Summary
- Steven Mih's first individual Disclosure Envelope Internet-Draft was announced on 27 September. It is a proposal without IETF endorsement, not an adopted audit standard or evidence of deployment.
- The proposed wrapper may reveal the raw agent input or output committed only as a digest in a signed Agent Action Capsule. The Capsule remains unchanged; a verifier must recompute each disclosed value's digest and report that result separately from verification of the Capsule.
- A matching digest links a disclosed value to a prior commitment. It does not certify the content's truth or protect the cleartext once the envelope reaches a recipient.
Two investigators receive the same signed record of an agent action. One sees only a digest for the agent's input. The other receives a separate package containing a purported copy of that input. Their view of the original record can be identical while their access to the underlying material differs. This is a hypothetical illustration, not a description of a deployed service. It captures the problem addressed by draft-mih-agent-disclosure-envelope-00, announced on 27 September: how to reveal what was previously committed without editing the signed object that carries the commitment.
Steven Mih's document is an active individual Internet-Draft. The IETF Datatracker says explicitly that such a submission is not endorsed by the IETF and has no formal standing in its standards process. The draft is a companion to the author's proposed Agent Action Capsule profile. In that base design, agent_input_digest and agent_output_digest contain SHA-256 commitments to JSON values canonicalized under RFC 8785. The raw input and output are not in those digest-only fields. No later disclosure can honestly be described as having been present in the signed record all along.
The proposed Disclosure Envelope puts an unmodified Capsule in one member and optional raw values in a sibling disclosures member. Initially the eligible values are agent_input and agent_output. If either is omitted, the draft calls it withheld; omission is not a failed verification or evidence that the input never existed. The envelope is a presentation structure, not the signed statement submitted for SCITT registration. Its disclosure values are added afterward and are not themselves covered by the Capsule signature. Keeping them outside the signed object preserves the same capsule_id for recipients who see different optional disclosures.
That separation gives a verifier two different jobs. It must verify the original Capsule on its own terms. Then, for each revealed value, it must recompute the SHA-256 digest of the entire RFC 8785-canonicalized JSON value and compare it with the digest already committed in the Capsule. The draft separates a match, mismatch, ineligible member and missing or malformed committed digest. It expressly says that a matching reveal must not upgrade a failing Capsule, and a valid Capsule must not be displayed as confirmation of a reveal that has not been recomputed.
A viewer that merely renders the supplied text and labels it verified would be promoting an unsigned assertion into apparent evidence.
This is not the same as the companion selective-disclosure proposal. That profile hides a field that otherwise would appear in the signed payload. Here the relevant fields were digest-only from the outset. A later wrapper supplies a preimage to the verifier; it does not reconstruct or rewrite the payload. The distinction matters because the trust claim is precise: the newly shown value matches an earlier commitment, provided the base record itself is valid and the recomputation succeeds.
A matching hash does not establish that the agent was given the right instructions, that its output was accurate, or that disclosing either one was authorized.
The privacy boundary is just as sharp. With no envelope, a recipient sees the digest but not the raw value. Once an envelope includes an input or output, anyone who receives that envelope can read the cleartext. The draft provides no per-recipient encryption, onward-sharing control or general rule for deciding who may ask. A producer could construct different envelopes for different verifiers, but the choice and safe delivery of each one remain outside the digest check. That is Daniel Kade's governance inference from the proposal, not a claim of misconduct or a newly binding IETF policy.
The older signed record can stay fixed while the disclosure decision changes what different people know.
Sources
- https://mailarchive.ietf.org/arch/msg/i-d-announce/WUZQnVSWjF1WFQiRgPxLgWDFAHE/
- https://datatracker.ietf.org/doc/draft-mih-agent-disclosure-envelope/
- https://www.ietf.org/archive/id/draft-mih-agent-disclosure-envelope-00.html
- https://datatracker.ietf.org/doc/html/draft-mih-scitt-agent-action-capsule-05
- https://www.rfc-editor.org/rfc/rfc8785.html
- https://www.rfc-editor.org/rfc/rfc9943.html
- https://heng.lu/on-why-btw-media-exists-and-why-reality-not-advocacy-is-the-product/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

