Summary
- The proposed Agentproto charter defines dialog context as identifiers and lifecycle state used to correlate and maintain a user-to-agent, agent-to-agent or agent-to-tool dialog; it explicitly excludes prompts, retrieved documents and model conversation memory.
- Continuity across intermediaries and interruptions is a useful receipt for one declared interaction graph, but it does not by itself authenticate every participant, carry delegated authority or prove tool execution and task completion.
- Operators need linked but distinct records for correlation, identity, authorization, content provenance, application semantics, action, confirmation, revocation and observed result.
One thread, several claims
An assistant begins a request on a phone, hands it to another agent, invokes a tool through an intermediary and resumes after the network changes. Without a stable way to say that these legs belong to one dialog, the system cannot reliably reconnect state, suppress a replay or explain which interruption preceded a later action. A persistent dialog identifier solves a real coordination problem.
It does not solve the adjacent trust problems merely by surviving them.
The Agent Communication Protocols proposed charter draws that line unusually clearly. Dialog context consists of the identifiers and lifecycle state needed to correlate and maintain an agentic dialog. It excludes content exchanged with AI models, including conversation memory, retrieved documents and prompts. The proposed protocol would define identifiers, lifecycle semantics and propagation over existing IETF transports. It would not replace application-layer protocols such as MCP or A2A, and it would not prescribe the application's structure or exchanged content.
That produces a bounded evidentiary statement: these interactions were presented as part of one dialog, in this order and lifecycle state. It cannot establish that every linked message was truthful, that an agent still possessed authority inherited earlier in the chain or that the real-world work represented by the dialog occurred.
Correlation is not authentication
The charter itself treats agent identity and represented-user identity as separate subjects. An agent may need to be authenticated independently, granted only a subset of a user's permissions and revoked without revoking the user. Those requirements would be unnecessary if a dialog identifier already carried reliable identity and authorization.
Consider a purchasing agent that resumes a dialog after a hand-off. The same identifier may correctly reconnect the negotiation history. The receiving service must still verify which agent is now present, which organization it represents, whether the user's delegation covers this supplier and amount, whether the credential is fresh and whether a later revocation has propagated. Continuity can preserve the question; it cannot supply all the answers.
The distinction grows more important across intermediaries. One intermediary may repackage a request, another may translate modality, and a third may call a tool. A coherent identifier allows an auditor to traverse the declared path. It does not guarantee that the intermediaries interpreted the same instruction, preserved the same constraints or refrained from adding an unauthorized step.
A lifecycle state is not a business result
The proposed lifecycle includes establishment, modification, termination and revocation of propagation relationships, with recovery from path and intermediary failures. Those states describe the dialog mechanism. They are not a universal business transaction state machine.
established cannot mean that the user has approved every later action. terminated cannot mean that a payment was reversed or that a cloud change was rolled back. A propagation relationship marked revoked does not prove that a queued tool call, cached credential or downstream subscriber stopped accepting the old authority. Each assertion needs evidence from the system that owns it.
The same applies to completion. A tool can return a syntactically successful response while the intended resource remains unchanged. An agent can compose a final answer before an asynchronous job fails. A delivery workflow can maintain perfect dialog continuity while sending the parcel to the wrong address. The last dialog event is evidence about the interaction record, not an oracle for the world.
Build a chain of receipts, not one overloaded identifier
A defensible record should link several objects without collapsing them. The correlation receipt names the dialog identifier, issuer, namespace, creation time, predecessor, lifecycle transition and participating hop. The identity receipt names the authenticated agent and represented user. The delegation receipt states scope, constraints, freshness and revocation reference. The content receipt preserves hashes or provenance for the instruction and retrieved material when policy allows. The application record defines the request semantics. The tool receipt records the operation, target, parameters and response.
User confirmation carries the exact decision presented. Finally, an outcome receipt observes the relevant external state.
The links matter as much as the separation. If a tool receipt cannot point back to the exact authorization and dialog step that caused it, investigation becomes guesswork. If all evidence is compressed into a single opaque correlation ID, the system can produce a tidy trace that proves almost nothing beyond internal consistency.
Persistent identifiers also create privacy exposure. The charter therefore calls for analysis and mitigation when identifiers cross intermediaries and trust boundaries. A globally stable label can become a cross-service tracking handle. Namespace, audience, rotation, minimization and retention are not secondary implementation details; they determine whether continuity becomes surveillance.
Governance is still open
On 17 September, the IESG review notice described Agentproto as a proposed working group, said the IESG had made no determination and invited comments through 27 September. Datatracker lists charter version 00-03 in external review and on the 8 October IESG telechat agenda. There is no chartered working group, adopted protocol draft, approved standard or deployment to report.
That uncertainty strengthens the useful design question. Before a wire format hardens, reviewers can insist that correlation metadata remain visibly distinct from identity, authorization and result evidence. The standard can make continuity interoperable without allowing an identifier to become an all-purpose badge of trust.
Sources
Primary records: the IESG WG review announcement, the current Agentproto proposed charter 00-03 and the Agentproto Datatracker group page.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

