Summary
draft-dogru-cedulon-decision-profile-02, dated 5 September 2026, remains an active individual Internet-Draft with no IETF endorsement or formal standing, no RFC stream and no Responsible Area Director.- The profile reconciles signed Decision Records against authenticated Effect Extract rows. An allow expects one matching effect; a denial or deferral expects none.
- Revision 02 explicitly says the binding does not order the two clocks. A row's timestamp is checked against its declared window, not against the timestamp of the Decision Record it answers.
effect-against-refusaltherefore establishes that a refusal and an effect with the same reference coexist in the audited population. It does not by itself prove that the effect occurred after the refusal or identify where a control path failed.- A separate sequence receipt should name both clock authorities, allowed skew and supporting order evidence, then report
before,after,within-skeworindeterminatewithout rewriting the population finding.
A mismatch is not yet a timeline
The current Datatracker record is institutionally modest. It identifies Cedulon Decision Profile: Reconciling an Agent's Decisions Against Its Effects as revision 02 of an active individual Internet-Draft by Emek Can Doğru, updated on 5 September. Datatracker also supplies the necessary warning: anyone may submit an I-D; this document has no IETF endorsement or formal standing. No RFC stream, Responsible Area Director or telechat date is recorded. The IESG state is only “I-D Exists.”
Within that boundary, the draft asks a precise operational question. A Decider signs a Decision Record saying whether an agent may act. A channel, or a capture process representing it, supplies an authenticated Effect Extract of what occurred. The verifier closes the two populations over one Decider, one channel and one time window.
The expected cardinality is simple. An allow should have exactly one effect under the same reference, with the content hash and effect class that were authorized. An allow with no effect becomes decision-without-effect. An effect with no decision becomes effect-without-decision. A denial or deferral is a refusal and expects no effect; a row under its reference becomes effect-against-refusal.
Those findings are valuable. They turn “the agent disobeyed” from a vague accusation into a reproducible comparison between two declared populations. But one phrase in the draft's explanation—“a refusal that was followed by the effect it refused”—invites a stronger temporal reading than the algorithm supplies. Revision 02 corrects that impression elsewhere by stating exactly what the binding does not measure.
Revision 02 names the missing comparison
Section 6.1 of the frozen revision says a row and an allow bind through their reference, content hash and effect class. For a refusal, the shared reference is enough to produce the prohibited-row finding. Then the text draws a bright line: the binding does not order the two clocks.
Each effect row contains timestampMs. Each Decision Record does too. Yet the row's time is tested only against the window declared by the Effect Extract. It is not compared with the time of the Decision Record it answers. As the draft puts the consequence, a row dated before the record still binds as though it had followed it. The current profile compares content and reference, not sequence. Revision 02 names no temporal finding, although it says a deployment that needs order may compare the stamps within the same allowance and a later revision may add one.
This candour strengthens the document. Specifications often become dangerous when a natural-language story acquires more force than the executable rule. Here the boundary is inspectable: the algorithm answers whether the populations reconcile under their references and counts; it does not answer whether a refusal was already operative when an effect occurred.
That distinction changes the incident narrative. Suppose the effect row says 10:00 and the refusal record says 10:01, both inside the same audited window. The current profile can still report effect-against-refusal. It cannot distinguish at least four possibilities: the effect really preceded the refusal; one clock was fast; the refusal was recorded after a decision made earlier; or either timestamp was assigned later by a capture process. The mismatch may be real while its chronology remains unresolved.
A window proves admission, not relative order
The profile is not indifferent to time. An Effect Extract declares [windowStartMs, windowEndMs), and every row must fall inside it. A single out-of-window row makes the extract malformed. The inherited boundary rule also defers or carries unmatched items close to a window edge. The companion implementation applies a default five-minute allowance.
These controls answer different questions. Window membership says which rows belong in this audit. Boundary handling limits false gaps when activity straddles two adjacent extracts. Neither test says that the Decision Record's clock and the effect row's clock have the same authority, accuracy or synchronization. A five-minute allowance around an extract boundary is not automatically a five-minute proof of causal order inside the window.
The difference matters because wall-clock values can look more authoritative than they are. A timestamp signed by the Decider proves that the signed record contains that number. A timestamp inside an authenticated channel export proves that the export contains another number. Those signatures do not necessarily prove when the signer first knew the event, whether its clock was disciplined, whether the capture process backfilled an entry, or whether the two clock domains were comparable.
Cedulon's trust section makes the wider version of this point. The profile has a root for the Decider and another for the Effect Extract, but the relationship between them is only as strong as their operational independence. Where the deployment itself captures a platform log, its assurance is conditional on that capture process genuinely being distinct from the Decider. Cryptography can bind each statement to a key. It cannot manufacture the independence or chronology that operations did not provide.
Keep the population finding narrow
The right response is not to discard effect-against-refusal. It is a useful name for a conservation failure: the audited effect population contains a row under a reference whose decision population says denial or deferral. The draft also correctly warns that this finding does not locate the failure. The problem may lie in control delivery, enforcement, a bypass, an unrelated route or the evidentiary path itself.
Temporal language should be just as disciplined. If no order comparison ran, the public report should say “effect present against a refusal reference,” not “agent acted after being refused.” The second sentence asserts a sequence and usually suggests a failed pre-action control. That implication can affect incident escalation, vendor liability, employee discipline and the design of automated containment. It needs more than a matching key.
Heng Lu's right to accurate records offers a useful editorial restraint: a record describes reality; it does not create it. Applied here, the signed records describe decisions, effects and the comparisons actually made. Their reconciliation cannot create an ordering fact omitted from the algorithm. This is not an IETF rule or a demand that Cedulon adopt registry doctrine. It is a reason to keep the report no broader than its measurement.
What a sequence receipt would add
A temporal extension should sit beside the existing population result, not alter it. The same pair might legitimately report both effect-against-refusal and sequence-indeterminate. One says the populations conflict under a reference. The other says the available evidence cannot establish which event came first.
The receipt needs a little more than subtraction between two integers. It should identify the exact Decision Record and effect row, preferably by signed-byte digest. For each timestamp it should name the clock source, the party controlling it, how the value entered the record, and whether the evidence was committed before the audit. It should record the permitted skew and the policy or measurement that selected it.
The result can then stay small:
before: the evidence places the effect before the refusal outside the permitted uncertainty interval;after: the evidence places the effect after the refusal outside that interval;within-skew: the numerical order exists, but the gap is too small to survive the stated uncertainty;indeterminate: the clock provenance, synchronization or evidence is insufficient for comparison.
Where available, a monotonic counter, append-only event sequence, trusted timestamp, checkpoint or independent observation may strengthen the result. Each aid needs its own authority and failure model. A monotonic sequence maintained by the same Decider is useful against accidental reordering but not automatically against a dishonest Decider. A channel-assigned sequence can establish order on that channel without proving when the policy decision became effective. An external timestamp can show that data existed no later than a time, not necessarily when the underlying action occurred.
Most importantly, the receipt should keep order and causation separate. “After” can establish temporal precedence under stated assumptions. It still does not prove that the refusal caused the effect, that the agent received the control, or that enforcement was possible. Those belong to the delivery and enforcement evidence the draft itself places outside this profile.
Running code makes the boundary testable
The draft's Implementation Status section, framed under RFC 7942, says the author-owned companion repository carries 20 conformance cases and four offline fixtures. It reports release 0.13.0 and several review or reproduction steps. It is equally clear about the limits: revision 02 changes text and adds no case; the ordering of the two clocks is stated, not enforced. The record reports no measured live channel log, no known independent implementation and no temporal precommitment for the public fixtures.
That is the right evidence posture. The repository shows that the profile has code rather than only aspirations, while also saying that its ordinary demonstrations use mocks and do not touch real wallets or payment rails. It remains author-controlled evidence, not independent interoperability. RFC 7942 gives implementation status a bounded role: help reviewers understand maturity and feedback, without turning code into IETF approval.
A sequence test would make the next claim falsifiable. Fixtures should include a row clearly before its record, one clearly after, two within tolerance, incomparable clock authorities, backfilled timestamps and conflicting monotonic evidence. A verifier should never collapse the last three into a confident after. The useful implementation milestone is not simply a new finding code; it is a test demonstrating that uncertainty survives the reporting path.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

