Summary

  • draft-vandemeent-ains-discovery-02 makes a useful retreat from its earlier abstraction: it removes portable scalar trust from the normative path and says federation should copy typed evidence and route posture, while each consumer computes its own local evaluation.
  • Signed mutation logs and optional Merkle proofs can establish who recorded what, in which order and without a silent rewrite. They cannot prove legitimate name ownership, capability truth, present suitability, admission or authority.

The most important feature of a proposed agent naming system may be the judgment it refuses to centralise. AINS describes a logical namespace, HTTPS lookup, capability metadata, evidence references and signed federation for autonomous agents, services, devices and human-operated endpoints. Its second revision, published on 24 September, also draws a boundary that procurement teams should treat as the heart of the proposal: evidence can travel; a verdict should not.

This is an individual Informational Internet-Draft. It has no working group, IETF consensus or RFC standing, and no reviewed source proves a production deployment. Its value today lies in the questions it makes testable, not in authority conferred by publication.

The revision history matters. Version -02 removes trust_score and min_trust from the normative path, recasts old numeric values as local compatibility output, and splits the former trust model into three different objects. Evidence is a portable proof or reference. Route posture says what an observer learned about reachability, provider role, freshness or coverage. Local evaluation applies a named consumer policy to those inputs for one interaction.

The three are not synonyms. A receipt may prove that an endpoint answered at a stated time without establishing who controls it now. A signed account challenge may prove control of that account without proving durable identity or organisational mandate. A route observation may show reachability without granting permission to use the route. A registry can preserve all three facts and still lack the context to admit a consequential request.

AINS proposes that each origin registry sign an append-only stream of record mutations. Replicas pull entries, verify the origin signature, enforce monotonic sequence numbers and keep provenance intact. Optional Merkle inclusion proofs let auditors test whether a mutation belongs to a committed history and whether the history was rewritten.

That is valuable custody evidence. It answers “did this registry record this object?” and “did a peer alter it?” It does not answer “was the claim true?” Certificate Transparency offers the same caution in a mature setting: inclusion and consistency proofs make log behaviour inspectable; they do not make every submitted certificate or underlying assertion legitimate. HTTP Message Signatures add another useful limit. Verification succeeds only after an application has decided that the key, algorithm, covered components, freshness and replay controls are appropriate. Mathematics binds bytes to a key. Policy decides what that binding means here.

The proposed conflict rule exposes the difference. If two origin registries claim the same AINS name, a replica keeps the record with the earliest registration timestamp, records a security event and refuses silent overwrite. That produces deterministic convergence. It does not adjudicate ownership. A squatter can be early too. The draft itself leaves cross-registry reservation to future work.

An operator should therefore retain both conflicting claims and the reason one became the active projection. “Earliest” is a resolver rule, not evidence that the earliest claimant was authorised by the person or organisation whose name it resembles. If a user interface turns the winner into a green verified badge, it launders a mechanical tie-break into institutional standing.

The draft's multi-channel verification deserves similar precision. A claimant receives a fresh nonce and publishes it through an external account or domain. Yet the procedure requires control of at least one channel. One is not multiple, and control of a social account, repository or DNS record is narrower than durable identity. More channels can raise assurance under a local policy; none grants permission for a later action.

This is why the sentence “federation replicates evidence, not conclusions” is more important than the namespace suffix. The same entity can receive different evaluations at a financial institution and a social service even when both parties hold identical records. That divergence is not fragmentation if each decision exposes its policy version, evidence set, freshness point and scope. It is local responsibility.

There is also a correction to make around competitive claims. The draft's informative comparison table says A2A lacks cryptographic verification. The current official A2A specification permits JWS-signed Agent Cards, defines canonicalisation rules and advises clients to verify a signature before trusting a card. AINS may still offer a different federation and evidence model, but it cannot establish necessity by freezing neighbouring protocols in an older form. A comparison table is an author's map, not independent evidence.

The remaining architecture contains its own pressure toward standing. Records carry tiers such as core, verified, sandbox and reserved. An origin registry owns its records. Companion references come from the same protocol suite. None of those labels must become authority according to the new text, yet applications may treat them as shortcuts. The decisive implementation test is whether a consumer can ignore a tier, reject the registry's evaluation, verify the underlying evidence independently and still interoperate.

Privacy creates a second test. Publicly resolvable records can expose endpoints, capabilities, route posture and operational-history references. Replication enlarges the audience and reduces the origin's power to withdraw information. A tombstone can prove that deletion was requested without erasing copies already exported. Selective disclosure, reference rather than duplication, cache expiry, replica discovery and retention limits therefore belong in the design before a human or commercially sensitive agent is listed.

Lu Heng's thin-coordination principle clarifies the acceptable common layer. Stable identifier syntax, deterministic validation, signed origin, portable evidence format and visible conflicts can be shared. Suitability, risk tolerance, business permission and adoption remain local unless a stated global invariant demands uniformity. A registry describes adopted reality; it does not create authority by recording a name.

For leadership, the practical artifact is a six-part decision record. Preserve the exact discovery response and origin signature; the log position and freshness; independently checked evidence objects; the route observation and its blind spots; the local policy version and result; and the later admission, execution and outcome evidence. If a dashboard compresses those stages into one trust number, revision -02's best idea has already been lost.

Sources