Summary
- Steven Mih's
draft-mih-agent-evidence-request-00, dated 26 September, is an individual Informational Internet-Draft, not an IETF-adopted standard or evidence of a running service. - For a fixed subject, resolved coverage anchor and requested derivation, the proposal calls for byte-identical evidence artifacts for every requester. An independently held
expected_pinis a stronger comparison point than a freshness threshold whose anchor the responder chooses. - The rule does not force disclosure. A responder can issue a signed refusal; a missing answer becomes a recorded absence only after a waiting window. Neither outcome proves that a hidden event occurred or that an available artifact is complete.
Imagine two auditors asking for the same agent-action history against a checkpoint they both saved before a dispute. One is sent a clean-looking extract, the other a less flattering one. Both extracts may be individually well formed. The important question is whether their bytes are the same. This is a hypothetical test, not a reported incident. It exposes the narrow but consequential property in Steven Mih's new proposal for requesting verifiable evidence: an answer cannot be tailored to its audience while still claiming to answer the same pinned question.
The document, dated 26 September 2026, is an active individual Internet-Draft with intended Informational status. The IETF Datatracker lists it as “Individual” and “I-D Exists.” That is publication of a work-in-progress proposal, not working-group adoption, consensus, deployment or a new right to demand records. Its target is the shape of an evidence request, not a universal format for evidence itself.
A request identifies a subject and a coverage boundary. The subject may be a full history, checkpoints, a record, a range, a correlation or an exchange. Coverage must use exactly one of two forms. With expected_pin, the requester supplies a checkpoint held independently of the responder's latest answer. With min_freshness, the requester states a threshold and the responder resolves it to a qualifying anchor. The first form allows two parties to ask a genuinely comparable anchored question. The second can still be useful, but if two responders choose different qualifying anchors, a byte difference alone is not proof that either broke the rule.
The caller-invariance test is precise: hold subject, resolved coverage anchor and any derivation constant; the resulting artifact bytes must be identical across requesters and channels. Identity, privilege or transport may govern whether the responder answers, but not the artifact bytes it supplies when it does answer that fixed query. This is a proposed interoperability and accountability rule. It does not say that all audiences must receive the artifact.
Even identical answers are only a local test. The draft requires served anchors for one stream to belong to a mutually consistent append-only history. A producer that shows one audience one branch and another audience a different branch may never be caught by comparing artifacts under different pins. An auditor therefore needs the pins, consistency proofs and, where possible, independent comparison or witnessing. A responder-selected “fresh” point cannot be treated as a neutral snapshot merely because its timestamp is recent.
Nor does a valid artifact prove that the underlying log contains every real-world action; an omitted event can leave a consistent but incomplete history.
The proposal separates an artifact from two other terminal outcomes. A signed refusal binds the digest of the request, a time and a machine-readable reason to a responder signature. Reasons include lack of authorization, unsatisfied coverage, unsupported derivation and policy refusal; a responder may choose a less revealing policy reason to avoid disclosing whether a subject exists. By contrast, recorded absence is the requester's account that a waiting window passed without a terminal answer. It is not a signed refusal and, by itself, says nothing about why the answer failed to arrive.
An optional signed retention commitment can make a later absence attributable to a party during its promised period, but cannot guarantee that a network path will stay available.
These distinctions keep an audit honest. The draft does not define the evidence format, principal identity system, access policy, trust verdict or a rule about who may ask. A history_card/1 derivation may show checkpoint progression without record contents, yet cadence and size can reveal operational patterns; low-entropy digests can also expose more than intended. The governance question is therefore not whether a hash makes evidence “open.” It is whether an auditor can preserve the independent anchor, test a supplied answer for audience-specific tailoring, and record refusals and silence without silently converting either into proof of misconduct.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

