Summary
draft-zhang-dawn-agent-discovery-framework-01, dated 6 September 2026 and last updated in Datatracker on 7 September, is an active individual Internet-Draft with no formal standing in the IETF standards process.- It proposes a Local Discovery Plane and a Federation Plane. A site gateway filters and redacts local agent metadata, then exports a signed Federation Metadata Record to authenticated peers.
- Revision 01 maps DAWN’s Minimum Discoverable Information into the record. The map includes origin, endpoint, capability, freshness and provenance fields, but no intended audience, onward-distribution permission or export-policy version.
- Daniel Kade proposes a small distribution envelope bound to the record digest. It would preserve the origin’s sharing decision beyond the first peer without pretending to authenticate the agent, score its trustworthiness or authorize its use.
A boundary appears in the architecture
The current Datatracker record describes an active individual submission by Bin Zhang. It has no RFC stream, responsible Area Director or telechat, and no intended RFC status is recorded there. The text calls itself Informational. Its appearance is news about a proposal, not evidence that the IETF has selected an architecture.
That distinction is especially important here because the document speaks of a DAWN working group. The official DAWN page still lists the group in BoF state and says it is not chartered. The IETF 126 minutes record a working-group-forming discussion in which the charter was a starting point rather than consensus. A draft’s vocabulary cannot promote the body that may one day assess it.
Within that boundary, revision 01 offers a clear composition. The Local Discovery Plane collects advertisements inside a site through mechanisms such as mDNS, an agent directory or another local service. A Federation Gateway stands between that local inventory and external domains. It applies an Export Policy Engine, converts selected information into a lightweight Federation Metadata Record, and exchanges those records through the Federation Plane.
The separation is useful. Full Capability Cards remain at the source and are fetched on demand by authenticated unicast. The federation carries a thinner index. A site can withhold an agent, redact fields and send different subsets to different peers. This is the draft’s central data-sovereignty control: the operator decides what leaves the administrative domain.
Revision 01 makes the record inspectable
The official comparison with revision 00 adds an explicit bridge from the DAWN Minimum Discoverable Information model to the Federation Metadata Record. The change matters because policy arguments can now be tested against a named set of fields rather than an abstract packet.
The map covers an entity identifier and type, an optional reachable endpoint, capability tags and a Capability Card reference. It includes an authentication hint, trust reference, publication time and TTL, provenance, an origin-gateway identifier and a record flag. A Geographic-Hint is described as an approximate binding for an MDI Scope Hint. Unknown extensions are to be ignored so the format can evolve.
That is enough to answer several questions. A recipient can know which gateway signed the record. It can decide whether the record is fresh. It can locate richer material without flooding the federation with a full Capability Card. It can preserve provenance when information crosses a domain boundary.
The same table does not answer a different question: who is allowed to receive the record after the first export? There is no authorized-audience set, confidentiality class, redistribution flag, maximum propagation path, export-policy identifier or policy epoch. The geographic hint says roughly where something belongs; it is not an access-control instruction. TTL says when a record becomes stale; it does not say where the record may travel before then.
This is not a contradiction in the first hop. Gateway A can decide that Gateway B receives a sanitized record while Gateway C does not. The draft explicitly allows different peers to receive different subsets. The policy engine has done its job at A’s boundary. The missing state appears when B has learned a valid record and participates in another dissemination relationship.
A signature preserves origin, not audience
The security model requires every outgoing FMR to be signed by its originating gateway. A receiver verifies the signature and discards records that fail. That protects the record’s integrity and stops one participant from impersonating another origin gateway. The draft is also candid about the limit: an admitted malicious gateway may still invent claims about its own local agents. Federation admission remains an out-of-band administrative decision.
An origin signature does not, by itself, carry the origin’s disclosure decision. If B forwards A’s unchanged signed record to D, D can verify that A created the bytes. D cannot infer from that proof whether A authorized B to disclose them to D. Cryptographic validity and distribution authority are separate propositions.
The structured peering model can keep them aligned through local configuration. Its appendix describes per-peer export and import policies. Operators with a small, closed membership can make every bilateral rule explicit, constrain route reflection and investigate a leak through known sessions.
The gossip model trades that precision for scale and resilience. Each gateway exchanges a digest of its federated directory with a small set of neighbours, then sends missing or updated records. The draft itself lists “precise per-record distribution policies” as difficult to enforce in this model. The same pressure returns in a mixed federation, where a bridge may carry a common FMR between structured and gossip overlays. Keeping the payload transport-independent improves interoperability, but it also means a restriction known only to one transport or one gateway may be lost at the bridge.
The problem is therefore not that gossip is ungovernable. It is that the current record lets downstream systems verify more about where the information began than about the terms under which it continues.
Bind the sharing decision to the record
A proportionate repair would leave the FMR thin and attach a compact distribution-envelope to its digest. The envelope would identify the origin gateway, exact record hash, export-policy identifier and policy epoch. It would state an audience class or named federation segment, then choose an onward-distribution state: no redistribution, one named next hop, or circulation within a bounded segment.
It should also include expiry and a withdrawal or revocation pointer. A short export-decision receipt identifier would let the origin reconcile what its policy engine released without exposing the private rule set. In a mixed-protocol bridge, an optional previous-hop receipt could show which component accepted responsibility for preserving the boundary.
This need not reveal a confidential access-control list to every recipient. A federation can use opaque segment identifiers or policy capabilities understood only by admitted gateways. Nor must the envelope sit inside the base FMR. It can be an associated signed object, provided the binding to exact record bytes survives forwarding and translation.
Enforcement still requires local policy. A dishonest peer can copy data outside the protocol, just as it can violate a contract today. The gain is narrower but real: compliant software can refuse unauthorized re-export, logs can show which rule was evaluated, and an auditor can distinguish a permitted path from a merely authentic record.
The envelope must not accumulate every unresolved DAWN problem. Stable identifier issuance, comprehensive trust evaluation, capability negotiation, open-Internet indexing and business governance are outside the framework’s declared scope. A distribution boundary should not become a universal identity credential or a trust score. It says who may receive this metadata under this policy, not whether the named agent is safe, competent or authorized to act.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

