Summary
- Andreas Ehstand’s first individual Internet-Draft on human oversight acts was announced on 27 September. It proposes terminology, not an IETF standard, audit format, protocol or mandatory process.
- Its four named acts are not interchangeable: observation shows at most that an object was presented; a check concerns one named property; a decision selects a course; a release permits a specified action within authority held beforehand.
- An undifferentiated approval proves an interaction was recorded. To support both “the output was checked” and “the action was permitted,” a consumer needs evidence of a check and a release, not a more emphatic approval button.
Imagine a human reviewer seeing an agent-generated payment on a screen. The screen is closed, an “approved” flag appears and the payment leaves the queue. That sequence is hypothetical, but the evidentiary problem is real: the flag alone does not say whether the reviewer saw the invoice, checked the recipient against a named rule, chose a disposition or held authority to release that amount. An audit trail can be authentic and still answer the wrong question.
That is the issue taken up by draft-ehstand-oversight-acts-00, announced on 27 September. Its author, Andreas Ehstand, names observation, check, decision and release as distinct oversight acts. Release is a particular decision made under standing authority, not simply a stronger version of clicking “yes.” The Datatracker labels the text an active individual Internet-Draft and warns that it is not endorsed by the IETF or part of the formal standards process. The document itself specifies no protocol, data format, procedure or measurement method. It should not be reported as a newly imposed control.
The distinctions narrow what a record can establish. Observation means that an object was presented to an overseer; it does not prove comprehension. A check asks whether a named property of that object holds and has an outcome: yes, no or could not determine. It says nothing about all the other properties not checked. A decision records which course was chosen and by whom, but a decision may occur without a check. A release permits a specified action or class of actions; the record supports a claim of authority only as far as it identifies the pre-existing standing authority relied on. Permission is not a finding that the action was correct.
The draft’s table makes the gap particularly stark. If a relying party needs to know that a payment was both within an authorized release and examined for a particular condition, one record of each kind is needed. Two releases do not become a check. A row labelled “approval” does not acquire those meanings through a signature or retention period. Cryptographic verification may establish who issued a record; it cannot change which human act the record describes.
The W3C Verifiable Credentials model likewise distinguishes verification from validation against a use case, but this draft’s four-act taxonomy is a separate proposal, not a new W3C rule.
Ehstand also gives a name to a harder failure: a fail-open check step. If closing a review screen writes the same “checked” record whether the named property was actually examined or not, normal logs cannot reveal the missed check. The draft calls for thinking in terms of error detectability and check tests, while expressly leaving the test method and acceptable result unspecified. It warns of rubber-stamping, falsely inflated act labels, substitution of the object after review and releases outside their intended scope.
Its privacy section adds a counterweight: logging screen time can surveil the reviewer while proving little about the object.
For governance, the useful question is therefore not “Was a human in the loop?” It is “Which human act is the evidence claiming, against which exact object and property, and under which prior authority?” This is Daniel Kade’s editorial inference from the individual draft, not an IETF requirement or a claim that any deployed agent system has failed. Heng Lu’s broader warning against turning symbolic participation into a mandate is a useful discipline here, but an oversight receipt still has to be judged on its own facts. A human’s presence, a valid signature, a property check and permission to act are four different propositions.
Sources
- https://mailarchive.ietf.org/arch/msg/i-d-announce/47yUg55Pm9vIiHZIJ2NmtVxs8wI/
- https://datatracker.ietf.org/doc/draft-ehstand-oversight-acts/
- https://www.ietf.org/archive/id/draft-ehstand-oversight-acts-00.txt
- https://www.ietf.org/about/open-records/
- https://www.w3.org/TR/vc-data-model-2.0/
- https://heng.lu/on-why-btw-media-exists-and-why-reality-not-advocacy-is-the-product/
- https://heng.lu/the-multi-stakeholder-mirage-how-the-multi-stakeholder-model-turned-attendance-into-mandate/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

