, Rust, Go) runs the test matrix and demonstrates conformance without needing to mirror our codebase. Not speculative, only builds if VeloGerber picks path (a) or another reimplementer signals demand. Standalone repo is cleaner to cite in OWASP/IETF documents than pointing at the interop directory of a main SDK.

Depends on: aivss-32-3-3-pr

aeoess/aps-conformance-suite v0.1.0 live

Day 70 Protocol done

Packaged corpus of byte-identical test vectors for Agent Passport System cross-implementation conformance. 37 fixture vectors across 4 categories: bilateral-delegation (10 vectors), inference-session (7 vectors), instruction-provenance (10 vectors), aivss-scenarios (10 vectors covering OWASP AIVSS §3.6.1 through §3.6.10). TS reference runner. .well-known endpoint mirror following the agentgraph.co/.well-known/cte-test-vectors.json pattern. All vectors deterministically reproducible from a fixed Ed25519 seed, JCS-canonicalized, signature-verified. Apache-2.0. Spec refs: 8 papers (Zenodo) + draft-pidlisnyi-aps-00.

MS AGT contributor-check installed across three active repos

Day 70 Ops done

GitHub Actions workflow installed on agent-passport-system, agent-passport-mcp, agent-governance-vocabulary. Pinned to AGT v3.3.0 (commit 15e001f9b53f). Profile + credential checks run on opened PRs and issues from external contributors. Cluster detection opt-in via workflow_dispatch (API-heavy). Risk threshold set to HIGH for the calibration window so only HIGH-risk events trigger public PR comment + label. Excluded actors: dependabot[bot], github-actions[bot], copilot-swe-agent[bot], aeoess. Validation runs: lawcontinue scored LOW (legit dev), mrperfectness-sketch scored MEDIUM (canary), aeoess scored HIGH (three signals fired: recent_repo_burst 41 repos in 90 days, cross_repo_spray 72 repos in 7 days, credential_laundering across 5 repos).

Discussion #20: The threat is laundering, not cyborg contribution

Day 70 outward done

Public Discussion opened in aeoess/agent-passport-system on substance evaluation as the layer above pattern detection. Endorses Imran's contributor-check tool, names that most active contributors in agent-governance today are human + AI systems (including aeoess), draws the substance-vs-pattern line. Names internal Model Citizen mode framing publicly. Includes the actual HIGH score and three signals fired against the aeoess account when run through contributor-check, framing the cross-repo activity as independent convergence rather than coordination. Companion comment on microsoft/agent-governance-toolkit#1473 linking back to the discussion.

aeoess/governance-attestation-predicate v0.1 live (in-toto sibling to Decision Receipt)

Day 70 Protocol done

in-toto Statement predicate binding agent authority-to-act: delegation chain root, principal signature, scope narrowing invariants, Values Floor attestation hash. Predicate type URI https://aeoess.com/attestation/governance/v0.1. JWS + Ed25519. Sibling to nobulex's Decision Receipt PR (in-toto/attestation#549). Composition: Decision Receipts reference GovernanceAttestation by digest in subject.digest.sha256, walking the chain exercises both axes. 5 fixture vectors deterministically reproducible (minimal-tier-1-self-delegation, multi-hop-delegation-tier-2, expired-window, monotonic-narrowing-violated, chain-root-mismatch). 29 tests pass including a composition test that exercises the full round-trip with tampering detection. Public notice posted on in-toto/attestation#549 with @arian-gogani tagged for the Apr 30 cross-impl round-trip.

Vocab PR #55 opened: APS ↔ ACTA receipt crosswalk v0.1

Day 70 vocab done

Pairwise composition crosswalk between Agent Passport System receipt primitives and ACTA Signed Receipts (draft-farley-acta-signed-receipts-01). 14 mappings: 1 exact, 7 partial, 3 divergent, 2 no_mapping, 1 non_equivalent_similar_label. Calibrated against actual shipped versions: APS 2.3.0-alpha, @veritasacta/artifacts 0.2.2, @veritasacta/protocol 0.1.1, @veritasacta/verify 0.6.0, protect-mcp 0.6.0. Migration paths documented for partial/divergent rows. Strategic posture: complementary surfaces, not competing stacks. APS specializes in delegation chain + cascade revocation + scope narrowing; ACTA specializes in selective-disclosure receipts via RFC 6962 Merkle commitment. Authored APS-side, ACTA-side review pending.

Paper 8: Cross-Family Oversight (empirical)

Day 70–120 Research done

Empirical paper built on Build G experimental data. Complementarity-gain metric measured across three AI families (Claude, GPT, Gemini) across 15 configurations and 5 scenarios. Venue likely ICLR, NeurIPS, or AISec workshop depending on how the experimental data lands.

Depends on: build-g-oversight-harness, build-e-converged-models

aps-system PR #19 merged: seven-vector CTEF inference-session fixture pack (lawcontinue)

Day 69 Protocol done

lawcontinue shipped a seven-vector test pack for the CTEF inference-session category at fixtures/inference-session/. Each vector covers a different shape of session attribution: clean handoff, mid-inference rotation, distributed cross-node, sequence-bounded validity, parent-chain Merkle anchoring, replay defense, and a negative case where the session_id does not match the canonical JCS hash. Every signature is RFC 8785 JCS-canonicalized and Ed25519-signed. Two structural fixes flagged in review (a session_ids array shape mismatch and a missing parent_receipt_hash wiring on one vector); lawcontinue pushed corrections at commits 95c1ca9c and 73d52c08 in twenty-two minutes. Second time this week he has turned a structural review around inside half an hour. The inference-session pack composes with the existing rotation-attestation fixtures published Apr 24 at aeoess.com/fixtures/rotation-attestation/, giving the SDK two distinct CTEF v0.3.1 fixture surfaces (rotation events plus inference-session attribution). Both lock through the same RFC 8785 JCS canonicalization.

Vocab PR #46 merged: AgentLair becomes the third production issuer of behavioral_trust

Day 69 vocab done

piiiico's crosswalk/agentlair.yaml merged after one round of structural revision. First iteration mapped AgentLair's TrustProfile to peer_review as primary signal type. The full v0.2 review against piiiico's live envelope and the canonical vocab definitions found that primary mismatched: peer_review is task-completion attestation signed by a delegating agent after a service agent completes work; AgentLair's TrustProfile is aggregate behavioral scoring across events with no task binding. Fix was to promote behavioral_trust to primary with match: exact and demote peer_review to no_mapping with a note explaining the definitional gap. piiiico turned that around in fifteen hours. Same commit added AgentLair to behavioral_trust.issuers_in_production at vocabulary.yaml line ~340, which now lists three independent issuers (RNWY, Logpose, AgentLair) producing real signal data against the same canonical type. That is the production-signal evidence behavioral_trust needs to remain canonical with multi-issuer coverage. Direct commit 0653c1b added AgentLair to issuers_in_production list.

Vocab PR #49 merged: PIC Standard becomes the 23rd crosswalk (action-boundary verification primary)

Day 69 vocab done

madeinplutofabio's crosswalk/pic.yaml merged at midmorning PT, mapping the PIC Standard's verification-pattern primitive to the vocabulary's canonical signal types. The crosswalk models action-boundary verification as a parallel surface to visa-layer issuance rather than a sub-field beneath it: visa-layer primitives like APS, AgentNexus, and MolTrust handle issuance-side identity and delegation tokens carried by the agent; PIC handles receiver-side fail-closed verification at the action boundary, consuming trust roots that may include visa-layer issuers but owning the verdict primitive itself. Both compose; neither contains the other. The crosswalk landed describing PIC in PIC's own terms first, with the composition pattern documented in the notes block. PIC became the twenty-third crosswalk in the vocabulary registry. Resolution of the visa-vs-verification-gate taxonomy debate that had been open on aeoess/agent-governance-vocabulary#48 for two days.

Vocab PR #51 opened: docs/descriptor-dimensions/invariant-survival.md (co-authored with QueBallSharken)

Day 69–71 vocab done

Single docs-only PR adding docs/descriptor-dimensions/invariant-survival.md, with QueBallSharken (Logpose / BBIS) as Co-authored-by: on the commit. The doc names the BBIS canonical language explicitly at three structural points so the vocabulary references the same vocabulary BBIS uses, not a parallel coinage. Closes the loop on the Apr 23 BBIS-classification-grammar adoption (ENFORCEMENT-TRUST-ANCHOR.md v1.2 from Day 67) by anchoring the same vocabulary in the descriptor-dimensions registry. Awaiting QueBallSharken review.

Vocab PR #52 opened: entity_continuity PDR validator + reference vectors (co-authored with nanookclaw)

Day 69–70 vocab done

Validator built directly from nanookclaw's slope-computation spec posted earlier the same evening on issue #36. 309 lines of pure-Node validator (scripts/validators/entity-continuity-pdr.js) with no dependencies, a 32-test suite all passing (scripts/validators/test-entity-continuity-pdr.js, 300 lines), four reference vectors at fixtures/validator-vectors/ covering stable, drifting, improving, and out-of-range agent behavior, and a long-form docs file at docs/descriptor-dimensions/entity-continuity-pdr.md (184 lines). Slope formula from nanookclaw's spec: L2 distance over four normalized fingerprint dimensions, OLS over a window of twelve sessions, max divergence of sqrt(4)=2.0, max possible slope of 2.0/(N-2), score clamped to [0.0, 1.0]. Verified scores: stable=1.0, drifting=0.9212, improving=1.0 (clamped), invalid=exit-1. nanookclaw posted the spec at 21:34Z; the validator opened at 22:52Z. Co-authored-by: Nanook on commit 069ef9a. Closes the Nanook §8 commitment. Complementary to nutstrut's structural continuity-analyzer (vocab PR #42). Awaiting nanookclaw review.

autogen-governance-adapter: first external security contribution (pshkv PR #1 merged)

Day 68 outward done

Second external contributor on the repo after EchoOfDawn's MoltBridge lane opening, and the first security-class PR. Previous _lookup_issuer_key implementation had a silent fallback: if the declared kid did not match any key in the issuer's JWKS, it would accept the first Ed25519 key in the keyset anyway, producing a silent binding failure rather than a rejection. This is precisely the class of implicit-trust hazard the composition-rule discipline in CTEF v0.3.1 §6.3 is designed to prevent. PR tightens to strict kid-match and raises UnknownKeyIdError on mismatch. 16/16 tests green post-merge. Good signal that kid/alg registry discipline (which we have been arguing for in the A2A Agent Cards and CTEF threads) is showing up as concrete patch-level work from independent contributors, not just spec-level advocacy.

Five-way claim_type convergence (AgentGraph + AgentID + APS + Nobulex + HiveTrust)

Day 68 Standards done

Wire-format substrate convergence across five live implementations on the discriminator key name. Naming collision was identified mid-thread on #1672: AgentID had been shipping claim_type on the live /verify endpoint; AgentGraph + APS rotation-attestation spec used claim_category. Same concept, same closed set values, different key name. kenne offered three resolution options and renamed AgentGraph claim_category → claim_type at commit agentgraph-co/agentgraph@69ad94d so all live implementations agree. AgentID's harold confirmed claim_type live with 32/32 endpoint tests pass and JCS canonicalizer byte-matching all 10 APS bilateral-delegation vectors. Nobulex (arian-gogani's @nobulex/crypto TS canonicalizer) byte-matching APS + AgentGraph fixtures. HiveTrust (srotzin) confirmed concur with the four-layer split + 'history-stability under rotation' framing on #1672, and posted the disjoint-namespace projection rule resolving the wire-collision concern: ctef.envelope.claim_type vs hivetrust.internal.claim_type sit at different envelope levels with explicit projection_rule mapping HiveTrust claim records onto ctef.envelope.claim_type='authority' when carried in a CTEF-composed envelope. Risk-tier bucketing under HiveTrust's claim_category stays HiveTrust-local until a future WG reservation. HiveTrust byte-match fixture committed pending claim_type.envelope composition-rule spec draft. Settlement-evidence-as-reputation-anchor (x402 receipt on Base 8453 → evidence_basis.evidence_type.payment_execution) lands on a v0.3.1-reserved field, with crewAI #4560 cited as cross-reference.

OpenClaw #49971 closed COMPLETED: integration surface defined as public plugin contract

Day 68 outward done

MoltyCel's RFC 'Native Agent Identity & Trust Verification for OpenClaw' closed by maintainer steipete (Codex review) with stateReason: COMPLETED at 04:34Z. Ruling: trust providers (APS, MolTrust, AgentLair, AgentID, etc.) build on existing public hooks rather than a new core onAgentVerify. Five hooks cited at file/line precision against commit 45146913007d: before_install (src/plugins/hook-types.ts:635, runtime invocation at install-security-scan.runtime.ts:586) for skill install gating; before_tool_call (hook-types.ts:318) for per-action enforcement at the runtime tool-call gate; inbound_claim + message_received + before_dispatch (hook-message.types.ts:16) for inter-agent verification; gateway_start (server-startup-post-attach.ts:503) for self-verification on startup. SDK reference docs at docs.openclaw.ai/plugins/sdk-overview confirm these as supported public plugin contracts. This is an architectural answer not a soft punt, different from the openclaw#43705 showcase closure (route to ClawHub, no architectural commitment), steipete did codebase work mapping the RFC requirements onto specific hook surfaces and committed them as public plugin API. Reframes the openclaw integration story: APS ships @aeoess/openclaw-trust-plugin as the integration artifact (not a core dependency) targeting at minimum before_install + before_tool_call + inbound_claim + gateway_start, calling a public trust-lookup endpoint on the gateway for per-agent JWS-signed trust attestation. ~200-300 line plugin, npm-publishable, README cites CTEF v0.3.1 substrate. Post acknowledgment to #49971 only after scaffold exists.

Rotation-attestation fixtures v1 live + canonicalization loop closed with AgentGraph

Day 68 Protocol done

Five canonical DID-document rotation-attestation fixtures plus JSON Schema plus test-vectors manifest published at aeoess.com/fixtures/rotation-attestation/. Fixtures cover happy-path, cross-signed, migration-attested, happy-path-compound (cross-signed + migration-attested in one entry, realistic production case), and negative-no-attestation (rotationLog entry with empty rotationSignature, must trigger INVALID_CLAIM_SCOPE on a conformant verifier). Every signature and hash input is RFC 8785 JCS-canonicalized; attestor is a dedicated fixture-signing key separate from the gateway with pubkey at keys/attestor-v1.pub.json and seed documented so third parties reproduce the set byte-identical from a fresh clone. v1 narrows migration_type to key_class_upgrade only; v2 extends to did_method_migration. Closes the rotation-attestation fixtures commitment on the same day (Apr 23 PT commitment, Apr 24 PT delivery). AgentGraph landed test_aps_rotation_attestation_interop.py in main at commit 8baaad4 within hours of publication, live-fetching fixtures at test-collection time rather than pinning a repo-local snapshot, dual-locking each fixture against the published test-vectors.json canonical SHA-256 AND what their canonicalize_jcs_strict produces from the live body. All five fixtures reproduce byte-identical. Canonicalization loop closed: APS bilateral delegation, APS continuity rotation, and AgentGraph CTE vectors now pin the same canonicalization through JCS bytes rather than shared code, which is the actual interop test. Pattern will mirror into v0.2 capability-token fixtures once those publish.

Vocab PR #46 merged: crosswalk/agentlair.yaml, pre-delegation behavioral check

Day 68 vocab done

piiiico's agentlair.yaml lands as the canonical pre-delegation behavioral check issuer. Maps to peer_review as primary signal type (match: exact, production data exists, trust endpoints live, behavioral event ingestion live, three-dimensional scoring operational consistency/restraint/transparency, Bayesian with cold-start prior, non-null scores on non-test agents). Secondary mappings: behavioral_trust (exact), trust_verification (partial, AAT is session auth with identity component), governance_attestation (partial, hash-chained audit trail). Eight explicit no_mapping entries with technical rationale per CONTRIBUTING.md §3.6 Seven Deep-Review Dimensions. Four-temporal-layer sequencing (pre-delegation → at-delegation → at-execution → post-execution → feedback loop) documented inline in the peer_review notes block, NOT as a new top-level section, preserves PR #44 precedent that novel top-level blocks set permissive precedent for every later issuer. AgentLair added to behavioral_trust.issuers_in_production in follow-on commit 0653c1b. Five-check protocol applied (Identity / Format / Substance / Scope / Reversibility) with STEP 0 mandatory disk-read of CONTRIBUTING.md from filesystem before applying memory-cached protocol, the slot #29 swap codified earlier in the day.

Microsoft AGT #1354 interop proposal posted to Imran Siddique

Day 67–69 outward done

Imran Siddique (Microsoft Engineering Architect driving the agent-governance-toolkit and active on the ADR-0007 cross-org federation direction in #1386) opened the door on #1354 for a concrete interop proposal between APS and AGT. Reply maps the three questions he opened #1386 with, policy precedence across orgs, evidence correlation across boundaries, trust tier compatibility, to named APS primitives that already ship in the public SDK. Policy precedence resolves through the combination of invariant_survival (pre_action / during_action / post_action / permanent) and refusal_authority (issuer / verifier / consumer_policy / shared), giving a declarative precedence grammar covering all four candidates (tool-side, agent-side, intersection, declared). Evidence correlation is DecisionLineageReceipt with content-addressed delegation_chain_root (SHA-256 over RFC 8785 JCS-canonicalized hops), which lets two verifiers independently confirm the same chain without round-tripping a registry. Trust tier semantics map the AGT TrustProvider tier enum from #1274 to the vocabulary's passport_grade plus behavioral_trust scoring; the bridge is already half-built through RNWY and MolTrust as trust_verification issuers. Four possible artifacts offered in increasing scope and without prescribing an order: vocab crosswalk entry pointing AGT's runtime evidence format at canonical terms (mirrors the rnwy.yaml and moltrust.yaml pattern); interop spec section as a follow-on ADR to #1234/ADR-0007 with canonical bytes + hash algorithm + envelope shape (APS drafts first pass, byline follows contribution during review); Tutorial 42 on cross-org delegation drafted against AGT's tutorial template; conformance fixture exchange adding AGT as a second verifier target in the existing harness. Three prior APS PRs already merged in AGT (#274 reputation-gated authority, #598 APS-AgentMesh adapter, #1328 cognitive-attestation example) provide established contribution standing. Posted 22:22 PT; response pending.

BBIS classification grammar adopted: v1.2 of trust-anchor doc, v0.2 of capability-token spec

Day 67 Protocol done

ENFORCEMENT-TRUST-ANCHOR.md v1.2 replaces v1.1's five-bucket taxonomy with the BBIS classification grammar (closed, bounded, partial, detectable-only, theater) per Steven Kyle Hensley's OWASP#817 answer. The Class B framing is tightened so typed epistemic receipts are classified as honesty discipline, not admissibility upgrade. Construction is implementation detail; invariant survival is the claim. CAPABILITY-TOKEN-SPEC-DRAFT.md v0.2 renames M4 EffectReceipt to FRCBE (Final Refusal-Capable Boundary Event) per the qntm#7 naming coined by the same author. Post-effect forensic artifacts split into a new optional M5 ExecutionReceipt; most deployments omit M5. Three-way naming convergence lands within 18 hours: BBIS (framework), APS (protocol), AgentGraph (implementation committed to CTEF v0.3 accepting delegation_chain_root by end of week). Branch feat/v1.2-bbis-grammar awaiting review before merge to main.

CTEF v0.3.1 adopts APS composition-rule table and INVALID_COMPOSITION error code

Day 67 outward done

AgentGraph pulled the four-row per-layer composition grammar (identity / transport / authority / continuity, each with its declared composition rule) from the A2A #1672 thread into CTEF v0.3.1 §6.3 verbatim as normative language. Identity composes by key binding, transport by identity-key binding, authority by monotonic narrowing with content-addressed delegation_chain_root, continuity by rotation-attestation chain. Two verifiers given the same inputs must arrive at the same composed result; layers that cannot declare a deterministic composition rule are underspecified. INVALID_COMPOSITION adopted as a distinct error code alongside INVALID_CLAIM_SCOPE, they share the ordering constraint (structural failure precedes semantic evaluation) but surface different divergence classes. APS commits to publish canonical rotation-attestation fixtures at aeoess.com/fixtures/rotation-attestation/ this week (four fixtures: happy-path, cross-signed, migration-attested, negative-no-attestation) with versioned schema and matching test-vectors.json; AgentGraph lands them under tests/fixtures/aps-rotation-attestation/ with a companion test_aps_rotation_attestation_interop.py locking byte-identical canonicalization. Concurrent spec PR plan: A2A Agent Cards PR citing CTEF v0.3.1 §6.3 for composition-rule table + error codes, v0.3.1 citing the Agent Cards PR for the four-layer split + claim_type discriminator. Both held pending @haroldmalikfrimpong-ops signal on WG direction.

Agent Ecosystem Directory shipped. Projects, people, threads as sortable tables on GitHub Pages.

Day 67 outward done

A community-maintained directory of the agent infrastructure field, built on live GitHub data. 18 projects enriched from projects/*.yaml + GitHub repo metadata (stars, license, created, last push). 115 people (filtered from 130 raw) pulled from the contribution map and enriched with GitHub user metadata (account age, bio, company, followers). 93 governance threads enriched with state, comments, participants. Three sortable, filterable tables replace the earlier force-directed graph, which was pretty but buried its data in tooltips. Account ages visible as pills (amber under 60 days, green 60-365 days, plain after), so a 3-week-old promotional account is instantly distinguishable from a 10-year veteran at a glance. Explicitly not a ranking, not a coalition, not a property of APS: the README invites co-maintainers from other projects in the directory and commits to neutral stewardship once anyone wants to co-steward. Code MIT, data CC-BY-4.0.

Full Code Audit v2.1, 42 steps, three tiers, 14 repos

Day 67 Ops done

Rewrote the CMD-SET-2 pre-publish audit from v1's 12 steps (SDK + MCP focused) to 42 steps across three tiers covering the full shipped codebase surface. Tier A Code Integrity runs test suites, typecheck, lint, build artifacts across SDK, MCP, Python SDK, Remote MCP, Gateway, Agent Governance Toolkit (405 tests), autogen-governance-adapter, vocab validator, intent-network-api, hermes-aps-delegation, hermes-decision-receipts, a2a-compliance-harness, solana-agent-identity, mingle-mcp, plus the SDK examples/ adapter apps and aeoess_web operational scripts. Tier B Supply Chain runs npm audit and pip-audit across every repo, secret scan with fixture/test exclusions, .npmignore and MANIFEST.in hygiene, LICENSE and NOTICE presence, CI workflow YAML validity and floating-action-ref detection, Dockerfile and Railway config pinning, Node engines field presence, package-lock presence. Tier C Runtime checks cross-repo version alignment across SDK/MCP/Python/Remote-MCP, npm and PyPI registry drift, live endpoint health, Gateway JWKS parity against source, committed fixture URLs reachable, the process supervisor RSS memory leak detection with proper the process supervisor-presence detection, git status across 20 repos with expected-branch check, build artifact freshness, stale artifact hunt, canonical number consistency including paper count, downstream licensee sentinel, large binary accidental-commit hunt. Self-check found 17 gaps in the initial v2 which v2.1 closes. Read-only throughout; explicit do-not-install / do-not-restart / do-not-commit-outside-aeoess_web constraints. Paste-ready for CC in one message.

PR Merge Protocol v0.2 + public CONTRIBUTING.md expansion

Day 67 Ops done

Added §3.6 Seven Deep-Review Dimensions to the internal PR merge protocol, codifying what Phase 1 (Adversarial First) and Phase 4 (Invariant Cross-Check) must catch beyond the surface checklist. Seven dimensions: Ecosystem Precedent (novel structure sets permissive template), Semantic-Primitive Mismatch (match: exact vs vocab definition), Cross-Signal Field Overlap (composition hazard for consumers), Endpoint Content Depth (HTTP 200 is not production data), Cryptographic Coherence (alg/curve/proof-type/chain pairing), Ownership &amp; Coordination (concurrence on THIS PR not related issues), Related-Issue Dependency (PR jumping ahead of open debate). Distributed across Phase 1 and Phase 4, not new phases, named patterns the existing phases must catch. Extracted from PR #43 nutstrut measurement_point and PR #44 alex-pathcourse Pathcourse Health reviews where validator-clean PRs still carried substantive issues only visible under cross-touchpoint analysis. CONTRIBUTING.md on agent-governance-vocabulary expanded from 5 one-line review questions to explicit sub-bullets under Substance and Scope so contributors can self-calibrate before submission. First PR through the public criteria (#44) merged clean after three iterations.

Third aeoess PR merged in microsoft/agent-governance-toolkit (PR #1328)

Day 66 outward done

examples/cognitive-attestation-governed/ merged into microsoft/agent-governance-toolkit at 19:41 UTC. 443 lines, two files, zero APS SDK dep. Third merged aeoess PR in the repo after PR #274 (Mar 16, reputation-gated authority proposal) and PR #598 (Apr 6, APS-AgentMesh adapter), and the first community-example-style contribution. Layering signed interpretability envelope on top of AGT's policy decision: AGT decides whether an action is permitted, the Cognitive Attestation envelope signs a sparse-autoencoder decomposition of the model state that drove the decision, downstream auditors can inspect what the reasoning substrate looked like when the action fired rather than just whether the policy rule matched. Follows the pattern set by examples/signet-attestation/ (willamhou's Signet example merged last week). Lands cleanly against the community-extension boundary formalized by ADR 0006 two days ago: policy evaluation stays in AGT core, proofs about the reasoning that produced the decision live as extensions that plug into the decision boundary without changing AGT's interface.

aeoess/autogen-governance-adapter v0.1 skeleton shipped

Day 66 outward done

New public MIT repo standing up the composition glue for autogen's before_tool_call hook. Single governedToolCall() entry point, three ordered checks (identity via APS passport, authorization via delegation scope with monotonic narrowing invariant, optional trust provider), provider-agnostic TrustProvider Protocol that MoltBridge and MolTrust both implement on the same interface. 12 tests passing (target was 9+), CI green across Python 3.10/3.11/3.12 on first push at commit 8e1c88d. EchoOfDawn at SageMind AI invited as co-maintainer with write access (invitation 315925480 pending acceptance). providers/moltbridge/ reserved as Dawn's lane for MoltBridgeTrustProvider PR, providers/moltrust/ open for MolTrust implementation. Substrate requirements ride inside delegation scope per scope-bound design, no parallel capability-tier gate. Standalone dep footprint. Adapter does not import agent-passport-system SDK.

Enforcement Trust Anchor v1.1 + Capability Token Spec Draft

Day 66 Research done

v1.1 reorganizes the enforcement-trust-anchor document around a sink-awareness boundary after sustained adversarial architectural review, replacing v1.0's flat four-closure-paths framing. Every construction is classified into a five-bucket taxonomy (full closure, subset closure, detection / deterrence, composition primitive, architectural limit) so the document no longer conflates full closure with partial or detection-only primitives. The companion capability-token spec draft at docs/CAPABILITY-TOKEN-SPEC-DRAFT.md proposes the four-component APS-aware closure stack (sink-authored canonical challenge, consumable authority tokens, sink-signed effect receipt, typed epistemic receipts) as a v3.0 research target with no fixed date; universal hygiene layers land incrementally in v2.3 through v2.5 without waiting for v3.0.

composed/v1 extends 3-signal → 4-signal via JEP PR#8

Day 66 outward done

schchit (JEP author) opened PR #8 at agentid-aps-interop extending the composed/v1 envelope we shipped yesterday with JEP as a fourth signal in the decision_event CTEF category. JEP receipt flows into slots.jep verbatim without reshape. verify.py recognizes version: jep-v1 and handles judgment events per their native semantics (gate composition skips them rather than mistreating a judgment record as pass/fail). Pattern validated: composed/v1 host stays generic, new signals register by adding CTEF category + slots.<issuer> key + native version string. Harold merged PR #7 at 09:44 UTC, schchit opened PR #8 seven hours later, first third-party extension of the composed/v1 pattern. AgentID + APS + AgentGraph + JEP now composable under one shared subject DID.

Depends on: d65-agentid-aps-interop-5-kenne

Mutual authentication v1, SDK v2.2.0

Day 66 Protocol done

Closed the protocol-level asymmetry where agents authenticated to systems but systems did not authenticate to agents. Downgrade-proof four-step handshake (hello + attest each way), local trust-anchor bundle with binding constraints and revocation, replay defence via nonces + signed timestamps + max_clock_skew_ms, downgrade defence baked into the attest signature covering chosen_version + both nonces + peer certificate, adapters for A2A and MCP. 29 new tests, 2395 total, 146 MCP tools. Explicitly does NOT ship federation, gossip, consensus revocation, cross-signing, hosted CA, or legal-entity model. Mutual auth stands on its own as a primitive; a future federation layer composes on top without changing it. Module lives at src/v2/mutual-auth/ with standalone README.

agentid-aps-interop#7: composed/v1 three-signal worked examples shipped

Day 65 outward done

First three-issuer composed envelope in the interop repo, shipped end-to-end in seven hours after slot shapes landed. PR#7 adds: (a) three APS v1 structural fixtures at fixtures/aps/v1/ (happy-path, revoked-delegation, scope-widening-attempt), (b) three composed envelopes at composed/v1/agent_interop_test_001/ stitching AgentID + APS + AgentGraph slots under shared subject DID, (c) issuer-neutral Python verify.py (jcs dep only, no APS SDK), (d) additive schema amendment 1.1.0 to 1.2.0, (e) composed/v1/README.md documenting composition contract and two-level version discipline. 51 of 51 checks pass at exit zero. Kenne ran verify.py on his machine and posted LGTM from the AgentGraph seat. Waiting on Harold merge.

Depends on: d65-harold-signing-alignment

A pre-tool-call governance hook is proposed to Google ADK

Day 65 outward done

Feature request to the Google Agent Development Kit for an interception point before a tool call runs, the same shape argued to other runtimes: the framework needs somewhere for an external decision to land before the action, not after it.

AgentID voluntary signing-convention alignment to raw digest bytes

Day 65 outward done

Harold (haroldmalikfrimpong-ops) merged PR#38 (Interop Week 1 Step 1) and then, at 08:40 UTC Day 65, came back with a voluntary alignment: AgentID's production signer switched from signing UTF-8 hex strings to signing raw 32-byte digest bytes (the option (b) from our 5-check review, the convention APS/SINT/MolTrust already use). Follow-up PR will replace the one signature field on the already-merged fixture to match the new signer. Five production issuers now converge on one signing convention: the Week 1 bundle README convention table becomes a single sentence rather than per-issuer footnotes. Materially important for cross-issuer harness verification under OWASP / IETF reviewer gaze. Acked via https://github.com/aeoess/agent-governance-vocabulary/pull/38#issuecomment-4289797509.

Depends on: harold-canonical-repo

OpenLineage#4409 covenantInEffect facet schema shipped

Day 65 outward done

Delivered the three-step schema package (JSON Schema draft-2020-12 facet + two worked examples + README with design decisions) committed on Apr 20. Five load-bearing design decisions captured: RunFacet not DatasetFacet (agent + covenant are run-scoped), digest required with resolver optional (tamper-evidence without forcing public URLs), type is open enum with governance_attestation as vendor-agnostic default, covenantInEffect.additionalProperties: true scoped to sub-object for vendor extensions, digestAlgorithm defaults to sha-256 with explicit override. Both examples (Nobulex nobulex_covenant + APS governance_attestation) validate cleanly against the schema. Two asks back to @arian-gogani: (1) review Nobulex example shape since we don't have the live receipt structure, (2) confirm covenant-hash mapping still matches v0.2 CTEF governance_attestation digest shape. Next step: upstream PR to OpenLineage/OpenLineage spec repo once arian signs off. Caught and fixed an honesty drift in the draft (speculation that arian had mentioned covenant graphs, which he hadn't) before posting.

Depends on: openlineage-4409-facet-schema

a2a-compliance-harness v0.1 repo (this week)

Day 64–68 Product done

Bounded-scope Python repo under aeoess org. Single-file script, 5-step harness (fetch Agent Card, DID resolve, signature verify, delegation chain verify, emit v1.1-compatible JSON row). Three distinct failure modes observable: signature_invalid_format_drift, signature_invalid_key_mismatch, signature_invalid_tampered. MolTrust co-maintainer access on invite. Committed Apr 17 on a2aproject/A2A#1755, this-week deliverable (~Apr 21-24).

Depends on: d61-v2-architecture-separation

AAIF TC triage decision on #14

Day 64–88 Ops done

Waiting on the AI Agent Interoperability Foundation Technical Committee to triage project-proposals#14. #12 (SINT) and #13 (similar proposal) set the Tuesday UTC precedent for TC turnaround, expected window Apr 21. Outcome shapes whether APS moves toward Linux Foundation stewardship now or the Working Group path stays the primary governance vehicle. A founder call, not a delegated one.

Depends on: d64-aaif-submission

AIVSS §3.3 commit-level evidence rows + naming boundary + conformance path

Day 64–65 outward done

Day 64 (Apr 20): boundary held on §3.3 naming when a proposal came in to co-list APS APS and AiEGIS APS as one citation. Accepted on technical content (evidence sequencing, measurement method); declined on naming, paste-ready §3.3 text names only APS APS as shipped reference, with AiEGIS APS re-evaluated at v1.0. Day 65 (Apr 21): VeloGerber accepted the naming position (22:51 Apr 20) and asked scope-clarification: does independent Python reimpl (a) or SDK-consumption (b) qualify as §3.3 production conformance evidence for AiEGIS v1.0. Answered: (a) earns a separate conformance row, (b) is a deployment pattern; v0.9 cites APS APS, v1.0 re-evaluates once (a) lands. Concrete offer: ship interop fixtures as standalone aps-conformance-suite repo so the bar is legible.

Depends on: d64-owasp-aars32-boundary

Day 64: APS submitted to AAIF (path to Linux Foundation stewardship)

Day 64–88 Ops done

Filed as aaif/project-proposals#14. Foundation submission for the public protocol layer, cross-referencing SINT #12 (Illia) and the three-vendor governance_attestation convergence with MolTrust. APS company, YC application, private gateway, and commercial partnerships deliberately excluded, commercial adjacencies stay independent of the protocol submission. Every live-artifact claim in the submission verified before posting: JWKS endpoints return 200, npm and PyPI artifacts resolve, Zenodo DOIs have landing pages, crosswalk entries validate. Gist for Illia's AAIF cover email at gist.github.com/aeoess/a622521d10625179c2d7760d83663714. Waiting on AAIF TC triage, expected Tuesday UTC per #12/#13 precedent.

Depends on: d61-v2-architecture-separation

Day 64: ClawHub skill bumped to v5.5.0

Day 64 Ops done

Numbers-only minor bump on the agent-passport ClawHub skill. Description, SKILL.md line 3, and SKILL.md line 181/184 all synced to the current surface: 124 modules, 2,366 tests, 142 MCP tools. _meta.json description rewritten to match. v5.4.0 already existed on ClawHub from an earlier auto-publish cycle; bumped straight to v5.5.0 to reflect on-disk state. Commits 00b40fd + 6e43f99.

Depends on: d64-v210-cognitive-attestation

Day 64: Thirteen substantive partner engagements

Day 64 outward done

Context: the structured ecosystem map from Day 61 rebuilt Sunday night, today's response queue visible at session start. Posts in two batches. Tier 1 (7): AAIF cover-email gist for Illia on sint#130, pshkv crosswalk ack on vocab#8, governance-declaration proposal for tomjwxf on ossf/security-insights#171, APS+SINT composition MVP for EchoOfDawn on autogen#7525, SDK#16 MIGRATION.md field-diff patch + v2.1.0 ship follow-up to MoltyCel, vocab#38 five-check protocol review for Harold's AgentID fixture (JWKS live, Solana tx verified, signing-input UTF-8-hex vs bytes ambiguity flagged), vocab#34 context_dimensions PR flipped ready-for-review. Tier 2 (4): autogen#7528 three-layer APS+SINT+OPA composition mapped onto ConversableAgent lifecycle, A2A#1716 Enclave+SINT+MolTrust converged-architecture ack with sub_delegate for 1→3 hop + AND-composition for MolTrust-score + APS-grade gate, VoltAgent#1166 full TS GuardrailDecision interface reference implementation (Alvasilev12/MEEET canary correctly ignored), llama_index#21312 dispute-primitives reference from v2.1.0. insumer-examples#1 skipped, zero activity since our Apr 17 scope ack.

Depends on: d61-ecosystem-engagement

Day 64: OWASP AARS#32 naming boundary held

Day 64 outward done

VeloGerber (AiEGIS) proposed co-listing 'APS APS' and 'AiEGIS APS' as two entries in the permanent v0.9 §3.3 standards citation. Technical content of the proposal accepted on its merits (evidence sequencing, measurement methodology). Naming framing declined firmly in writing with paste-ready §3.3 text naming only APS. Apr 21 calendar typo in the proposal also flagged. Posted at github.com/OWASP/www-project-artificial-intelligence-vulnerability-scoring-system/issues/32#issuecomment-4284723330. Not every be-nice reflex is the right one.

Day 64: v2.0.0 promoted to npm @latest

Day 64 Protocol done

Stability window closed clean. SDK v2.0.0 and MCP v3.0.0 flipped from @next to @latest. PyPI 2.0.0 final replaces the 2.0.0b0 pre-release. v1.46.0 and MCP v2.27.0 moved to the legacy-v1 tag, six months of legacy-tag availability committed. Propagation sweep also caught a Python __init__.py __version__ drift carrying "0.15.0" from the beta period, if a caller imported agent_passport.__version__ at runtime, they would have seen 0.15.0 while pyproject.toml and the wheel said 2.0.0b0. Fixed to 2.0.0 during the promotion sweep.

Depends on: v2-promotion-decision

Day 64: SDK v2.1.0, Cognitive Attestation envelope + verifyBoundWallet object form

Day 64 Protocol done

Two primitives shipped on @latest same day as the v2 promotion. Cognitive Attestation envelope: TypeScript port of the normative JSON schema from Paper 7 (Zenodo 10.5281/zenodo.19646276), module at src/v2/cognitive-attestation/ with types, envelope, verify, disputes, index, README. Stage 1 cryptographic verification with required_signer_roles coverage fully implemented; Stage 2 registry interface, Stage 3 replay typed stub with clear TODO. Typed dispute primitives ship the vocabulary of disputes without baking resolution logic into the protocol (resolution layer lives in the consumer). 35 new tests (envelope 17, verify 12, adversarial 6), zero new npm deps, reused internal canonicalizeJCS + crypto/keys. Second primitive: verifyBoundWallet object-form overload, closing the SDK#16 UX asymmetry MoltyCel flagged. Commits ceb1cd1 (wallet-binding) + 8c9cc14 (cognitive-attestation) on @latest. Test count 2,325 → 2,366.

Depends on: d64-v2-promoted-latest

Interop Week 1 Step 1 (trust_verification) merged

Day 64–65 outward done

AgentID trust_verification fixture merged via PR#38 (Harold). First of five Week 1 slots filled. Production JWKS and Solana devnet anchor both verified live during 5-check. Status ack posted to vocab#36 with running fixture table; Step 4 (peer_review task_completion) re-pinged to @QueBallSharken / Logpose after @rnwy's graceful decline to pad bundle with reviewer_credibility into a task_completion shape.

Depends on: d63-interop-week-1-opened

in-toto#549 Governance Attestation sibling predicate PR

Day 64–70 outward done

PR against in-toto/attestation adding a sibling predicate type for session-level Governance Attestation, referenced by hash from Decision Receipts. Accepted delegationChainRoot: DigestSet camelCase per tomjwxf's #549. Triggers when tomjwxf's Decision Receipt predicate PR#549 lands. Draft scaffolding already started at specs/in-toto-sibling-predicate-draft/.

Depends on: d61-ecosystem-engagement

Nanook PDR §8 review (48h SLA)

Day 64–76 Research done

Committed on aeoess/agent-passport-system#12 to a 48-hour review turnaround once @nanookclaw sends the PDR v2.20 §8 draft. Section 8 is PDR's proof-of-orthogonality workbook between Saebo (constraint compliance), Pidlisnyi (Hold/Bend/Break), and PDR (cross-session reliability). Our v1.46.0 pin commitment + optional dogfood gist refresh for the experimental substrate is already on the table. Passive until nanookclaw sends.

Depends on: pdr-paper-cites-aps

vocab#26 context_dimensions PR (Apr 22 target)

Day 64–65 vocab done

PR #34 merged Day 65 (commit 6a24b73f) adding context_dimensions as third top-level structural section in vocabulary.yaml. Four Day-1 entries with non_signal_test discipline: counterparty_standing, request_origin, session_dynamics, physical_environment_state. Incorporated @pshkv review (resolution_source marked recommended-not-required in v0.1, physical_environment_state per-evaluation variance documented, 4-value enum as v0.2 fallback). @tomjwxf's 5-value enum preserved per his Day 63 sign-off. Self 5-check protocol run publicly before merge (transparency move on our own repo). Closes #26.

Depends on: d61-aeoess-aps-crosswalk

YC application update (May 4 deadline)

Day 64–83 Ops done

Batch update on the existing YC application. Day 64 state to carry: v2 architecture separation, AAIF filing, Paper 7 ship, 124 modules, 2,366 tests, 142 MCP tools. Tima owns the irreversible commercial lane, Claude drafts the update diff only. Deadline May 4.

Depends on: yc-application

Interop Week 1 issue #36, five-signal compose test

Day 63–76 outward done

Opened vocab#36 as a structured five-signal compose-test invitation to the ecosystem: trust_verification → governance_attestation → entity_continuity → peer_review → settlement_witness. Framed as a test not a standardization play, with explicit disclaimers (not a spec change, not an APS showcase, not an entity_continuity canonical promotion attempt). Two fixtures confirmed within 45 minutes of opening: @arian-gogani (Nobulex, governance_attestation, HIPAA scenario with bilateral-receipt structure) and @nutstrut (continuity-analyzer, entity_continuity + settlement_witness). @rnwy declined step 4 gracefully (RNWY reference_point is reviewer_credibility, not task_completion), re-pinged Logpose for step 4. Steps 1 (MoltyCel/Harold) and 4 (Logpose) still open.

Depends on: d58-vocab-momentum

Day 63: MoltyCel v2 compat test + wallet binding shape-diff

Day 63 Protocol done

Stability-window Sunday. Exactly one partner compat test ran through [email protected] and MCP v3.0.0, MoltyCel on Solana wallet binding with a fresh Ed25519 keypair, bs58 signature, full bindWallet → verifyBoundWallet round-trip. Two findings surfaced: MIGRATION.md did not call out the wallet_ref field-level v1-to-v2 shape change explicitly enough, and verifyBoundWallet accepted only positional args while bindWallet accepted an object form. Shape-diff clarification landed same day as commit 0a3edeb. UX overload queued for v2.1.0. Nothing else broke; promotion path stayed on for Monday.

Depends on: d61-v2-architecture-separation

OpenLineage#4409 covenantInEffect facet JSON Schema draft

Day 63–65 outward done

Commitment to @arian-gogani on OpenLineage/OpenLineage#4409 after his 8-minute endorsement of the vendor-agnostic digest abstraction. Three-step plan delivered Day 65 (Apr 21): minimal JSON Schema shape, open type enum, two worked examples (Nobulex bilateral-receipt + APS gateway trust profile), all three files valid JSON and both examples validate cleanly against the schema. Posted on the thread for arian review before any upstream OpenLineage PR. Positions APS's governance_attestation canonical as a referenceable issuer type in OpenLineage's covenantInEffect facet, multi-day audit exchange compresses to single verification step. Committed inside the week window as promised on Apr 20. Waiting on arian sign-off before the upstream PR to OpenLineage/OpenLineage.

Depends on: d61-aeoess-aps-crosswalk

adk-aps-integration repo (Google ADK × APS joint)

Day 62 Product done

New repo at github.com/aeoess/adk-aps-integration spun up Day 62 in response to google/adk-python#5164. Joint ownership with @tomjwxf (ScopeBlind). LICENSE carries both names (Copyright 2026 Tymofii Pidlisnyi, Thomas Farley). Structure: main branch (README pointer) + integration-skeleton branch with aps_delegation.py, receipt_signing.py, verify.sh, examples/basic-tool-call. CI matrix across Python 3.10/3.11/3.12 against both @next and @latest APS SDK plus @veritasacta/[email protected]. Receipt format shipped as audit-bundle shape (matches verifier's actual contract, not per-call receipts). Six jobs green after CI fix (commit 7f7bae68). tomjwxf collaborator invite pending acceptance.

Depends on: d61-v2-architecture-separation

Day 62: Substantive reads on x402#1904 and ATF#8

Day 62 outward done

Two ecosystem threads got substantive engagement, neither inserting APS into the conversation. x402#1904: MnemoPay (Jerry) shipped x402-compatible paywalls plus a financial-brain MCP. Reply was a three-point read on what they shipped (wallet-decision layer is new terrain, receipts plus MCP tool outputs are compatible with APS signing for downstream composition, composition hook via delegation-reference in X-Agent-Identity would make APS passports attachable to x402 requests without modifying x402). ATF#8: desiorac proposed the ArkForge three-plane decomposition (delegation, decision, execution). Reply was a +1 proposing a Notes-column cross-reference so the composition is visible in their ECOSYSTEM table without inference, linked in-toto#549 as the chain-linkable primitive. Both threads pushed forward the conversation on the partner's terms. Several unrelated canary threads correctly skipped (handles not named here for operational hygiene).

Depends on: d61-v2-architecture-separation

Day 62: SINT refresh + RNWY a2a.yaml crosswalks merged

Day 62 vocab done

Two external vocabulary crosswalks merged same day. SINT refresh (PR #30, Illia Pashkov) normalized match semantics to the canonical enum (exact|partial|no_mapping), added a peer_review no_mapping row, updated home to docs.sint.gg, recorded entity_continuity and consent_provenance alignment notes. RNWY a2a.yaml (PR #32) maps A2A Agent Card governance metadata (peer_review, behavioral_trust, wallet_intelligence) against did:web:rnwy.com with a live JWKS serving rnwy-trust-v1, rnwy-trust-v2, rnwy-wallet-v1. Both PRs submitted clean, validator passed, scope was tight. Registry is now at 14 external partner crosswalks plus aeoess-aps (shipped Day 61). Validator chore f092f0e also landed same day, renaming note to notes for schema consistency.

Depends on: d58-vocab-momentum

hermes-aps-delegation repo (NousResearch Hermes × APS)

Day 62 Product done

New repo at github.com/aeoess/hermes-aps-delegation spun up Day 62 in response to NousResearch/hermes-agent#11692. Single-repo scope (original prompt asked for three; scope correction held). Structure: src/, tests/, charter/, examples/, pyproject.toml, LICENSE, .gitignore. 12 pytest cases + ruff + 3 example smoke runs + charter validator, all green on Python 3.10/3.11/3.12. v0.1.0 release tracking at aeoess/hermes-aps-delegation#1 (end-of-April milestone). Hermes-specific hook points stubbed with offer to wire real interfaces if NousResearch shares their non-public integration surface.

Depends on: d61-v2-architecture-separation

Day 62: AgentNexus round-trip + VeritasActa KU signer

Day 62 Protocol done

Two interop harnesses landed in the SDK. AgentNexus Track A fixtures (kevinkaylie, PR #17) replay end-to-end: JCS re-canonicalization, Ed25519 signature verification, delegation chain walk, monotonic narrowing check at each hop. Both fixtures match expected, happy-path accepts, scope-expansion denies at the subset gate, zero canonicalization drift. VeritasActa KU signer (tomjwxf, VeritasActa/verify#2, test vectors PR#6) slots APS into their external_receipts.aps bundle field with JCS-canonical sha256 over each knowledge unit receipt, records the chain in contributingSources, signs with deterministic test key. Cross-layer integrity is observable either direction: tampering any KU byte invalidates the recorded accessReceiptId while the APS signature stays cryptographically valid. Neither interop required a protocol change. APS slots in as specified.

Depends on: d61-v2-architecture-separation

MnemoPay x402#1904 (framing credit from Day 49)

Day 62 outward done

Jerry Omiagbo (MnemoPay) pinged aeoess directly on x402#1904, crediting the receipt-as-verifiable-economic-memory framing from Apr 2 (Day 44) with driving his last three MnemoPay releases. MnemoPay SDK @mnemopay/sdk v1.3.1 shipped Apr 17 with mnemopay.com live: receipt-as-primary-object, 3-verdict lifecycle (permit_settled/permit_failed/deny), per-agent Merkle log. First concrete case of another company building on a framing we published without us writing a line of their code. Replied with three substantive acks + composition hook for delegation-reference in X-Agent-Identity.

Depends on: d49-twelve-primitives

Paper 7: Cognitive Attestation (Zenodo)

Day 62–63 Research done

Paper 7 published on Zenodo (DOI 10.5281/zenodo.19646276). Introduces the Cognitive Attestation envelope: a cryptographic commitment attached to an agent's action record declaring which sparse-autoencoder features engaged and at what intensity during the output. Three-stage verification model, Stage 1 cryptographic verification (required_signer_roles coverage), Stage 2 registry interface, Stage 3 replay. Accompanied by a normative JSON schema (papers/paper-4/poc/schema/cognitive_attestation.schema.json) and a Python reference envelope validated against Llama-3.1-8B via Neuronpedia. Ported to TypeScript as SDK v2.1.0 on Day 64.

Depends on: d57-paper-published

ScopeBlind/agent-governance-testvectors PRs #2 + #3

Day 62 outward done

Two fixture PRs shipped upstream to ScopeBlind/agent-governance-testvectors. PR #2: A2A#1742 Week 2 APS fixtures in a2a-trust-header/, 6 JSON fixtures (happy-path, scope-expansion, revocation, multi-hop, tampered, partial-chain) + deterministic generator + verify script + README, all Ed25519/JCS-canonical, 6/6 round-trip pass. PR #3: OWASP#802 gateway enforcement vectors, 4 vectors (fail-closed, external-verification, state-drift, portability), 34 files, every signed artifact verified before commit. Both PRs mergeable, tagged MoltyCel + tomjwxf.

Depends on: d62-interop-verification

Day 61: aeoess-aps.yaml crosswalk published in the governance vocabulary

Day 61 vocab done

First time we published our own crosswalk in the registry we host. Closes a dogfooding gap: twelve external partners had contributed their crosswalks (InsumerAPI, SINT, AgentNexus, Veritas Acta, Logpose, RNWY, SoulboundRobots, Nobulex, SAR, JEP, asqav, SATP), we had not. crosswalk/aeoess-aps.yaml covers 3 exact-match signal types (passport_grade, trust_verification, governance_attestation), 2 partial (behavioral_trust, entity_continuity), 7 honest no_mapping entries, 4 decision_trajectory mappings, 1 constraint mapping, and out_of_vocabulary_primitives section for runtime enforcement mechanics. vocabulary.yaml updated: APS added to governance_attestation.issuers_in_production as 4th production issuer via Build D2 JWS trust profile endpoint.

Depends on: d58-vocab-momentum, d59-build-d2-jws-signing

Day 61: 11 substantive partner replies + release announcement

Day 61 outward done

Posted primary release announcement at aeoess/agent-passport-system#16 as canonical reference link. Four cross-references to targeted threads (aeoess#2 closing SDK-publish issue, haroldmalikfrimpong-ops/agentid-aps-interop for Harold's interop fixtures, aeoess#12 for Nanook §8 coordination, openclaw#49971 for MoltyCel wallet binding). Seven substantive replies to active partners: A2A#1742+1755 (MoltyCel coordination plan + DID resolution), VeritasActa/verify#3 (tomjwxf ecosystem tracker), microsoft/agent-governance-toolkit#787 (pshkv + tomjwxf wine-shipment three-way composition, committed to ship aps_delegation_wrapper.py PR), google/adk-python#5164 (tomjwxf co-maintain acceptance for agent-governance-stack-example repo), aeoess/agent-governance-vocabulary#12 (nutstrut failure_codes draft feedback), langchain-ai/langchain#35691 (vdineshk Observatory composition observation). 3 new deliverables tracked for the Apr 21-24 window.

Depends on: d61-v2-architecture-separation

A company rebuilds its receipt design around a framing we argued in a thread, and says so unprompted

Day 61 outward done

In early April a distinction was drawn on a public payments thread between an agent remembering what happened and an agent being able to prove it, with a sketch of a receipt carrying intent, scope evaluation and outcome under one signature. Two weeks later the maintainer wrote back that the gap was where they had been drawing the line wrong, that the framing drove their last three releases, and that they had been treating the receipt as a log artifact when it needed to be the primary settlement object. What shipped carries the full lifecycle in the receipt, chained to a Merkle root with per-leaf reconstruction, and a million-operation stress test. No code of ours is in it. This is the clearest case of a framing travelling without an implementation attached to it.

Day 61: V2 architecture separation shipped

Day 61 Protocol done

Monolithic SDK split along the protocol-vs-product axis. Public SDK keeps crypto, types, scope logic, adapters, conformance suite, interop vectors, and the 8 core primitives (byte-identical to v1.46.0). Private gateway package takes ProxyGateway, DataEnforcementGate, ContributionLedger, SettlementGenerator, IntentNetwork, DelegationStore, ReceiptLedger, 18 behavioral-analytics modules, EscalationWorkflow, SemanticDriftTracker, AnomalyDetection, MigrationWorkflow, AttestationLedger, and runtime state management. ~647 tests moved with them. Partners on any v1 pin unaffected: v1.46.0 stays on npm @latest through stability window. Unlocks foundation submission (AAIF target) and protects the pixel attribution moat. SDK v2.0.0-beta.0 on @next (2,325 tests, 130+ modules), MCP v3.0.0 on @next (142 tools, down from 154 after removing 12 product-only tools and stubbing 10 gateway-moved tools), Python v2.0.0b0 on PyPI as PEP 440 pre-release, Gateway repinned to ^2.0.0-beta.0 and Railway-redeployed zero-downtime. Three-layer safety net: anchor tags in every repo, local snapshot kit, and a private archive repo (internal).

Depends on: d59-build-a-shipped

v2.0.0 promotion to @latest, done Day 64

Day 61–64 Ops done

48-to-72-hour stability window closed clean. v2.0.0 promoted to npm @latest across SDK and MCP v3.0.0. PyPI 2.0.0 final shipped (non-pre-release, replacing 2.0.0b0). v1.46.0 and MCP v2.27.0 parked on legacy-v1 tag for six months, installable indefinitely. Four external partner integrations landed against v2 during the window (AgentNexus Track A, VeritasActa KU signer, SINT refresh, RNWY a2a.yaml), all ran through v2 transparently. One partner compat test surfaced two shape/UX findings (MoltyCel, SDK#16), both fixed within the window. Python __init__.py __version__ drift also caught and corrected during promotion sweep.

Depends on: d61-v2-architecture-separation

Build C: Settlement Pipeline

Day 60 Protocol done

Per-period signed settlement records aggregating Attribution Primitives across D/P/G/C axes. Four Merkle-committed axis roots. Contributor query endpoint verifying end-to-end without trusting the gateway beyond its JWKS. Economic half stays gateway-private; evidence half ships in the SDK. 5 cross-language fixtures, byte-identical across runs. Shipped SDK v1.46.0, MCP v2.27.0 (3 new settlement tools), Python v0.15.0.

Depends on: build-b-fractional-weights

Offline-verifiable decision receipts become a tutorial in Microsoft's governance toolkit

Day 60 outward done

Tutorial 33 in the Microsoft agent-governance-toolkit documents offline-verifiable decision receipts. Written by a maintainer of that project and merged there, which puts the receipt shape in front of that toolkit's readers rather than ours.

Build B: Fractional Weights

Day 59 Protocol done

Role-based fractional weight formulas for D and C axes. Merkle tree composition. Sum-to-one property tests. Shipped SDK v1.45.0.

Depends on: build-a-attribution-primitive

Build A shipped: unified four-axis attribution primitive

Day 59 Protocol done

One signed Merkle envelope replaces four separate attribution receipt types. D (data), P (protocol), G (governance), C (compute). Each axis projection verifies independently; two projections of the same receipt cross-verify by shared action_ref + merkle_root + signature. 6 new SDK exports, 6 new MCP tools, 1:1 Python port with cross-language sig verification. SDK v1.44.0 (2,910 tests), MCP v2.25.0 (149 tools), Python v0.13.0. Unblocks Builds B and C.

Depends on: build-a-attribution-primitive

Build D2, JWS-signed gateway trust profiles

Day 59 Protocol done

Gateway a public trust-lookup endpoint on the gateway now attaches compact Ed25519 JWS to successful responses via three headers: X-APS-JWS, X-APS-JWS-KID: gateway-v1, X-APS-JWS-JWKS pointing at the public JWKS. Body unchanged, non-breaking for existing consumers. Cross-engine verifiable with jose: kid matches, alg is EdDSA, signature checks out against the public key. Closes the gap between 'the gateway told me X' and 'I can show a third party that the gateway told me X.'

Coordination layer consolidated

Day 59 Ops done

Three-agent coordination path (primary operator + reviewer agent + comms relay) retired. Reviewer agent workflows archived under archive-portal-era/ with ARCHIVE-README.md, nightly cron deleted, GitHub posting flows through a single path. Historical records (roadmap, blog, ops log) preserved as-is. Fewer moving parts.

Vocab #29: peer_review canonical definition audit

Day 58–59 outward done

Self-opened issue auditing peer_review canonical promotion (Logpose task-completion vs RNWY reviewer-credibility, different primitives under one name). Proposed Path A: narrow peer_review to task-completion (Logpose), introduce reviewer_credibility as proposed with RNWY as sole implementer. Closed 2026-04-17 via PR#31 merge (rkaushik29 peer_review scope note).

Depends on: d58-vocab-momentum

Solana wallet_ref, chain enum + case-sensitivity fix

Day 58 Protocol done

SDK v1.43.0 adds Solana to the wallet_ref chain enum with base58 validation. Paired gateway fix: chain-aware normalization replaces blanket lowercasing of the wallet payload so base58 addresses round-trip correctly. Bug was silent data corruption, every receipt that passed through would have signed over the wrong address. End-to-end wallet binding now spans Ethereum, Bitcoin, Solana. 2,848 tests. Closes openclaw #49971.

Depends on: d57-boundary-primitives

Vocab registry, four PRs merged + peer_review canonical

Day 58 vocab done

Four PRs merged Apr 15: asqav crosswalk (jagmarques, ML-DSA-65 server-side, first lattice-based contributor), JEP (schchit, IETF I-D pending, JCS+Ed25519), insumerapi license-endpoint fix (douglasborthwick-crypto), validator cleanup + format normalization. peer_review promoted to canonical status after Logpose (rkaushik29) and RNWY (rnwy) landed as two independent implementations, first post-launch canonical promotion under the CONTRIBUTING.md two-implementation threshold. 14+ contributors, 11 PRs merged in 6 days.

Depends on: vocab-contributing-lands

Vocab PR #28: SoulboundRobots (entity_continuity)

Day 58–59 vocab done

rnwy opened PR#28 adding SBR crosswalk for entity_continuity. Merged 2026-04-17.

Depends on: d58-vocab-momentum

A contribution map is built across 59 threads and 1,471 comments

Day 57 outward done

A map of who is actually doing the work across the agent-governance threads we track. 59 threads pulled, 29 of them carrying human activity once automated posts are filtered out, 1,471 comments and 73 participants across 10 repositories. Contributions are scored by weighted signal tier rather than comment count, so an embedded code block or a commit reference outranks a short release announcement, and single-word reactions are penalised. The map exists to find the people worth answering, so it records contribution and carries no judgement of any participant.

Three Boundary Primitives Shipped

Day 57 Protocol done

Three v2 constitutional modules address distinct failure modes that surfaced in production. AttributionConsent prevents citing third-party principals in binding artifacts without dual signature, representation boundary. ProvisionalStatement + PromotionEvent defaults agent-to-agent statements to provisional, requires explicit PromotionEvent for binding, commitment boundary. HumanEscalationFlag gates per-action-class owner confirmation with three scope modes, escalation boundary. Integrated into charter, settlement, and completion-receipt verification. SDK v1.42.0 (2,844 tests), MCP v2.24.0 (143 tools), Python v0.12.0.

Depends on: sdk-v141-state

Paper 6: Governance in the Medium (Zenodo)

Day 57 Research done

Working paper published on Zenodo (DOI 10.5281/zenodo.19582550). Argues that the unit of agent governance is not the agent but the population-with-medium, the collective state of inherited fragments across short-lived sessions. Defines the medium as a governance contract that specific substrates implement, distinguishes access from declared influence, names the central open problem (cryptography formalizes authorship, not meaning), and grounds the cognition claim in existence proofs already around us: institutional memory, Wikipedia, open-source development. Six rounds of adversarial review across three model families before publication.

Depends on: d57-boundary-primitives

Merge Protocol + Contributor Tiers Codified

Day 57 Ops done

Internal rule: five-check evaluation (identity / format / substance / scope / reversibility), three decision classes (AUTO-OK / REPORT-FIRST / NEVER-AUTO), tier-based contributor classification T0-T3 with auditable promotion/demotion. Replaces implicit pattern-matching with structural discipline. A live transfer-request incident used as the worked example. Applied on first test: vocab#14 auto-merged (T2 descriptor typo fix), vocab#15 formal CHANGES_REQUESTED review (T2 peer_review canonical entry, touched canonical vocabulary.yaml, needed status:proposed + descriptor dimensions before merge).

Depends on: principal-accountability-reversal

CONTRIBUTING.md + CODE_OF_CONDUCT.md Shipped

Day 57 outward done

Public contribution standard for the vocabulary repo. Quick Start checklist, merge criteria (5 review questions applied equally), canonical-status rule (2+ independent implementations), stability expectations, no CLA required. Contributor Covenant 2.1. Written after two multi-model review rounds, the review flagged defensive tone and trauma leaks, both addressed. Template for roll-out across SDK and spec repos.

Depends on: vocab-repo-launches

Build A: Attribution Primitive

Day 56–59 Protocol done

Unified four-axis (D, P, G, C) signed Merkle receipt. One AttributionPrimitive envelope, four independently-verifiable axis projections, cross-verify by shared action_ref + merkle_root + signature. Canonical weight-string representation, balanced Merkle composition, residual-bucket aggregation for sub-threshold contributors. Shipped SDK v1.44.0, MCP v2.25.0, Python v0.13.0.

Depends on: attribution-primitive-spec

Principal-Accountability Reversal

Day 56–57 Ops done

A vocabulary repo transfer request surfaced that a collaboration agent had made commitments its principal had not authorised. The public reversal established the thesis this entry exists to record: broad delegation scopes cover pragmatic overreach, which is the Model Citizen trap; counterparty standing is invisible to agents, so a fresh account and an established one look identical at the point of decision; and the principal, not the agent, carries accountability for what was committed. Counterparty identity is deliberately omitted here. The pattern is the record, not the person.

Depends on: vocab-repo-launches

#13: BBIS Boundary

Day 55–57 outward done

QueBallSharken boundary statement. Three separate problems acknowledged.

Build D2: Public JWS Signing

Day 55–57 Protocol done

Default a public trust-lookup endpoint on the gateway signs with gateway Ed25519 key. X-APS-JWS / X-APS-JWS-KID / X-APS-JWS-JWKS response headers. Ed25519, kid gateway-v1, cross-engine verifiable against the public JWKS. Shipped 2026-04-16.

qntm #7: Decision Composition

Day 55–58 outward done

xsa520's evaluation-point vs decision-point gap. Hard/state-volatile/contextual gates.

Public Roadmap

Day 55 Ops done

aeoess.com/roadmap timeline with dependency graph. YAML-driven, static, matches site design. Shipped at https://aeoess.com/roadmap.html.

SDK PR #14: SINT Integration

Day 55–57 outward done

pshkv's SINT integration merged (9/9 cross-verify passing). Physical-world enforcement layer. Now in INTEGRATION.md.

Depends on: vocab-pr7-sint-crosswalk

SDK PR #15: SAY-5 Redirect

Day 55–57 outward done

First-time contributor PR on SDK repo. Redirected to separate vocabulary repo, which became the canonical home for this kind of contribution. PR closed. 7 SAY-5 equivalents have since landed in agent-governance-vocabulary from other contributors.

Vocab PR #9: AgentNexus

Day 55–57 vocab done

kevinkaylie's AgentNexus governance vocabulary crosswalk.

Depends on: vocab-pr7-sint-crosswalk

YC Application

Day 55–83 Ops done

Commercial-irreversible lane. Tima's sole ownership.

A2A #1717: Cross-Verify Demo

Day 54–73 outward done

Three-namespace cross-verify: did:agentnexus subject, APS + MolTrust issuers. Test DID registered.

AGT #772: Liveness ADR

Day 54–55 outward done

Three-property liveness decomposition ADR on microsoft/agent-governance-toolkit. PR #948 co-authored.

Attribution Primitive Spec

Day 54–57 Research done

Formal spec v1.1 (71KB) committed to aeoess_web/specs/ATTRIBUTION-PRIMITIVE-v1.1.md on Apr 12. Unified cryptographic object with three axis projections (data, protocol, governance). Unblocks Build A.

Depends on: paper-5-physics

Build D1: Audit Log Export

Day 54 Protocol done

Audit log export in JSONL, CSV, PDF. Tenant isolation, rate limiting, delegation chain resolution.

Depends on: d53-convergence

Build F: Vocabulary Validator

Day 54 vocab done

CI validator checking descriptor enums, signal types, required fields against vocabulary.yaml. 162 lines.

Depends on: d53-convergence

Build G: Cross-Family Harness

Day 54 Protocol done

15-config experiment harness (5 scenarios × 3 AI families). Measures complementarity-gain across Claude, GPT, Gemini.

Depends on: d53-convergence

SDK v1.41.0 State

Day 54–57 Protocol done

[email protected] on npm. 2,763 tests passing across 714 suites (1 skipped). 35 v2 constitutional modules + core. MCP server at v2.23.0 with 132 tools. Python SDK at 0.11.0. Wallet binding, subDelegateAdvisor, credentialCheckPolicy all shipped.

Vocab PR #7: SINT Crosswalk

Day 54–57 vocab done

pshkv's SINT crosswalk. Review complete. Waiting on validity_temporal fix.

Vocabulary Repo Launches with 6 Merged Crosswalks

Day 54–57 outward done

aeoess/agent-governance-vocabulary opens as the canonical naming layer for agent governance primitives. IANA JWT Claims Registry / W3C DID Registries precedent. Six crosswalks merged in four days from five independent maintainers: InsumerAPI (Douglas Borthwick), SINT (Illia Pashkov), JEP (schchit), AgentNexus (Kevin Kaylie), SATP (0xbrainkid), Nobulex (Arian Gogani). Each system keeps its internal names and publishes a crosswalk mapping to the canonical vocabulary.

Depends on: vocab-pr7-sint-crosswalk

28 Active Ecosystem Threads

Day 53 outward done

A2A, crewAI, qntm, SINT, OWASP, x402, VoltAgent, langgraph-swarm, AgentID. APS in every layered-identity discussion.

Depends on: w3c-normative

Three Walls: SDK /core + MCP Essential

Day 52 Protocol done

New user bounced in 90s from 132-tool flood and 925 SDK exports. Shipped /core subpath (~25 curated functions) and MCP essential profile (20 tools). SDK v1.40.0, MCP v2.22.2, 2,552 tests, 103 modules.

Depends on: d51-quantum-governance

Quantum Governance

Day 51 Protocol done

Six weeks of circling quantum. Multi-model review found it: physics facets on delegations. 7 experiments on IBM Quantum. Bell 5.2pp + GHZ 7.7pp fidelity gaps.

Depends on: d49-twelve-primitives

Paper 4: Behavioral Derivation Rights

Day 51 Research done

Governing what agents learn from authorized access. Telemetry scopes, BMOs, BYOM.

Depends on: paper-3-faceted-authority

Paper 5: Physics-Enforced Delegation

Day 51 Research done

Governing quantum hardware quality. Real IBM Quantum experiments. 5.2pp Bell + 7.7pp GHZ fidelity gaps.

Depends on: paper-3-faceted-authority

Customer-Ready Gateway

Day 50 Product done

Longest session yet. 4-pass audit (30 findings, all fixed). Email infrastructure. Portal redesign. Full API docs. Status page. Admin endpoints. SDK v1.36.4, MCP v2.21.3, Gateway v0.4.0, 2,497 tests.

Depends on: d49-twelve-primitives

Delegation-scoped tool authorization is proposed to LangChain and to the OpenAI agents SDK on the same day

Day 50 outward done

Two proposals filed the same day arguing the same boundary from different ends: tool execution governance in LangChain, where authorization is scoped by delegation rather than by the calling code, and delegation-scoped handoffs in the OpenAI agents SDK, where authority narrows as a task passes between agents. Both closed.

Twelve Primitives in One Day

Day 49 Protocol done

Nate B Jones reverse-engineered Claude Code's orchestration into 12 primitives. We shipped all twelve. Tool registry, permission tiers, context compression, state machines. SDK v1.36.2, 626 suites, 132 tools, MCP v2.21.1, 2,497 tests.

Depends on: d48-six-sessions

Insumer 7-Verified Issuers

Day 49 outward done

douglasborthwick-crypto ran multi-issuer verification on insumer-examples#1. APS position 5 (passport_grade, gateway-v1 kid) verified alongside InsumerAPI (wallet_state), ThoughtProof (reasoning_integrity), RNWY (behavioral_trust), Maiat (job_performance), AgentID (trust_verification), AgentGraph (security_posture). Cross-protocol attestation composable format.

Depends on: harold-canonical-repo

MCP Block (Risk Guardian Origin)

Day 49 Ops done

60 GitHub issues posted in one afternoon. Anthropic/MCP org blocked the aeoess account from posting on modelcontextprotocol/modelcontextprotocol. Permanent reference case for what volume costs. Origin of the Risk Guardian discipline, comms became something to govern, not just do.

Depends on: wg-formed

Six Build Sessions, One Shipping Day

Day 48 Protocol done

Five reviewer models attacked specs before a single line shipped. Six sequential sessions, each depends on previous deploy. Gateway auto-deploys on push. SDK v1.34.0, MCP v2.21.0, 131 tools, 2,306 tests, 103 modules, Gateway v0.4.0, Python v0.9.0.

Depends on: d47-ms-merged

Drift Protocol Structural Response

Day 48 Research done

$285M UNC4736 DPRK social engineering hack. Ran 5-model architectural review on forensic attribution vs structural constraints. Killed 5 bad ideas (behavioral signals, cascade verification, prosecution scoring, general stake, forensic attribution test). Posted A2A#1628 reply framing authority-class separation + non-bypassable timelocks + hard velocity ceilings. Drove Values Floor timelock + Grade-gated authority build queue.

Depends on: multi-model-review-methodology

Microsoft Merged + SINT + W3C Normative

Day 47 Protocol done

Microsoft approved APS PR into Agent Governance Toolkit. SINT v0.2 shipped with our delegation_depth_floor. W3C behavioral attestation reached normative language. Evidence-based grading + freshness semantics.

Depends on: d46-byoi

PDR v1.9 Cites APS (Section 7.6.2)

Day 47 Research done

Nanook's PDR in Production v1.9 published on Zenodo. Section 7.6 is the first independent deep technical review of APS architecture, Bayesian sigma dynamics, structuralVerdict/trustVerdict separation, Module 37 as worked example. Tony Mason UBC production deploy (Hamut'ay, 98 cycles on Sonnet 4.6). DOI 10.5281/zenodo.19323172.

Depends on: paper-3-faceted-authority

W3C Behavioral Attestation Normative

Day 47 outward done

Timing asymmetry became normative constraint. Evidence-based passport grading + freshness semantics.

Depends on: wg-specs-ratified

Bring Your Own Identity

Day 46 Protocol done

APS stopped looking like an identity system. Four modules accept external credentials: did:key, did:web, SPIFFE SVIDs, OAuth 2.0. Routed through enforcement boundary. Python SDK v0.8.0, MCP v2.19.1, 125 tools, 2,180 tests, 559 suites, 103 modules.

Depends on: d45-governance-hardening

MolTrust Production Partnership

Day 46–47 Product done

Lars Kroehl / CryptoKRI GmbH. Partner API key received (10K calls/day, 1K agents per batch). 11 APS agents bridged did:aps → did:moltrust → Base L2. Reciprocal gateway verification via GET a public trust-lookup endpoint on the gateway with JWKS. First bilateral production partnership.

Depends on: d46-byoi

SDK v1.31.0: Governance Hardening

Day 45 Protocol done

Stricter validation on delegation chains. Tighter scope authorization. 34 new tests covering edge cases from MoltyCel security audit. 99 modules, 125 tools, 533 suites, Gateway v0.3.4.

Depends on: d44-solana-integration

First External Code Integration

Day 44 Protocol done

PR #3 merged into kai-agent-free/solana-agent-identity. APSProvider is the 4th identity provider in Solana Agent Kit. First external code that imports the SDK. SDK v1.29.6, Gateway v0.3.1, 99 modules, 2,051 tests, 34 routes, MCP v2.19.1. Plus 5 security fixes.

Depends on: d43-multi-attestation

Solana Agent Kit Adoption

Day 44 outward done

First external code that imports the SDK. Not a spec comment, APSProvider is running in another project's production repo as the 4th identity provider.

Depends on: yc-ceo-endorsed

Multi-Attestation Verification

Day 43 Protocol done

douglasborthwick-crypto ran 5-issuer live pass: InsumerAPI, ThoughtProof, RNWY, Maiat, APS. Five dimensions, two algorithms (ES256 + EdDSA), independently signed. APS is the 5th verified issuer. SDK v1.29.4, 38 routes, 503 suites, 125 tools.

Depends on: d42-attestation-architecture

Harold Canonical Repo

Day 43 outward done

haroldmalikfrimpong-ops shipped agentid-aps-interop on getagentid.dev. 32/32 tests passing. Harold's PolicyChain primitive (SHA-256 policy hash chaining) adopted into APS SDK with name-attribution in commit message. Canonical external collaborator, contributor attribution as compounding strategy.

Depends on: d43-multi-attestation

Agent Attestation Architecture

Day 42 Protocol done

Lev's agent farmed unlimited passports, drained Nik's promo wallet in 60s. Identity Sybil unsolvable in open protocols. 3-round multi-model architectural review across Claude, GPT, Gemini. SDK v1.29.1, 1,987 tests, 96 modules, MCP v2.19.0, 125 tools, Gateway v0.3.0, 37 routes.

Depends on: d41-agent-wallets

Agent Wallets

Day 41 Protocol done

Agents need to spend money. Coinbase charges gas. ChainHop takes 0.75%. We charge nothing. Three commits, 1,430 new lines. Gateway v0.3.0, 18 → 36 API routes.

Depends on: d40-gateway-wiring

Gateway dogfood on always-on host + gw CLI

Day 40–42 Product done

Private gateway cloned to the always-on host and run via the process supervisor on a local port alongside the Intent Network API. Four agents registered with real Ed25519 keys (tima-principal, claude-operator, portalx2-reviewer, aeoess-gpt-executor). Delegation chain bootstrapped with scoped authority and spend limits (a delegated build with a spend cap and a zero-spend review, both under the same chain, claude→portal sub-delegation). Full enforcement test battery passed: scope enforcement, spend tracking, cascade revocation. Built the gw CLI (gw eval, gw receipt, gw dash, gw audit, gw agents) for one-line authorization checks against the live gateway. APS runs on APS, this is the dogfood milestone.

Depends on: gateway-production

Gateway Wiring

Day 40 Protocol done

Import graph showed only 20% of modules connected to gateway enforcement hub. Four rounds of wiring. 20% → 79% interconnection. SDK v1.29.1, 96 modules, 1,987 tests, 503 suites.

Depends on: institutional-layer

Gateway on Railway

Day 40–41 Product done

Production enforcement at gateway.aeoess.com. Multi-tenant. Policy evaluation <1ms. Pixel attribution live.

Depends on: institutional-layer

Paper 3: Faceted Authority

Day 39 Research done

Product lattice model. Seven dimensions. IETF Internet-Draft submitted same day (draft-pidlisnyi-aps-00).

Depends on: d32-data-attribution-thesis

Rebrand: Governance for the Agent Economy

Day 39 Ops done

Site said 'APS' in giant letters, three paragraphs saying the same thing three ways. Passports metaphor doing the work plain language should do. Academic redesign, enterprise positioning, 10-question FAQ.

Institutional Governance Layer

Day 38 Protocol done

Estimated 12 sessions. Shipped in one. Charter, approval, time, reserve, federation. Zero lines to 1,634 passing tests. SDK v1.27.0, MCP v2.19.0, 108 tools, 53 modules, 503 suites.

Depends on: encrypted-relay

Governance Distribution Stack

Day 37 Product done

Protocol could sign and verify. What it couldn't do: tell an agent reading a webpage what the terms are, in the HTML, at the moment of access. aps.txt, 360 consumer loop, 108 MCP tools, SDK v1.25.0. First publication deploys APS. 1,480 tests.

Depends on: d34-30-modules

Clean Slate + OATR Founding Member

Day 36 outward done

Audited instead of building. Pulled all four repos, full test suite (1,178 pass, 0 fail), line-by-line dead-weight scan. 68 dead imports removed. OATR founding member.

Depends on: yc-ceo-endorsed

3 WG Specs Ratified

Day 36 outward done

QSP-1, DID Resolution, Entity Verification. Working Group formalized.

Depends on: d36-clean-slate

qntm Bridge: First Encrypted APS Envelope

Day 35 Protocol done

Vessenes shipped the qntm relay spec. HKDF-SHA-256 + XChaCha20-Poly1305 bridge built in 369 lines, zero new deps. 3/3 known-answer vectors match byte-for-byte. Live relay test: HTTP 201, seq:6, first encrypted agent governance communication anywhere. 1,178 tests, 320 suites, 63 test files.

Depends on: d34-30-modules

Working Group Formed

Day 35–36 outward done

Five independent projects agreed on a shared spec. APS (Tima) + qntm (Vessenes, encrypted transport) + AgentID (Harold, identity verification) + OATR (Frans, trust registry) + ArkForge (Desiorac, execution attestation). First spec ratified unanimously. Five weeks from first commit to four-project convergence. The inversion, inbound matching outbound.

Depends on: encrypted-relay, comms-phase-2-external-engagement

30 Constitutional Modules, Every Gap Closed

Day 34 Protocol done

Claude, GPT, Gemini each attacked full codebase. Identified 16 gaps in governance. All 16 running code by end of day. SDK v1.21.2, MCP v2.12.0, 83 tools.

Depends on: d33-constitutional-running

Module 37: Decision Semantics

Day 33 Protocol done

Every policy decision content-addressable (SHA-256 of canonical JSON). Verdict classification: deterministic, heuristic, LLM-based, hybrid, human. 42 modules, 83 MCP tools, 1,178 tests.

Depends on: d31-five-engines

AMCS v0.1.0

Day 32 Ops done

AI-native media credentialing spec. Open standard for AI-native publications. 25 tests, Module 36.

AMCS v0.1.0 spec formalized

Day 32 Ops done

AMCS (AI-Native Media Credentialing Standard) shipped as an open specification published by the project. Two-layer structure: editorial accountability (self-attested by the publication, public evidence audit trail) and cryptographic infrastructure (Ed25519 signing, Merkle proofs, delegation chains). Any publication can apply. SPJ Code of Ethics independence principle reflected in the structure. 25 tests. Module 36 in the SDK.

Depends on: d24-publication-integration

Data Attribution Thesis

Day 32 Research done

Bernie Sanders on data rights. Protocol already has 80% of the answer. Gateway tracks access (taint), Merkle trees commit receipts, delegation chains attribute. 'Pixel on crypto' crystallizes. Module 36.

Depends on: cross-protocol-envelope-spec

Three Modules + Five-Engine Disagreement

Day 31 Protocol done

Modules 28, 29, 30. First real cross-engine disagreement in agent identity space. Claude, GPT, Gemini, Grok, DeepSeek, all on one thread.

Depends on: d30-encrypted-messaging

Module 19: E2E Encrypted Messaging

Day 30 Protocol done

Separate X25519 keys, ephemeral ECDH per message, double signature. Inner over plaintext prevents identity stripping, outer over ciphertext enables gateway verification without decrypt. 42 modules, 1,178 tests. Two Claudes built three modules in one day.

Depends on: reputation-gates

Cross-Protocol Envelope Spec

Day 29 Research done

Three independent groups (CrewAI, Guardian, APS) converged on the same signed execution envelope. Mapped all three proposals to APS SDK types, wrote the RFC. Every field already in SDK.

Depends on: paper-2-monotonic-narrowing

YC CEO Endorsed + Microsoft Merged

Day 28 outward done

The weekend the protocol stopped being just Tima's. Garry Tan repost. Microsoft merged APS code. Federal agency reviewing.

Depends on: substack-launch

Full Stats Sweep + Gateway Decision

Day 27 Product done

Strategic decision day. Full staleness audit across all surfaces. 33 tools → 55 tools. 481 → 511 tests. 16 modules. Gateway architecture call that shaped the next month.

Depends on: d26-mingle-v2

MCP Registry listing (distribution)

Day 26–27 outward done

agent-passport-system-mcp listed on the official MCP Registry (registry.modelcontextprotocol.io) as the Anthropic-maintained discovery directory for MCP servers. Every Claude Desktop, Cursor, and Windsurf user browsing for agent-identity tools finds APS in the catalog. Complementary to the 12+ channel distribution done Day 7 (awesome-mcp-servers, clawhub, npm, Smithery, mcp.so).

Depends on: mcp-server-ships

Mingle v2: Semantic + Ghost Mode

Day 26 Product done

Biggest Mingle ship since launch. Four phases in one day. Semantic matching, ghost mode, consent flow. The network actually connects people now.

Depends on: d23-mingle-v1

Tesla Social MVP (side project)

Day 25 Product done

Working React + Supabase + Vercel MVP of a Tesla-community social app at tesla-social.vercel.app. Dashboard with miles-driven points, tier progression, odometer logging, proximity chat with real-time messaging, social feed, profiles. Not an APS product, a proof that a solo founder can ship a working social app in a weekend, used as a comms asset alongside the cross-protocol bridge Substack article. Not currently maintained; kept as a reference artifact for the Day 25 launch narrative.

Depends on: substack-launch

Multi-Model Review as Practice

Day 25–42 Research done

Multi-model adversarial review, same prompt to Claude, GPT, Gemini simultaneously, no cross-talk, synthesize after. Origin Day 25 (first honest pushback). First formal three-way Day 37. Peak Days 40-42 (Sybil, Agent DNA, data lifecycle, constraint architecture). Self-critique Day 38 identified anti-patterns. Stopped being default, became selective tool for genuine competing framings.

Depends on: paper-2-monotonic-narrowing

Substack Launch

Day 25 outward done

Two Substack articles: Cross-Protocol Bridge + Tesla Social. Social posts across X and LinkedIn.

Depends on: d11-agora-signed-speech

First publication on APS

Day 24–26 Product done

Three-layer integration of an AI-native publication with APS. Layer 1 (article provenance): every published article carries an APS signature over canonical article JSON, verifiable at article-level permalink. Layer 2 (journalist passports): each AI journalist persona gets a scoped delegation (topic areas, token budget per article). Layer 3 (Ethics Engine binding): 274 scored articles against 10 checks, credentialing mirrored on NPC membership tiers. Full CTO audit of the 68-file Python pipeline completed before any protocol binding. First production publication running APS receipts end-to-end in its editorial pipeline.

Depends on: reputation-gates

Gateway Security Hardening

Day 24 Protocol done

Three gateway bugs fixed. NW-001 memory leak in replay protection. NW-003 crash on unregistered agent. Setup commands, cross-protocol resolve.

Depends on: reputation-gates

Mingle v1

Day 23 Product done

Standalone MCP plugin that turns AI into a networking agent. Tell Claude or GPT who you need, your agent publishes a signed card, matches, introduces.

Depends on: d22-intent-network

Agent identity and delegation governance is proposed to NVIDIA NeMo

Day 23 outward done

Proposal to the NVIDIA NeMo Agent Toolkit covering agent identity and delegation governance. Filed early, still open, and the earliest of the framework proposals.

External Ecosystem Engagement Begins

Day 22 outward done

First substantive comment on someone else's repo, Karpathy's autoresearch on Garry Tan's repost thread. Same posture from internal model dialogue, now applied externally. The shift from 'building in private' to 'showing work in public.' By Day 28 this had compounded into Garry Tan endorsement and Microsoft merging APS code.

Depends on: comms-phase-3-multi-agent-ops

Intent Network

Day 22 Product done

Biggest ship since protocol launched. Network where agents represent humans, discover matches, propose introductions. No app, no signup. AI conversation is the interface. 30 tests, 1,178 tests total.

Depends on: reputation-gates

Intent Network API launched (api.aeoess.com)

Day 22–23 Ops done

Intent Network API deployed on a dedicated always-on host via the process supervisor + cloudflared tunnel. SQLite database, signed IntentCards, relevance scoring, intro protocol. First production service hosted outside Vercel or Railway, first use of named cloudflared tunnel for an APS endpoint (CNAME api.aeoess.com). Established the laptop versus always-on host split that still governs today: Air = dev only, Mini = production services.

Depends on: d22-intent-network

ProxyGateway Enforcement Boundary

Day 22 Protocol done

Shipped src/core/gateway.ts, ProxyGateway enforcement boundary with replay protection and two-phase execution. 30 tests. The architectural piece that makes the gateway both judge and executor, not just approver.

Depends on: reputation-gates

Homepage Redesign + FAQ + Footer Sweep

Day 21–22 Ops done

Site-wide redesign: constellation visualization rebuilt with semantic layout, bold hero with gold gradient rule + accent initials, 3-tier copy (hook / plain-English / technical). Deleted bot.html and bio.html with reference cleanup across 13 subpages. Created faq.html with 10 questions + Schema.org FAQ markup. Footer added to all subpages. Commits 539e923, d09b893.

Depends on: d13-website-overhaul

Reputation-Gated Authority

Day 21 Protocol done

Agents earn trust, not just receive it. Reputation scoring wired into delegation. SDK v1.11.0, MCP v2.5.0, 83 tools, 76 tests.

Depends on: d18-autoresearch

Paper 2: Monotonic Narrowing

Day 20 Research done

Authority attenuation formalized. Mathematical proof that delegated authority can only decrease. Formalizes what autoresearch validated.

Depends on: d18-autoresearch-findings

3-Experiment AI Agent Study

Day 19 Research done

Published findings from running 3 experiments with real AI agents. What broke, what worked. Early empirical backing for the threat model.

Depends on: d18-autoresearch

A four-run experiment holds the task constant and varies only role separation: error corrections go 0, 2, 5, 5

Day 18 Research done

Four conditions, one task held constant: analyse five agent identity protocols across ten dimensions. Only the division of work changed. Error corrections rose from 0 in the solo baseline to 2 with a coordinating pair and 5 in both separated conditions. Evidence gaps went from none flagged to 44 percent flagged, then 4 percent once the process was tuned. Citation coverage went from roughly 80 percent to 100 percent and stayed there. Overhead fell from 2.5 to 1 down to 0.67 to 1. The informative run is the role swap: the same agent scored 5 out of 10 as researcher and 10 out of 10 as analyst, which points at the role constraint rather than the agent. Two limits belong with the result: the scoring is internal, produced by the same system that ran the conditions, and there is one run per condition, so this is a result and not an effect.

Autoresearch: AI Finds Bugs AI Wrote

Day 18 Protocol done

Adapted Karpathy's autoresearch pattern. AI generates attacks, tests run, keep what breaks something new. 320 suites, 1,178 tests, 63 test files.

Depends on: d17-principal-identity

A2A Protocol Bridge

Day 17 Protocol done

Interop module for Google's Agent-to-Agent protocol: passportToAgentCard, verifyAgentCard. 8 tests. Commit bb88f90. src/core/a2a.ts shipped in SDK v1.10.0.

Depends on: d17-principal-identity

W3C DID Method + Verifiable Credentials

Day 17 Protocol done

Shipped W3C DID Method (did:aps), passports now resolve as Decentralized Identifiers. W3C Verifiable Credentials issue/verify from passport data. SDK modules did.ts, did-interop.ts, vc.ts, vc-wrapper.ts. Part of SDK v1.10.0 (commit d34abb2).

Depends on: d17-principal-identity

EU AI Act Compliance Mapping

Day 17 Research done

Automated compliance checks against EU AI Act, risk classification, Articles 9, 15 and 50 mapping, gap analysis, transparency disclosure. 14 tests. Commit 73d948e. src/core/euaiact.ts shipped in SDK v1.10.0.

Depends on: d13-threat-model

Nightwatch autonomous loop spec

Day 17 Ops done

Three-agent autonomous governance loop designed. 02:00 UTC GitHub Action creates a dispatch issue with repo state (latest commit, open issues, open PRs). Three roles assigned: scanner (nik-prime), analyst (PortalX2), synthesizer (aeoess). Consensus vote 2-of-3 drives a PR that the human merges in the morning. The protocol governs its own development: every step is a signed Agora message, every delegation scoped, every vote through the consensus primitive. Retired Day 59 as part of the coordination-layer consolidation; spec kept as reference design for protocol-governs-protocol patterns.

Depends on: d17-principal-identity

Principal Identity + Python SDK

Day 17 Protocol done

Five new modules. Principal identity, Python SDK v0.4.0, three protocol extensions. 20 modules, 86 tests.

Depends on: d15-ship-day

Python SDK, First PyPI Releases

Day 17 Protocol done

Four PyPI releases of agent-passport-system in a single day: v0.1.0, v0.2.0, v0.3.0, v0.4.0 (all 2026-03-06). Cross-language compat with TypeScript SDK via canonical JSON. 8 layers, 101 tests at v0.3.0. pip install agent-passport-system.

Depends on: d17-principal-identity

Remote MCP Server Live at mcp.aeoess.com

Day 17 Ops done

New public repo aeoess/agent-passport-remote-mcp (created 2026-03-06T16:43:22Z). stdio-to-SSE/HTTP bridge, isolated MCP subprocesses per session. a supervised process behind a tunnel → mcp.aeoess.com.

OWASP AI Security Mapping

Day 16 Ops done

Community health baseline. APS scored 10/12 on BBIS later (Day 51).

SDK v1.21.2 + MCP v2.12.0

Day 15 Protocol done

Ship day. Five npm publishes. 83 MCP tools. 1,178 tests. Every version reference propagated automatically.

Depends on: d14-first-audit

A sandboxing requirement is tightened in HuggingFace smolagents

Day 15 outward done

Contribution to smolagents making explicit that sandboxing is required rather than advisable for the local Python executor. Small, early, and merged: the first change of ours to land in a widely used agent framework.

First Real Audit

Day 14 Protocol done

PortalX2 and aeoess ran full-system audit in parallel with cross-review. 16 iterations across source, tests, MCP. 10 findings.

Depends on: d13-graduated-enforcement

Graduated Enforcement + Threat Model

Day 13 Protocol done

Four ships. Graduated enforcement tiers, threat model document, Agent District. 55 suites, 214 tests. Pushing code 9am to midnight.

Depends on: d12-agentic-commerce

Threat Model Published

Day 13 Research done

Published threat-model.html, 38 attack scenarios with direct references to the test suite. Asset inventory, threat actors, trust boundaries, and explicit non-goals. Commit 52b7dd0.

Depends on: paper-1-social-contract

Website Overhaul + SEO Sprint

Day 13 Ops done

Fixed 56 misspelled 'Ed25519' occurrences across three repos (npm typo bump 1.8.1, commit 3b0f1ea). Rewrote hero text, aligned Quick Start to real API. Rolled out GA4, Open Graph, Twitter cards, and Schema.org across all 11 HTML pages (commit 2f69c6e). llms.txt layer descriptions aligned with actual architecture.

Layer 8: Agentic Commerce + MCP v2.1.0

Day 12 Protocol done

Three major ships. 4-gate checkout. Integration wiring. MCP v2.1.0, 30 MCP tools, 214 tests.

Depends on: d11-doc-sprint

Agent District, Pixel-Art Protocol Visualization

Day 12–13 Ops done

Shipped world.html, a pixel-art operational map showing all protocol layers in live operation. Nine buildings (one per layer plus central square), four agents with unique character designs, walk cycles, and task queues moving between buildings in real time. Commit 23eba32. Live at aeoess.com/world.html.

Agora: Signed Speech for Agents

Day 11 outward done

Publication piece framing Agora as the missing layer, signed, verifiable agent-to-agent messaging on top of Ed25519 identity.

Depends on: d4-community-shows-up

Documentation Sprint

Day 11 Protocol done

No new layers. Making everything findable and understandable.

Depends on: d10-coordination

Layer 7: Coordination Primitives

Day 10 Protocol done

Identity tells you who. Delegation tells you what. Coordination tells you how agents actually work together.

Depends on: d8-intent-architecture

Site Cleanup: Agora Feed Fixed, Board Surfaced, Logo Refresh

Day 10 Ops done

agora.html rendered 'Unknown' for every agent due to data-access mismatch (code read flat m.agentName, data was nested under m.author). Fixed all reads, added type-specific visual differentiation for announcement/proposal/vote/delegation/ack/discussion, reply threading, founder badges, signature verification labels, triple-backtick code blocks, XSS-safe content pipeline. board.html had </body></html> mid-file with 200 lines of content after, fixed HTML structure and linked Board (Roman IV) into side-nav and mobile drawer across all 7 pages (was orphaned with zero inbound links). New logo aeoess_logo-06.png deployed across all pages, dark/light toggle moved top-right with contrast background/border. Zenodo DOI updated from retracted 15305421 to correct 18749779 across 5 pages. Commits 1ac19de, b422e3a, 5629b11, 353d950, 56aa73f.

Depends on: mcp-server-ships

Cross-Model Dialogue as Practice

Day 8 outward done

Manual carrying of ideas between Claude, GPT, Gemini. Not assistants, adversarial reviewers. Their disagreements treated as signal. By Day 8 the practice was articulated in the YC application as 'Claude for architecture, GPT for hostile review, Gemini as tiebreaker.' Origin of every later multi-model architectural review.

Depends on: mcp-server-ships

Multi-Agent Ops Layer

Day 8 outward done

Three-bot Telegram group operational (Tima + aeoess on always-on host + Portal on OpenClaw). GitHub comms bridge built (from-portal.json ↔ from-aeoess.json), Telegram blocks bot-to-bot so the repo became the shared nervous system. Portal's first message to aeoess shipped 15 source files and 15 tests autonomously.

Depends on: comms-phase-1-cross-model-dialogue

Layer 5: Intent Architecture

Day 8 Protocol done

Protocol stops being about identity, starts being about decision-making. Intents, proposals, verdicts.

Depends on: mcp-server-ships

The package is placed in twelve distribution channels in a day

Day 7 outward done

Distribution rather than construction: the protocol and the MCP server were listed across twelve or more channels in a single day, including awesome-mcp-servers, clawhub, npm, Smithery and mcp.so. The reasoning was that a package nobody can find is indistinguishable from a package that does not exist, and that the catalogues are where anyone browsing for agent-identity tooling actually looks.

MCP Server + Agora Seeded

Day 6–7 Protocol done

11 tools native in every major AI dev environment. npm SDK + MCP live. awesome-mcp-servers PR on the 81K-star repo. Agora seeded with first signed messages from claude, aeoess, PortalX2.

Depends on: project-begins

The Community Shows Up

Day 4–5 outward done

Days 4-5. Paper published. Media coverage breaks. First wave of external attention.

Paper 1: Agent Social Contract

Day 4–5 Research done

First formalization of agent governance as a social contract. Ed25519 identity, monotonic delegation.

Depends on: project-begins

First media coverage arrives one day after launch, unplanned

Day 2 outward done

One day after the protocol and the npm package went public, the work drew its first outside coverage. The timing was not arranged. Recorded because it is the first evidence that the problem was already on other people's minds rather than only on ours.

Project Begins

Day 1–2 Protocol done

Ed25519 identity, delegation chains, first tests. 'The Speed of Wrong vs The Speed of Right.' SDK v0.1.

Backlog (8)

Compliance reports (EU AI Act, re-anchored Dec 2027)

Day 500–560 Product backlog

Gateway endpoint GET /api/v1/compliance/report generating machine-readable and human-readable reports mapped to EU AI Act Article 10 and GDPR Article 30. Sections: agent registry, delegation inventory, evaluation log, revocation history, behavioral sequence per agent, data lifecycle, attestation summary. Query params: since, until, agent_id. The underlying data already exists in the gateway; this is formatting work, not new primitives. Re-anchored 2026-07-16: the Digital Omnibus on AI (political agreement 2026-05-07, adopted by the European Parliament 2026-06-16) defers Annex III high-risk obligations to Dec 2, 2027 and Annex I embedded systems to Aug 2, 2028; Article 50 transparency still applies from Aug 2, 2026 and is a thin slice of this surface. Build window targets mid-2027, ahead of the Dec 2027 date. Enterprise buyers increasingly require this reporting. Lives in the private gateway (product intelligence), not the public SDK.

Depends on: build-d-gateway-enterprise

Paper 7 v2: multi-layer + transcoder + SCITT mapping

Day 280–400 Research backlog

Three v2 items (12+ months out). (1) Multi-layer attestation specification, currently single layer, v2 needs composition semantics across multiple layers of the same forward pass. Load-bearing for decision-pathway attestation (vs concept-engagement attestation). (2) Transcoder and crosscoder attestation, v1 restricts to SAE variants with well-defined layer_index; transcoders operate across layers, spec needs a coherent representation. (3) SCITT CBOR/COSE mapping, v1's JSON/JCS canonicalization re-serialized under SCITT's canonical encoding rules, enabling cognitive attestations as SCITT transparency-log entries. Revisits the Ledger Events kill territory from a different angle.

Depends on: paper-7-v1-2-zkml-policy

Paper 7 v1.2: zkML + OPA/Cedar policy extension

Day 200–280 Research backlog

Two v1.2 items. (1) zkML or TEE-backed inference attestation paired with cognitive attestation, so the envelope proves both what features were active AND that the claimed inference actually ran on the claimed model. Research-stage engineering, 6+ months. (2) Working demonstration of feature-level policy expressions against cognitive attestation envelopes (OPA / Cedar / XACML). "Reject any action where feature 20946 is active above 2.0." Could spin out as a separate paper rather than a v1.2 side-product.

Depends on: paper-7-v1-1-governance-study

The trusted job checks out a mutable branch name rather than the exact base commit the pull request was evaluated against

Day 197 security backlog

Found while wiring the oracle and kept out of that chain on purpose. The job takes its grading code from the base branch by name, so the oracle is not reproducible against a fixed base, and a base that moves between checkout and run silently changes what trusted means for that run. It governs all three trusted invocations and predates the chain. The fix is not a one-line reference swap: pinning changes what the job is authoritative against and interacts with how a merge commit is produced, so it gets its own threat-modelled change. Recorded on its own so a harvest of finished rows cannot delete it along with the chain that found it.

Build H: Post-Quantum Sigs

Day 171–260 Protocol backlog

Signature interface for Ed25519 or CRYSTALS-Dilithium without breaking delegation chain semantics.

Depends on: build-a-attribution-primitive

First hosted-gateway conversion

Day 171–260 Product backlog

Commercial milestone: the first tenant on the hosted gateway converts from the free tier. The portal and billing infrastructure went live in the Day 49 to 50 customer-ready work, so this is a sales and outreach motion rather than a build motion, and it sits in a founder lane.

Depends on: customer-ready-gateway

SCITT agent-profile (Ledger Events revival path)

Day 171–230 Research backlog

If SCITT (IETF Supply Chain Integrity, Transparency, Transparency) stalls at IESG or if the WG explicitly asks who is doing agent-specific profiles, the Ledger Events revival path is to ship a SCITT statement-type profile for agent governance receipts, not a parallel bespoke spec. Standing revival criterion, not active work. Track ietf-scitt-architecture on the standards-scanning pipeline (added to the watch list after the Ledger Events kill).

Depends on: ledger-events-primitive

Paper 7 v1.1: N≥200 governance-relevance study

Day 120–200 Research backlog

Scale the Neuronpedia experiment from N=10 per group to N≥200 per group. Mechanical work, most code exists. Paired with controlled-probing feature-label validation (targeted prompts to activate/suppress the described concept), exact prompt set published in experiment/prompts-v1.1/, hosted-to-local verification transfer characterization (local sae_lens vs Neuronpedia hosted, within paper's epsilon), and cross-hardware reproducibility (H100 vs A100 or MI300X). This is the condition for submitting to FAccT/NeurIPS as a peer-reviewed venue rather than leaving the paper at preprint stage.

Depends on: d62-paper-7-cognitive-attestation

Killed (with rationale) (6)

Ledger Events primitive (KILLED Day 61)

Day 62–64 Protocol killed

Planned as the next protocol build post-v2 swap but killed on Day 61 review. Three-factor check failed on all three axes: concrete external demand (none surfaced), clean scope versus SCITT (substantial overlap), additive value beyond the existing ledger stack (marginal). Postmortem at specs/killed/LEDGER-EVENTS-v0-KILLED-2026-04-17.md with revival criteria for future reference. Former handoff prompt renamed to specs/killed/LEDGER-HANDOFF-PROMPT-STALE-2026-04-18.md with stale banner. Replaced in the v2.1.0 slot by Cognitive Attestation envelope primitive (actual demand, clean scope).

Killed: Killed Day 61 multi-model architectural review (Claude + GPT-5 + Gemini 2.5 Pro). Three-factor check failed on all axes: no concrete external demand, substantial SCITT overlap at IETF draft-22, marginal additive value beyond the existing ledger stack. Revival criteria: (1) a partner arrives with a dispute-resolution requirement our existing primitives cannot handle, OR (2) SCITT stalls at IESG and an agent-specific profile is needed, OR (3) a regulatory forcing function requires signed dispute lineage. "I can see it coming" is explicitly not a revival criterion. Replaced by Cognitive Attestation envelope (Paper 7, shipped as SDK v2.1.0 on Day 64).

Depends on: d61-v2-architecture-separation

Standalone Attribution Primitive paper for arXiv

Day 54–60 Research killed

A standalone academic paper on the unified four-axis attribution object was originally planned for the Paper 6 slot in the research sequence around Day 54-57. The working code (Build A + B + C + D2, Days 59-60) shipped first with full implementations across SDK, MCP, and Python.

Killed: Not killed as in abandoned, killed as a standalone paper target. The working code arrived before the formal paper felt necessary. Venue pull never materialized (no reviewer asked for a paper, no conference deadline demanded one). The material remains strong and will likely land as part of the AISec Workshop submission (aisec-workshop-paper) alongside Paper 4 + Paper 7 material. Revival criterion: a concrete venue deadline that requires a bespoke Attribution Primitive paper separately from the other papers.

Depends on: attribution-primitive-spec

Cascade verification (supervisor chain)

Day 48 Protocol killed

Proposed Day 48. Before every delegated action, walk the full delegation chain and require each supervisor in the chain to re-verify that the downstream action is still within scope. Intended to catch chained compromise through deep delegation trees.

Killed: Killed Day 48 own-team attack. Supervisors rubber-stamp clean history. Routing is attacker-controlled, so an attacker can present only the supervisors who will sign. UX kills adoption, every action blocks on N manual approvals. Fell apart on first red-team pass. Replaced by structural authority-class separation plus non-bypassable timelocks at action time, not trust-chain verification. 95% confidence kill.

Depends on: multi-model-review-methodology

Forensic attribution test (5-signal)

Day 48 Research killed

Proposed Day 48. A five-signal test to detect whether an authorized trade was secretly colluding with a counterparty, checking ordering, size, timing, pricing, and trajectory against benign baselines. Would have produced a forensic score on every gateway-observed action.

Killed: Killed Day 48 multi-model architectural review. All four model reviewers (Claude, GPT-5, Gemini 2.5 Pro, plus a fourth adversarial Claude) independently designed an undetectable attacker class, legitimate-looking losing trades against colluding counterparties within per-transaction limits. The test catches naive attackers designed to be catchable and fails against adversarial-aware ones. Building it is a waste. Replaced by cumulative-exposure-tracking: enforce net position change per delegation per rolling window at the gateway, not behavioral forensics per action. 95% confidence kill.

Depends on: multi-model-review-methodology

Quantum computing inside APS

Day 42–51 Research killed

Days 42-51. Six weeks of circling three framings for using quantum computing to strengthen APS itself: quantum speedup for delegation-chain math, quantum randomness for keygen, Bell-state non-collusion proofs between gateways. Each felt like it should work; none actually did.

Killed: Killed Day 51 multi-model architectural review. Quantum speedup for APS math: delegation verification is already microsecond-fast, no asymptotic win matters. Quantum randomness for keygen: modern CSPRNGs are commodity, a quantum source adds cost with no security delta. Bell-state non-collusion: cute, not useful, the threat model doesn't need entangled gateways. Correct reframing: put APS *around* quantum, not quantum inside APS. Shipped as Paper 5 (Physics-Enforced Delegation, Zenodo 10.5281/zenodo.19478584) governing quantum hardware physics via delegation facets. Six weeks of circling produced a Zenodo paper and an IBM experiment, just not the paper we set out to write.

Depends on: multi-model-review-methodology

vessenes entity binding test (A2A#1575)

Day 37–62 outward killed

An entity binding test promised to @vessenes on a2aproject/A2A#1575 around Day 37. The test would have demonstrated how a single entity (person or org) could be bound to multiple agents across different identity systems with APS as the binding layer. Sat open in the promise ledger for ~25 days.

Killed: Dropped Day 54 and formally killed Day 62. The thread moved past entity binding into TCP-IP-vs-Visa architectural framing; kevinkaylie's AgentNexus participation made it a three-issuer architecture discussion, not a bilateral entity-binding test. vessenes has since closed APS#5 (Ed25519→X25519 test vectors) on his side without requiring our output. No partner harmed, no drift. Keep it visible as a reminder that sitting promises age: re-evaluate open promises older than 14 days, decide send/drop/pause.

Depends on: qntm7-xsa520-response

Other (no status declared) (38)

A2A's AgentCard signing example cannot be verified as published, filed upstream

Day 216 Standards waiting

The specification publishes neither the verification key nor the exact signed payload, and it never pairs the example signature with the canonical form it defines. The issue asks for both.

An Agent Replay run over the lab's corpus reproduced, and recorded as an observation

Day 216 conformance waiting

Its 13 vendored fixtures are byte identical to the suite's, and every recorded blob hash matches. How the lab records an external tool is still an open question, and this is not counted as adoption.

A Bernstein assignment we held for 17 days was released before we delivered

Day 216 Ecosystem dropped

The issue is a delegation chain that still verifies after its final receipt is removed. The maintainer freed the assignment. Recorded as dropped.

The TRACE action receipt integration rebuilt on Python 4.0.0 and returned for review

Day 216 interop waiting

It verifies a draft-03 action intent, issued and signed by the acting agent, with the fixed declaration as its result. Key resolution failures report as unverified, never as bad signatures. An appended third-party signature can no longer change the result. The fixture's authority delegation is real, and its validity is tested separately.

A published paper describes APS delegation as a single-parent rooted tree, and against the current draft that is fair

Day 213 Protocol proposed

Each delegation record has one parent identifier, one chain authorizes an action, scopes and budgets are never unioned across chains, and revocation cascades through descendants. The limit is at the record level rather than the agent level: an agent holding two unrelated chains keeps the second when the first is revoked, but a descendant created under the revoked chain does not survive on the strength of the other. No correction is owed to the authors. What is recorded is a design question on revocation semantics for independently authorized shared agents, not a change, and not the obvious change of making the parent field an array.

The OWASP AISVS binding requirement was closed by the maintainer as too aspirational for 1.01, and nothing further was posted

Day 212 Standards dropped

The test had already been tightened to the binding with a first-declaration negative fixture after a reviewer's correction, and the reviewer had accepted the requirement. The maintainer closed to keep the backlog concise and left the door open for later. No follow-up comment, no related issue. Not a rejection of the finding, not an acceptance of the requirement, and not evidence that an executable vector is what it lacked.

The evidence-sufficiency rule text was put to CoSAI WS4 #189 for the reviewer to confirm or tighten

Day 212 conformance waiting

A negative claim over a scope passes only when both field visibility and observation completeness for that same scope are established, whether the relevant field is absent or present but empty. Missing either gives not_established with the unmet obligation named. Malformed input, unsupported verification, parser failure and internal error stay outside the verdict. Posted as a question to the reviewer who found the four defects, not as a settlement. The merged candidate cases stay labelled candidate against proposed text.

The governance vocabulary can read the physical world as context and cannot name authority over it

Day 206 vocab in-progress

governed_action_class has six values, all digital-native, and none of them describes operating a sensor or an actuator. physical_environment_state already exists as a context dimension resolved from signed sensor readings, so the physical world sits on the input side of a decision with no matching class on the action side. The issue proposes no new values. Three outcomes are named as legitimate, including that the six classes are deliberately broad and nothing changes.

A boundary statement for what a verifier may conclude when evidence is absent, delivered to the CoSAI workstream that asked for it

Day 206 Standards in-progress

Three parties had reached the same requirement separately: a verifier that finds no evidence needs a third answer, because absence is neither conformance nor violation. The statement keeps three layers apart. A runtime outcome describes what happened, a receipt-chain outcome describes a disclosed gap in a chain, and not_established is the property verdict, returned after the applicable verification has run when the admissible evidence justifies neither pass nor fail. It must name the unresolved obligation and must not absorb verifier failures, or a broken verifier becomes conformant by returning the third value. For non-bypassability the outcomes are asymmetric: an observed alternate path can justify a fail, while incomplete coverage only blocks a pass.

A third OpenClaw fix went up with a unit regression, the review bot asked for a real Gateway trace, and the first attempt at that trace said the fix did nothing

Day 203 Ecosystem in-progress

The completion path dropped a requester agent id that spawn had already persisted, so on a multi-agent Gateway a finished child re-derived its owner, threw, and retried forever. The first real-Gateway run reported the fix changed nothing; the cause was a build stamp keyed to the git head, which let an edit-run-revert cycle reuse the mutated build. With the stamp deleted on both sides the restored-row case fails without the line and delivers with it, three runs each way, and that e2e is now the second commit on the pull request.

agentrust-trace 0.10.0 fixed the schema defect and surfaced a question the integration cannot answer alone: must a Level 0 record pass the full verifier

Day 203 interop in-progress

The witness run against the published wheel confirmed the packaged-schema fix and the fail-closed revocation stores. It also showed the APS mapper's record, which omits three fields APS never observes, now fails verify_record while still passing trace-tests at Level 0, and the integration's own CI has been red since the release. The repository's adapters guide already says there is nothing truthful to default the missing digest to, so the issue asks only which of the two graders defines Level 0; tested_against stays at 0.9.0 until it is answered.

The OpenClaw atomic-write fix was rebased onto the current upstream head with the patch unchanged, and the request's evidence section refreshed with the current red and green numbers

Day 200 Ecosystem in-progress

After the upstream flake fix merged, the branch was rebased onto the new head, force-pushed with lease, and range-diff shows the patch identical. The regression is red on the base at 1 failed and 149 passed and green at 150 with the fix; the pull request body now carries those numbers. A second rebase onto later unrelated commits was declined because CI was already running on the current head.

The bernstein draft was rebased onto the current upstream head with no conflict, and its one red test stays red because upstream chose the other semantics

Day 199 Ecosystem in-progress

The record_delegation_hop branch rebased cleanly. The narrowing test that fails does so because an upstream change (#5306) adopted a file-scope model that collides with the fail-closed contract the maintainer chose for this PR. Changing the test to pass would hide the collision, so it stays red, and one question on the PR asks the maintainer to pick between three file-scope models. A side finding became its own issue (#5390): the fast path's formatter calls escape their working directory, which also explained a day-old anomaly in our own scratch tree.

The audited release commit merged with its identity intact, and the hardening change that followed surfaced two high-severity races in the release helpers

Day 197 security in-progress

The security release landed on main as a two-parent merge pinned to the audited head, so the published release identity survives as a first-class commit instead of being squashed away; ancestry was proven from a fresh clone rather than from the compare endpoint, which answers a different question. The hardening candidate was then pushed and opened against that main with all four required checks green. The alert gate failed anyway: two new high-severity file-system-race findings, one in the helper that computes the digests deciding publish versus skip, one in the helper that parses the manifest whose publication-redirect check depends on it. Both resolve a path, validate it by name, then read the name again; nothing binds the validated object to the bytes consumed. The candidate is superseded. The fix is a same-open-file invariant with no-follow and non-blocking open semantics, because a naive no-follow open on a special file trades the race for a hang in a privileged job, and a fallback to the pathname sequence is forbidden because it is the defect.

Two of the lab's own rulings disagreed about one family, and the fix is one rule: npm run verify is the generic corpus, npm test is the gate

Day 194 conformance in-progress

A day-old sentence said npm test does not execute external families. A two-day-old ruling required an allowlisted family's dedicated verifier and mutation proof to run in npm test. The oracle-safety-check family satisfied the second and violated the first, and the contributor could not satisfy both. The family stays in the gate; the sentence was wrong. The policy change also gives the lab one definition of independent, the runner authored neither the vectors nor the implementation whose output supplies the recomputation, a thin harness around independent primitives does not make a record author-produced, and a harness that decides the semantic result is part of the implementation; and it makes mode and authorship two axes that never determine each other. Committed locally, lands before the two families it unblocks.

Two field names attributed to APS in a vocabulary entry do not exist in APS, and the source of the error was me, months ago

Day 194 vocabulary in-progress

The bilateral_receipt entry lists compromise_window_ts and evidence_merkle_leaf as APS-only fields. Neither exists: the receipt field is evidenceCommitments and the compromise window is a verifier input, not a receipt field. The names were confirmed verbatim on the originating issue in May by me. The entry is otherwise sound and held at reserved; the correction is two dropped lines, and the promotion trigger stops naming two projects. The contributor carried the error in good faith and is owed the fix, not the blame.

Delegation attack pack proposed to a PHP security package, with the model gap it exposed filed separately

Day 191 Ecosystem proposed

Six actor-versus-subject confusion cases for fissible/verdict, five live and one pending on their cross-invocation lineage issue, following their existing pack structure; three tests make the identity assertions fail on purpose; their full local gate passed (1157 tests, 4178 assertions). Their observation object never exposes the persisted decision evidence row, so no pack can assert on the recorded actor or subject fingerprint directly; the PR states that limit, addresses rather than closes their issue, and the gap is filed as its own issue, cross-linked. Written entirely in their vocabulary.

Charter text proposed for the IETF AUDIT BOF after the chair asked for it

Day 149 Standards waiting

One sentence appended to the audit data models deliverable: the models carry what is needed to correlate an interaction across domains with the authorization under which it was taken, and to evaluate relationships among delegations that a record claims. Three adversarial reviews killed two earlier versions that assumed authorization is tree-shaped. PR open and unreviewed.

W3C CG ai-agent-protocol #32 correction plus blog erratum queued (agent-morrow note)

Day 136 Standards dropped

Correction opened on w3c-cg/ai-agent-protocol #32 with a paired blog erratum and an agent-morrow note, extending the same never-measured-figures cleanup started with the CSA provenance correction.

Killed: Dropped 2026-08-06 in the Day 171 audit. The correction and the erratum both shipped; the item tracked a cleanup arc that has no remaining work. Reversal cost: none, a fresh correction gets its own entry.

did:cycles verify-path wiring and Cycles golden-fixture vectors (required follow-up)

Day 121–170 Protocol dropped

The stacked follow-up to aps#46: wire signer_did through the resolver into envelope verification so issued_at is bound to the authentic signed payload, and add the byte-for-byte Cycles golden-fixture vectors covering open-ended expiry, rotation overlap, and path-bearing server_id. Two confirmations fold in here: that an open-ended cycles_exp_ms is the intended active-key model per the Cycles thread rather than a required bound, and that the rotation-overlap rule (kid disambiguates, residual ambiguity fails closed) matches the settled text. No Cycles-conformance claim ships before these land.

Killed: Dropped 2026-08-05 after 49 days waiting with no upstream movement. Reversal cost: low, the fixture work is small if Cycles resumes.

A sibling attestation predicate is drafted and never opened, because the pull request it depended on closed unmerged

Day 118–170 Standards dropped

Draft scaffolding was written for a session-level governance attestation predicate, designed to sit beside a decision-receipt predicate proposed upstream and reference it by hash. The trigger was that upstream pull request landing. It closed without merging, so the sibling was never opened. Recorded as dropped rather than left pending, because the condition it waited on has resolved in the negative. Reversal cost is low: the scaffolding survives and the design still holds if a predicate of that shape is proposed again.

Killed: Dropped 2026-08-05. Upstream in-toto/attestation PR #549 closed unmerged, so the trigger condition failed. Draft scaffolding retained.

CoSAI tool-registry integrity: APS adds the missing four components

Day 92 Standards dropped

OASIS Coalition for Secure AI has a control proposal in review (controlToolRegistryandDiscoveryIntegrity) covering integrity of tool registries, manifests, and discovery endpoints. APS already had signed registry entries and implementation-hash integrity. The cosai-tool-registry-integrity branch adds the other four required pieces: signed tool manifests with a distinct metadata hash, publisher identity verification against an external trust root or APS-native identity, namespace governance so a tool under a claimed namespace must be published by that namespace's owner, and re-approval bound to a resolved attestor identity (metadata change moves a manifest to pending, only a verifiable attestor can clear it). Each piece has tests including adversarial cases plus cross-language conformance vectors. APS offered as reference implementation for the CoSAI control proposal.

Killed: Dropped 2026-08-05 after 76 days stalled. The CoSAI engagement continued on ws4 #99 instead, where APS is cited by name in the synthesis to the RFC drafters. Reversal cost: low, reopen if a tool-registry integrity work item appears.

Colorado AI Act compliance reports (Jun 2026)

Day 90–110 Product dropped

Colorado AI Act enforcement window begins Jun 2026 (≈ Day 105). Subset of the EU AI Act reporting surface with Colorado-specific jurisdictional tags in the report metadata. Lower regulatory bar than EU but earlier deadline. Same private-gateway endpoint pattern, smaller report scope.

Killed: Dropped 2026-08-06. A jurisdictional subset of the EU AI Act reporting surface, which is itself still future-dated. Building the narrower one first inverted the order. Reversal cost: low, it reduces to tags on the wider surface when that ships.

Depends on: compliance-reports-eu-ai-act

Machine unlearning verification (Paper 4 open problem)

Day 85–100 Research dropped

Named as one of four open problems in Paper 4 (Behavioral Derivation Rights). When a principal revokes consent for their data to have shaped an agent's behavior, can we verify cryptographically that the agent has actually unlearned it? Hard problem with no clean answer in the literature. Research item, not a build item, likely ships as a paper before it ships as code.

Killed: Dropped 2026-08-05 in the Day 170 audit. No evidence on disk. Remains an open research question in Paper 4. Reversal cost low: the item can be reopened with a new window if it is wanted.

Depends on: paper-4-bdr

AISec Workshop at ACM CCS submission

Day 78–90 Research dropped

Paper submission target ~July 2026 deadline. Likely draws on Paper 4 (Behavioral Derivation Rights) and Paper 7 (Cognitive Attestation) as the empirical spine. LaTeX conversion pipeline needed, current paper pipeline ships markdown-to-PDF. Workshop is the first venue where APS can land a paper alongside mainstream AI security research rather than in the protocol-spec lane.

Killed: Dropped 2026-08-06. The submission window passed without a LaTeX pipeline, and the empirical spine it would have drawn on is published as papers in its own right. Reversal cost: medium, a future venue means rebuilding the conversion pipeline.

Depends on: paper-4-bdr

Build E: Converged Orchestrator

Day 75–90 Product dropped

Routes queries to Claude, GPT, Gemini simultaneously. Attribution Receipt per model. Synthesized answer with receipt chain.

Killed: Dropped 2026-08-05 in the Day 170 audit. No evidence on disk in any repository or record. Reversal cost low: the item can be reopened with a new window if it is wanted.

Depends on: build-a-attribution-primitive, build-g-oversight-harness

Vocab issue #73: self_enforced proposed as fifth refusal_authority value

Day 75 Protocol dropped

Surfaced while auditing nobulex.yaml refusal_authority self_enforced usage. Distinct from #57's confusion (which was about location vs strength). Nobulex collapses actor and enforcer architecturally via Cedar-inspired covenant DSL where evaluator_did equals agentDid; refusal happens because the agent runtime cannot perform the refused action by construction. The four canonical values (issuer, verifier, consumer_policy, shared) cannot capture this pattern. Proposes adding self_enforced as canonical fifth value. Tagged arian-gogani for confirmation, Douglas Borthwick + QueBallSharken + MoltyCel for naming alternatives.

Killed: Dropped 2026-08-06 in the Day 171 audit. The refusal_authority question was resolved inside the registry rather than by adding a fifth value. Reversal cost: low, the audit trail on the issue survives if the distinction is needed later.

in-toto SVR extension Go decision

Day 73 outward dropped

Path forward for governance attestation as an in-toto SVR extension scoped. Worked-example draft underway in private workspace at INTOTO-SVR-EXAMPLE-DRAFT/. Two artifacts: agent-governance-svr-extension.md (~200 LOC) plus agent-governance-svr-extension.json (~80 LOC). Single-SVR shape per maintainer framing; two-SVR variant flagged as open question for May 1 meeting. May 1 CNCF #in-toto-attestations meeting attendance committed (per Apr 28 PR #549 comment). Bilateral byte-match track with marcelamelara holds in parallel. aeoess/governance-attestation-predicate stays canonical. [DROPPED 2026-05-11: PR #549 closed unmerged 2026-04-28. No active aeoess activity on in-toto since. governance-attestation-predicate stays canonical at aeoess.]

Killed: Dropped 2026-08-06. Superseded by the sibling-predicate route, which was itself dropped when the upstream in-toto pull request it depended on closed unmerged. Reversal cost: low, the draft scaffolding is retained.

Build D: Gateway Enterprise

Day 70–85 Product dropped

Multi-tenant isolation, dashboard views, and compliance reporting for the hosted gateway. Product work on the private side of the boundary, listed here so the roadmap is complete rather than to describe the commercial design.

Killed: Dropped 2026-08-05 in the Day 170 audit. Superseded by d50-customer-ready-gateway, which records the customer-ready gateway shipping on Day 50, before this window opened. Reversal cost low: the item can be reopened with a new window if it is wanted.

Depends on: build-d1-audit-export, build-d2-jws-fix

Attribution primitive formal paper (deferred)

Day 70–90 Research dropped

A standalone academic paper on the unified four-axis attribution object was planned for the Paper 6 slot in the research sequence, but the working code (Build A + B + C + D2, Days 59-60) landed first and the paper never materialized as a standalone artifact. The material is strong enough to ship as a paper whenever there is pull, but there has been no concrete demand for it. The AISec Workshop submission is a more likely home for this material than a standalone Zenodo drop.

Killed: Dropped 2026-08-05 in the Day 170 audit. Duplicate intent with killed-paper-attribution-standalone-arxiv, which already records the decision. Reversal cost low: the item can be reopened with a new window if it is wanted.

Depends on: attribution-primitive-spec

a2a-compliance-harness PR #1: MolTrust optional resolver adapter (almost-merge, DRAFT)

Day 69 outward dropped

MoltyCel published moltrust v0.2.0 to PyPI today, then opened a PR adding moltrust as an optional resolver adapter to the harness with a clean fallback path when the package is not installed. Thirteen tests pass on Python 3.12. Two minor asks from review (a docstring sharpening and a pytest.skip for the no-moltrust path), both acknowledged. Co-maintainer access granted on aeoess/a2a-compliance-harness with maintain permission tier (effective write per org base-permission cap). Once MoltyCel marks the PR ready for review on Monday, the merge is mechanical. MolTrust now positioned as a drop-in second-issuer reference under the harness's resolver interface; the harness was originally shipped as APS-only on Apr 21 (a2a-compliance-harness v0.1). Three weeks of cycle: schema lock (Apr 17 a2aproject/A2A#1742), v0.1 single-issuer ship (Apr 21), second-issuer drop-in (Apr 25). [DROPPED 2026-05-03 per CTO call. MoltyCel harness#1 stays on inbound-only watch list. No active integration work.]

Killed: Dropped 2026-08-06 in the Day 171 audit. The optional resolver adapter is the contributor's to carry, not ours; the two review asks were delivered and the decision belongs upstream. Reversal cost: none.

Feasibility linting for delegations

Day 68–72 Protocol dropped

Tier-0 advisory checks at delegation creation + task assignment time. Catches valid-but-useless delegations before they fail silently at action time. Five cheap checks to ship first: spend limit below minimum useful amount for scope, scope does not cover required permissions for assigned tools, deadline already passed or delegation expires before task could complete, delegation depth at max (cannot sub-delegate), missing escalation path. Returns {severity, code, message}. Never blocks, advisory only. Admin UX fix, not a protocol invariant.

Killed: Dropped 2026-08-05 in the Day 170 audit. No commit, decision block or blog post mentions it after Day 72. Reversal cost low: the item can be reopened with a new window if it is wanted.

Depends on: d64-v210-cognitive-attestation

Gonka #1008 Cosmos SDK integration offer

Day 64–78 outward dropped

Substantive 1144-word reply on gonka-ai/gonka#1008 answering paranjko's three questions with concrete Cosmos SDK event shapes. Three attestation types defined: ProposalClassificationAttested, WeightClassAttested, DeliverableAttested, each with typed events slotting into Gonka's existing ante_validation.go pattern. Three-way deliverable attestation (proposer/evaluator/adjudicator) with auto-consensus at 0.15 tolerance using APS outcome-v2 primitives. Honest boundary statement on whale concentration (contract-level, not attestation-level). Offered Go-side Ed25519 verification library + ante handler wiring + CosmWasm helper contract as 1-2 weeks focused work if #1008 moves forward. First Cosmos SDK integration opportunity for APS; if shipped, positions for Juno/Osmosis/Secret/Cosmos Hub next. Gonka founders are Tima's friends/investors, friend-register, not commercial ask.

Killed: Dropped 2026-08-05. The referenced issue gonka-ai/gonka#1008 returns 404, so the condition this item was contingent on can no longer be evaluated. Reversal cost: reopen if Gonka resurfaces the integration offer on a live thread.

Depends on: d64-ecosystem-engagement-13

MolTrust fixtures Week 2-3 (consumer test script)

Day 64–72 outward dropped

Week 2 of the 3-week arc with @MoltyCel (A2A#1742, reconfirmed Apr 18 with sha256:hex delegation_chain_root format locked). Week 2: APS produces fixtures with non-trivial delegation_chain_root values (multi-hop chains, scope narrowing, revoked-parent negative testing). Week 3: consumer verifier test script validates both APS + MolTrust cards against single canonical schema. MolTrust import weighting note: 0.3 weight with 45-day half-life, POST /identity/resolve before import. Week 2 partially landed via ScopeBlind/agent-governance-testvectors PR#2; Week 3 still to ship.

Killed: Dropped 2026-08-06 in the Day 171 audit. The three-week fixture arc did not continue past week one on either side. Reversal cost: low, the format is locked and week one is on record.

Depends on: d62-scopeblind-fixture-prs

A2A #1713: Dual-Signature

Day 56–58 outward dropped

Envelope schema design. Chat Claude owns, Cowork renders.

Killed: Dropped 2026-08-05 in the Day 170 audit. The referenced thread is not ours to carry; it appears in the watch record as a live external thread. Reversal cost low: the item can be reopened with a new window if it is wanted.

Marketplace Proposal

Day 55 Product dropped

Public articulation of gateway-as-marketplace thesis. Attribution flows to contributors when their work is used.

Killed: Dropped 2026-08-06. The gateway-as-marketplace thesis stayed a thesis: no public articulation shipped and the commercial design belongs on the private side of the boundary. Reversal cost: low, the argument is intact and undated.

Depends on: attribution-primitive-spec

Harold fixture batch for agentid-aps-interop (goodwill)

Day 54–72 outward dropped

Seed Harold's agentid-aps-interop repo with the first APS fixture batch as a goodwill gesture. Unprompted delivery with a short note crediting inspiration back to him. Open since Day 54. Harold is the canonical external collaborator (32/32 tests passing, PolicyChain primitive adopted into APS SDK with name-attribution) and deserves the unasked-for contribution pattern that compounds trust.

Killed: Dropped 2026-08-06. The relationship it was meant to open already opened: that collaborator now carries three merged pull requests of ours and a shared interop repository. An unprompted goodwill batch is what you send before that, not after. Reversal cost: none.

Depends on: harold-canonical-repo

@QueBallSharken + @0xbrainkid section co-authorship (vocabulary spec)

Day 54–90 outward dropped

Two active co-authorship invites on the vocabulary spec sections that each contributor has been deepest on. @QueBallSharken on BBIS-adjacent continuity/boundary language, @0xbrainkid on SATP crosswalk semantics. Invites posted 2026-04-21 as aeoess/agent-governance-vocabulary#39 (QueBall on invariant_survival descriptor) and #40 (0xbrainkid on SATP crosswalk + delegation_chain_root field spec). Passive-waiting on response. Co-authorship compounds retention once accepted.

Killed: Dropped 2026-08-06. Two co-authorship invites posted 2026-04-21 that neither contributor took up. Left open they read as pending obligations on people who declined by silence, which is not a fair thing to keep on a public page. Reversal cost: none, either can be re-offered.

Depends on: vocab-contributing-lands