Summary

  • draft-jacobs-web4-federation-policy-00 proposes machine-readable, versioned federation policy advertisements covering authority, status, admission, retention, challenge, appeal and revocation.
  • The draft expressly says publication alone does not prove operator behaviour, and that integrity or evidence commitments do not establish truth, legality, completeness or fitness for purpose.
  • It is an individual Internet-Draft intended as Experimental work, not an RFC, IETF-adopted work item, certification scheme or report about a deployed operator.

Suppose a verifier retrieves a policy advertisement from a stable endpoint. The issuer is authentic, the signature is intact, the effective date has arrived and the status service calls the version active. Those checks answer important questions. They do not say whether an applicant received the promised appeal, whether records were erased on schedule, or whether revocation was applied consistently.

That gap is not a defect hidden between the lines of the document. It is a boundary stated by draft-jacobs-web4-federation-policy-00, published on 12 September 2026. The draft defines what a federation should disclose in machine-readable form, then says that publication alone does not prove operator behaviour. This sentence prevents the advertisement from quietly becoming an assurance certificate.

The proposed advertisement identifies a policy, its version, the accountable authority, effective time, supported profiles, recognised formats, a status mechanism and an integrity proof. The underlying policy must describe categories of admission criteria, assurance profiles, evidence retention, challenge and appeal procedures, suspension and revocation, disclosure and minimisation, applicable jurisdiction and supported versions where relevant.

Those fields create a useful public surface. A client can discover what the federation says governs it without scraping prose from a changing website. An auditor can name the exact version claimed for an old decision. A participant can locate the stated challenge channel. The accountable authority is no longer merely inferred from branding or network reachability.

Three claims, not one

The first claim concerns authenticity: did the named issuer produce this exact object, and has it been altered? The integrity proof addresses that question. The second concerns applicability: was this version effective at the decision time, and is its current status active, superseded, withdrawn or unavailable? Stable discovery, temporal checks and retained history address that question.

The third claim concerns performance: did the operator act according to the policy? The advertisement cannot answer it by describing itself. Proof that bytes were committed does not prove that the assertions are true, complete, lawful, properly sourced or fit for the relying party’s purpose. A valid signature authenticates a statement; it does not transform the statement into observed conduct.

The draft reinforces that separation in its security guidance. A relying implementation should authenticate issuers, validate proof integrity and purpose, enforce temporal validity, resolve current status and bind the decision to the exact policy identifier and version. It also names replay, stale status, unauthorised supersession, identifier confusion, key compromise, algorithm downgrade, cross-policy confusion and fail-open handling among the risks.

Versioning is therefore part of the decision evidence. A material semantic change produces a new version, and enough history must remain to identify the policy governing past decisions. Replacing a file in place would deprive a later reviewer of the rule actually presented to the affected party. Marking a policy withdrawn without retaining history would make the present truthful at the cost of making the past unverifiable.

Disclosure without compelled exposure

The proposal does not demand publication of every internal input. Eligibility scores, admission rankings, private risk vectors, internal graph relationships, optimisation, deliberations, routing and control-plane information remain protected. A conforming federation can publish the policy boundary without revealing the model, commercial logic or private graph used inside it.

That protection creates a second governance balance. Too little disclosure leaves participants unable to identify the rule, authority or remedy. Excessive disclosure may expose personal data, security controls or decision models that can be gamed. The draft places a minimum declaration at the boundary and leaves protected internals inside.

Privacy risks do not disappear because the public object is small. Persistent identifiers, proof checks, status queries and linked receipts can correlate parties across interactions. The draft calls for minimisation and recommends unlinkable or pairwise identifiers when they satisfy the policy. Private evidence may be represented through a commitment, but retention and erasure obligations still have to be stated.

The listed appeal and challenge procedures also remain declarations. A URI can be reachable while the remedy behind it is slow, dependent on the original decision-maker or unable to suspend harm. The draft requires the policy to state the procedure; it does not report that a particular procedure is independent, effective or fair.

Status without borrowed authority

Revision 00 is a five-page individual Internet-Draft by Tim Jacobs, dated 12 September 2026 and intended for Experimental publication. Its datatracker state is I-D Exists, and it expires on 16 March 2027 unless updated. It is not a working-group document, an RFC or an IETF endorsement of “Web4” as a standard Internet layer. It requests no IANA action.

The draft refers informatively to wider Web4 architecture work. Those related documents provide terminology and deployment concepts; they do not transfer adoption or approval to the policy draft. BCP 14 keywords express the author’s proposed requirements inside the draft. Their uppercase form is not evidence that the IETF has agreed to them.

Sources