Summary

  • The 27 September Datatracker update is an individual Internet-Draft, not an adopted WIMSE specification, RFC or deployment report.
  • Revision 01 gives an in-scope write that cannot be assigned to a request an unknown effect; a permit with no effect is not-exercised, not the disagree result reserved for a denial followed by an attributed effect.

Imagine a reviewer checking whether an AI agent obeyed a denial. The log shows a write to the watched path, but the observer cannot tie that write to the denied request. Calling the denial successful would assume the write was someone else's. Calling it breached would assume it was the agent's. The record needs to retain the gap rather than choose a culprit.

That is the consequential change between versions 00 and 01 of Sankalp Gilda's draft-gilda-wimse-agent-audit-record. Both versions propose an in-toto predicate signed in a DSSE envelope for agent authorization audits. The new version does not invent that container. It changes what the container is allowed to conclude from the evidence inside it. Datatracker lists the 01 revision as an active individual draft, last updated on 27 September, with IESG state I-D Exists and no RFC stream.

The earlier text offered a binary observed effect, occurred or none. Its agreement table also treated a permitted request with no observed effect as disagree—the same label used when a denied request produced a write. Those are not equivalent failures. Permission allows an action; it does not compel an agent to act. A denial followed by a write attributable to that request raises a different control question.

Version 01 makes each write carry the digest of the request to which the observer attributes it, or the literal unattributed. Its effect.observed is then derived for the request named by this record, not for every operation in the time interval. A write tied to another request cannot turn this request's effect into occurred. If no write is attributed to the request but an unattributed write lies inside the declared path scope, the effect becomes unknown, not none. The same proposal maps permit plus no effect to not-exercised, any decision plus unknown to indeterminate, and deny plus an attributed effect to disagree.

There is a separate byte-level repair. When a tool's arguments cannot be bound by digest, 01 requires the argumentsDigest member to be absent—neither null nor an empty string—and removes it from the request-digest preimage. Otherwise two conforming readers could hash the same unbindable call differently and fail to join their records. New conformance vectors test that absence as well as another request's write, an unattributed write and an unused permit.

These are rules inside a proposed format. A signature can show that bytes were signed, and internal recomputation can expose certain inconsistent claims. Neither proves that the producer saw every write, attributed it honestly or actually occupied the independent observation vantage it claims. The draft defines no policy for accepting a record or for deciding an incident. Its indeterminate state identifies a limit of observation, not evidence of an attack.

Sources