Network Working Group K. Rampalli Internet-Draft Glyphzero, Inc. Intended status: Informational 6 July 2026 Expires: 7 January 2027 A Layered Requirements Mapping for Cross-Organization Agent Delegation draft-rampalli-cross-org-delegation-mapping-00 Abstract This document records a comparative mapping of two evidence layers for cross-organization AI agent delegation: a per-hop delegation chain (PEDIGREE) and a named-human authorization root (the EMILIA Protocol binding and evidence-graph drafts), evaluated against the nine requirements of draft-reece-wimse-cross-org-delegation under a no-shared-operator assumption. It also records a verifier-facing composition model in which key possession, delegated authority, and pre-execution human authorization are diagnostically separate inputs with independent failure behavior, joined by action digest. The mapping was developed on the WIMSE mailing list; corrections continue there. Status of This Mapping This document is a point-in-time record of a mailing-list discussion. Verdicts apply to the specific draft revisions cited and do not carry forward to later revisions automatically. The canonical venue for corrections is the WIMSE mailing list; agreed corrections will be folded into future revisions of this document. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 7 January 2027. Rampalli Expires 7 January 2027 [Page 1] Internet-Draft Layered Delegation Mapping July 2026 Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License. Table of Contents 1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2 1.1. Assumptions and Verdict Discipline . . . . . . . . . . . 3 2. Combined Requirements Mapping . . . . . . . . . . . . . . . . 3 2.1. Summary Table . . . . . . . . . . . . . . . . . . . . . . 3 2.2. Row Notes . . . . . . . . . . . . . . . . . . . . . . . . 5 3. Verifier-Facing Composition: Diagnostically Separate Inputs . . . . . . . . . . . . . . . . . . . . . . . . . 6 3.1. The Delegation-Chain Row, Stated Explicitly . . . . . . . 7 3.2. Template Compatibility . . . . . . . . . . . . . . . . . 8 4. Security Considerations . . . . . . . . . . . . . . . . . . . 8 5. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 9 6. Informative References . . . . . . . . . . . . . . . . . . . 9 Acknowledgments . . . . . . . . . . . . . . . . . . . . . . . . . 10 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 10 1. Introduction Requirements R1 through R9 of [I-D.reece-wimse-cross-org-delegation] describe what cross-organization delegation of authority to AI agents must provide when the relying party and the originating organization share no operator, no runtime, and no bilateral agreement specific to the interaction. During the July 2026 discussion of those requirements on the WIMSE mailing list, two candidate mechanisms were mapped against them independently and were then found to occupy different layers of the same problem: * a delegation-chain layer, in which authority conveyed by a root principal is narrowed at every hop and re-verified end-to-end by the relying party ([I-D.rampalli-pedigree]); and Rampalli Expires 7 January 2027 [Page 2] Internet-Draft Layered Delegation Mapping July 2026 * a human-authorization root layer, in which a named human, or an M-of-N quorum of distinct humans, authorizes a specific action, and that evidence is bound into agent-action records and evaluated with fail-closed verdicts ([I-D.schrock-human-authorization-binding], [I-D.schrock-ep-action-evidence-graph]). Neither layer claims the other's property. The chain proves that authority was conveyed and attenuated; the root layer proves that an accountable human authorized the act. Where the two meet, they join by digest equality, and digest equality is a join key, not a claim of sufficiency. This document records the combined mapping (Section 2) and the verifier-facing composition model that the discussion converged on (Section 3). It defines no protocol and no new evidence format. 1.1. Assumptions and Verdict Discipline The no-shared-operator assumption applies throughout. Each verdict states what holds offline and unconditionally versus what depends on a named assumption, following the conditional form requested in the originating thread. Three entries are not clean passes for the chain layer and are marked as such; deployments should read a "met" verdict together with its stated condition, never without it. 2. Combined Requirements Mapping 2.1. Summary Table "Chain" is the delegation layer ([I-D.rampalli-pedigree]). "Root" is the human-authorization layer ([I-D.schrock-human-authorization-binding], [I-D.schrock-ep-action-evidence-graph]). The composition column states how the layers relate on that row. +=====+===================+================+=======================+ | Req | Chain (PEDIGREE) | Root (EP) | Composition | +=====+===================+================+=======================+ | R1 | Met; inline | Out of layer | Chain-only property | | | conveyance | by design | | | | condition | | | +-----+-------------------+----------------+-----------------------+ | R2 | Anchor assumption | Pinned issuer | Same shape: | | | at chain root | keys, out of | assumption | | | | band (B3) | concentrates at one | | | | | root | +-----+-------------------+----------------+-----------------------+ Rampalli Expires 7 January 2027 [Page 3] Internet-Draft Layered Delegation Mapping July 2026 | R3 | Met offline given | Met offline | Both fail closed | | | conveyance | (deterministic | rather than fetch | | | | policy replay) | | +-----+-------------------+----------------+-----------------------+ | R4 | Deferred to | Not addressed | Shared gap: neither | | | transport (proof | | layer proves | | | of possession at | | possession; WIMSE- | | | the wire) | | native answers at the | | | | | wire are WPT and HTTP | | | | | message signatures; | | | | | composed stack: | | | | | possession at the | | | | | wire, attenuation | | | | | along the chain, | | | | | human authorization | | | | | at the root | +-----+-------------------+----------------+-----------------------+ | R5 | Invariance along | Native to the | Root proves who; | | | the chain (re- | artifact | chain proves nobody | | | verification) | (single or | swapped them | | | | quorum); B2 | | | | | ties it to the | | | | | host record | | +-----+-------------------+----------------+-----------------------+ | R6 | Conjunction | Policy | Entitlements stay | | | native; | identity plus | relying-party data | | | entitlements | replay; | | | | relying-party | entitlements | | | | local | relying-party | | | | | local | | +-----+-------------------+----------------+-----------------------+ | R7 | Lifetime bound | Normative | Root layer closes the | | | offline; fail- | fail-closed: a | gap the chain layer | | | closed on stale | stale verdict | names | | | revocation data | never | | | | is an admitted | authorizes; B4 | | | | revision item | | | +-----+-------------------+----------------+-----------------------+ | R8 | Signed hops; | Evidence | Join by digest: scope | | | SCITT capsule | graph; | versus act, neither | | | binding for the | unbacked edges | claims the other's | | | post-execution | poison; signed | property | | | half | Reliance | | | | | Result | | +-----+-------------------+----------------+-----------------------+ | R9 | Met (JWT/JOSE, | Met (JSON/JCS, | No new formats on | | | pluggable policy) | maps onto | either side | | | | existing host | | Rampalli Expires 7 January 2027 [Page 4] Internet-Draft Layered Delegation Mapping July 2026 | | | formats) | | +-----+-------------------+----------------+-----------------------+ Table 1: Combined R1-R9 Mapping The R5 and R4 cells reflect corrections agreed on-list on 2026-07-05: the named-human and quorum property is native to the receipt and quorum artifacts themselves, with binding requirement B2 tying the artifact's action binding to the host record; and R4's composition cell carries the constructive composed-stack line alongside the shared-gap statement. 2.2. Row Notes The full per-layer mappings live in the originating thread; these notes carry only what the one-line verdicts compress too much. R1, recursive attenuation: The chain meets it from conveyed material alone: per-hop scope subsetting and mandate narrowing are re-checked at verification, not only at mint, and the verifier re-verifies every parent token. The condition is inline conveyance of parents. The root layer does not narrow scope, and should not: it names the human and binds the action. A division of labor, not a gap. R2, cross-organizational verification: Both layers give the same answer in different vocabulary: the trust assumption does not disappear, it concentrates at one pinned root. For the chain that is the originating organization's anchor (self-certifying identifiers remove it for intermediate hops); for the root layer it is the discipline that a binding from an unpinned issuer must not be accepted. R4, proof of possession: The one row where the layers do not cover each other: neither proves possession. The chain binds the holder's key and defers the presentation-time proof to the transport (a WPT [I-D.ietf-wimse-s2s-protocol], HTTP message signatures [RFC9421], or a context-bound per-request token); the root layer addresses evidence binding, not possession. A deployment composing both layers still needs a possession-proving transport underneath, which is why the transport profile holds a first-class seat in the composition model of Section 3. R5, principal binding and invariance: The mirror image of R1. The root layer is native here: an accountable named human, or a quorum, signs, and the artifact's action binding must agree with the host record. The chain's Rampalli Expires 7 January 2027 [Page 5] Internet-Draft Layered Delegation Mapping July 2026 contribution is preservation: re-verification of every hop means an intermediary cannot alter the principal without breaking a signature it cannot forge. The root proves who authorized; the chain proves nobody swapped them en route. R7, authentic bounded-staleness revocation: On the chain side, staleness is bounded by lifetime, offline and unconditionally; event-driven cascade revocation rides a channel assumption; and fail-closed behavior on stale revocation data is an admitted gap, scheduled for the next PEDIGREE revision. On the root side the discipline is already normative: freshness bounds are policy inputs, the verdict set is closed with precedence unverifiable over conflicted over stale over missing_evidence over admissible, and the absence of evidence is insufficient rather than a default. The root layer closes, by construction, exactly the gap the chain layer names. When the chain layer states the same rule normatively, this row becomes two independent enforcements of one rule rather than one layer covering for the other. R8, tamper-evident composable audit: The chain proves scope: every hop is a signed object, and post- execution composition binds per-action authorization and provenance references into SCITT Agent Action Capsules ([I-D.rampalli-scitt-capsule-provenance-binding]), with the anchored tier assuming a transparency service. The evidence layer proves the act: a content-addressed graph in which an edge the bytes do not back poisons the verdict, plus a signed Reliance Result that adds accountability, never authority. They join by digest equality. R3, R6, R9: As the table states; the per-layer mappings in the originating thread carry the detail. 3. Verifier-Facing Composition: Diagnostically Separate Inputs The same list discussion, on a parallel thread about condition- bounded credentials, converged on a verifier-facing structure in which the inputs to an authorization decision are conjunctive for the final decision but diagnostically separate, so that each input class has its own failure path: * enrolled key, actor, workload, and environment binding; * live key possession at connection time; * local condition failure and key unavailability; Rampalli Expires 7 January 2027 [Page 6] Internet-Draft Layered Delegation Mapping July 2026 * external lifecycle or policy events, such as a Shared Signals / CAEP-class channel; * authorization inputs: audience, scope, operation, and time bounds; * an inherited delegation-chain input, where PEDIGREE or another chain mechanism supplies the authority path; and * pre-execution human authorization: a named human, or an M-of-N quorum of distinct humans, authorized this exact operation, bound to the same action digest the other rows join on. A live key with a valid, sufficiently scoped chain still fails closed if a required human authorization is absent, stale, or bound to different action bytes; a valid chain whose holder cannot prove possession fails as a presentation failure; a valid key whose terminal scope does not cover the operation fails as an authorization failure. No row inherits or grants another row's guarantees. 3.1. The Delegation-Chain Row, Stated Explicitly The mapping-table rules of [I-D.bu-agentproto-security-principal-binding] require that an inherited mechanism state its dependency and failure behavior before it counts as a guarantee. The delegation-chain row, with PEDIGREE as the supplier, in those terms: Claim: authority for this exact operation was conveyed from the root principal and narrowed at every hop; the terminal scope covers the operation. Carrier: the per-hop delegation tokens, conveyed inline with the request. Verifier and rule: the relying party, offline: re-verify each hop's signature against its issuer key, check per-hop scope subsetting and mandate narrowing, take effective expiry as the minimum over hops, and require the operator-ceiling conjunct. Binding and freshness: bound to the root principal and to the holder's key; staleness bounded by chain lifetime; cascade revocation rides a Shared Signals / CAEP-class channel where one exists. Failure behavior: any hop signature failure, subset violation, or Rampalli Expires 7 January 2027 [Page 7] Internet-Draft Layered Delegation Mapping July 2026 expiry fails the request as an authorization failure, independently of key possession and of human authorization. A revocation feed older than the configured bound must fail closed; making that normative is a scheduled PEDIGREE revision item. Dependency: the originating organization's trust anchor (root only; intermediate hops use self-certifying identifiers), inline conveyance of parent tokens, and the possession row at the transport for holder proof. Stated that way, nothing is inherited implicitly: the chain row supplies the authority path and its attenuation, and it explicitly depends on the possession row rather than assuming it. 3.2. Template Compatibility Each row of Table 1 and each input class above is kept expressible in the mapping-table template of [I-D.bu-agentproto-security-principal-binding] (claim, carrier, verifier and rule, binding and freshness, failure behavior, dependency, evidence reference). If the working group settles on that shared shape for comparative tables, moving this document into it is a re-rendering rather than a rewrite. 4. Security Considerations This document defines no protocol elements and introduces no new attack surface. Its risks are risks of misreading: * A conditional verdict read as unconditional. Every "met" in Table 1 carries its stated condition; a deployment that drops the condition (for example, accepting a chain without inline conveyance of parents, or trusting an unpinned issuer) does not have the property the verdict names. * Implicit inheritance across layers. The layers compose by digest and by conjunction; neither inherits the other's guarantees, and Section 3 exists precisely to keep their failure classes separate. In particular, neither layer proves possession (R4); a deployment without a possession-proving transport is open to replay of captured material regardless of how strong the chain and the root evidence are. * Version drift. Verdicts apply to the cited revisions only. A future revision of any mapped draft can invalidate a row without notice; the mailing-list thread, not this document, is the canonical record of corrections between revisions. Rampalli Expires 7 January 2027 [Page 8] Internet-Draft Layered Delegation Mapping July 2026 5. IANA Considerations This document has no IANA actions. 6. Informative References [I-D.bu-agentproto-security-principal-binding] Bu, S., "Security Principal and Verifier Binding for Agent Communication Protocols", Work in Progress, Internet- Draft, draft-bu-agentproto-security-principal-binding-01, June 2026, . [I-D.ietf-wimse-s2s-protocol] IETF WIMSE Working Group, "WIMSE Workload-to-Workload Authentication", Work in Progress, Internet-Draft, draft- ietf-wimse-s2s-protocol, 2026, . [I-D.rampalli-pedigree] Rampalli, K., "PEDIGREE: Per-Agent Delegation Identity with Governance-Enforced Execution", Work in Progress, Internet-Draft, draft-rampalli-pedigree-01, July 2026, . [I-D.rampalli-scitt-capsule-provenance-binding] Rampalli, K., "Binding Delegation Authorization and Provenance References into SCITT Agent Action Capsules", Work in Progress, Internet-Draft, draft-rampalli-scitt- capsule-provenance-binding-00, July 2026, . [I-D.reece-wimse-cross-org-delegation] Reece, M., "Requirements for Cross-Organization Delegation of Authority to AI Agents", Work in Progress, Internet- Draft, draft-reece-wimse-cross-org-delegation-00, June 2026, . Rampalli Expires 7 January 2027 [Page 9] Internet-Draft Layered Delegation Mapping July 2026 [I-D.schrock-ep-action-evidence-graph] Schrock, I., "Action Evidence Graphs and Evidence Policy Replay for High-Risk Agent Actions (EP-AEG)", Work in Progress, Internet-Draft, draft-schrock-ep-action- evidence-graph-00, July 2026, . [I-D.schrock-human-authorization-binding] Schrock, I., "Binding Named-Human Authorization Evidence into Agent-Action Records", Work in Progress, Internet- Draft, draft-schrock-human-authorization-binding-00, July 2026, . [RFC9421] Backman, A., Ed., Richer, J., Ed., and M. Sporny, "HTTP Message Signatures", RFC 9421, DOI 10.17487/RFC9421, February 2024, . Acknowledgments This mapping is a record of a discussion, and the discussion did the work. Morgan Reece framed the requirements and asked for the conditional form. Iman Schrock proposed the two-layer frame, reviewed the EP column of the combined table, and contributed the pre-execution human-authorization input class. Songbo Bu proposed the diagnostically-separate-rows structure and the mapping-table discipline this document keeps itself expressible in. Thanks also to the participants in the WIMSE mailing-list threads in which this mapping developed. Author's Address Karthik Rampalli Glyphzero, Inc. Email: karthik@glyphzerolabs.com Rampalli Expires 7 January 2027 [Page 10]