Summary
- The 27 September Datatracker update is an individual Internet-Draft, not an adopted WIMSE specification, RFC or deployment report.
- Revision 01 gives an in-scope write that cannot be assigned to a request an
unknowneffect; a permit with no effect isnot-exercised, not thedisagreeresult reserved for a denial followed by an attributed effect.
Imagine a reviewer checking whether an AI agent obeyed a denial. The log shows a write to the watched path, but the observer cannot tie that write to the denied request. Calling the denial successful would assume the write was someone else's. Calling it breached would assume it was the agent's. The record needs to retain the gap rather than choose a culprit.
That is the consequential change between versions 00 and 01 of Sankalp Gilda's draft-gilda-wimse-agent-audit-record. Both versions propose an in-toto predicate signed in a DSSE envelope for agent authorization audits. The new version does not invent that container. It changes what the container is allowed to conclude from the evidence inside it. Datatracker lists the 01 revision as an active individual draft, last updated on 27 September, with IESG state I-D Exists and no RFC stream.
The earlier text offered a binary observed effect, occurred or none. Its agreement table also treated a permitted request with no observed effect as disagree—the same label used when a denied request produced a write. Those are not equivalent failures. Permission allows an action; it does not compel an agent to act. A denial followed by a write attributable to that request raises a different control question.
Version 01 makes each write carry the digest of the request to which the observer attributes it, or the literal unattributed. Its effect.observed is then derived for the request named by this record, not for every operation in the time interval. A write tied to another request cannot turn this request's effect into occurred. If no write is attributed to the request but an unattributed write lies inside the declared path scope, the effect becomes unknown, not none. The same proposal maps permit plus no effect to not-exercised, any decision plus unknown to indeterminate, and deny plus an attributed effect to disagree.
There is a separate byte-level repair. When a tool's arguments cannot be bound by digest, 01 requires the argumentsDigest member to be absent—neither null nor an empty string—and removes it from the request-digest preimage. Otherwise two conforming readers could hash the same unbindable call differently and fail to join their records. New conformance vectors test that absence as well as another request's write, an unattributed write and an unused permit.
These are rules inside a proposed format. A signature can show that bytes were signed, and internal recomputation can expose certain inconsistent claims. Neither proves that the producer saw every write, attributed it honestly or actually occupied the independent observation vantage it claims. The draft defines no policy for accepting a record or for deciding an incident. Its indeterminate state identifies a limit of observation, not evidence of an attack.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

