Summary

  • Revision 06 of Raza Sharif’s individual Agent Audit Trail Internet-Draft says a verifier must not declare a presented session complete without a final session_end record, even if every hash-chain check passes.
  • It also replaces the old instruction to retain an erased record’s signature: a signed-chain tombstone needs a new signature from the deleting authority over the tombstone itself.

The investigator verifies every link in an agent’s audit file. No hash mismatch appears. Yet the final action could still have been cut away. The remaining prefix is mathematically consistent because its links never referred to a later record. Calling that file “complete” would confuse integrity of what survived with evidence that nothing followed it.

That is the sharp new rule in version 06 of the Agent Audit Trail proposal, submitted on 29 September. Section 6.3 adds a tenth verification step: when the last presented record is not a session_end close record, completeness must be reported as inconclusive—“tail unverifiable”—even if the preceding nine steps pass. The draft points to a close record, a declared heartbeat cadence or an external anchor as ways to bound the end of a session. It does not claim that an ordinary hash chain can prove the absence of records beyond the last one offered to a reviewer.

The baseline matters. Version 05 already described session-close records and periodic heartbeats. The new event is not the invention of a closing marker; it is a mandatory limit on what the verifier may conclude when that marker is missing. An abnormal termination may have a benign explanation, and the draft discusses synthetic close records after crashes. But a green chain-integrity result cannot silently be promoted into a clean completeness verdict.

Version 06 makes a second, related correction at the point where a record is deliberately removed. The old tombstone clause said to retain the original signature if one existed. That signature covered the original record, not the replacement. The new Section 9.3 instead says that, in a signed chain, the deleting authority signs the tombstone’s own canonical bytes with its own signer_kid. Copying the old signature is expressly forbidden. An unsigned or invalid tombstone fails verification in a signed chain; an unsigned tombstone is acceptable only in an unsigned chain and should be reported. The draft further recommends that an agent’s own key not be allowed to erase the record of that agent’s actions.

These changes expose two distinct control questions at an audit handoff. Who can establish that the account of a session reaches a bounded end? And who is authorized to replace a record while leaving a trace of that replacement? A verifier, retention service and agent operator need not be the same actor. Daniel Kade’s proposed handoff receipt would record the final sequence or close status, the heartbeat or anchor relied on, the verifier’s completeness verdict, and the identity of any deleting authority. That receipt is an editorial operating proposal, not a field prescribed by the draft.

This is an active individual Internet-Draft, not an RFC, IETF-endorsed standard or evidence of a deployed attack. The Datatracker lists no RFC stream and an I-D Exists state. The practical lesson is therefore narrower and more useful: a defensible audit answer must say what was verified, what may still be absent and whose signature authorized a deletion. “All presented hashes passed” answers only the first of those questions.

Sources