The complete Agent Trust Fabric protocol stack — three coordinated open standards, 40 formal invariants, and a published academic record.
Specifies the Agent Identity Record, Delegation Receipt, Trust Lattice, and Monotonic Authority Reduction invariant — a cryptographic framework for post-quantum-secured agent authority delegation. Every delegation event produces an artifact verifiable by any third party without platform access.
Every agent operating under ATF governance must have an AIR — a PQC-signed document establishing:
agent_id — format: AID-{JURISDICTION}-{DATE}-{HEX16}tier — TIER-1 (Human) · TIER-2 (Autonomous) · TIER-3 (Subordinate)authority_budget — ceiling [0.0, 1.0]pqc_public_key — ML-DSA-65 public keycontent_hash — SHA-256 canonical hashTier determines registration tier and default authority ceiling.
The Trust Lattice is a directed acyclic graph where each node is an AIR and each edge is a signed DR. Properties:
Extends RFC-ATF-1 into the full execution lifecycle of long-running agent workflows. Introduces the Runtime Continuity Record, the Continuity Eligibility Score, the Authority Fragmentation Guard, and the Escalation Protocol. Adds 8 RGC invariants.
| Stage | Threshold | Effect |
|---|---|---|
| NOMINAL | ≥ 75.0 | Standard operation |
| MONITORING | ≥ 50.0 | Elevated logging |
| WARNING | ≥ 25.0 | Reduced confidence |
| CRITICAL | ≥ 10.0 | Single-decision auth |
| HALT | < 10.0 | All execution blocked |
Closes an attack vector that MAR alone cannot detect: authority amplification through concurrent sub-agents each receiving near-full delegations from the same chain root.
A PQC-signed, TAR-anchored authority health artifact emitted at governed intervals. Key fields:
rcr_id — format: ATFRCR-{16HEX}ces_score — computed CES valuecontinuity_status — NOMINAL/MONITORING/WARNING/CRITICAL/HALTtar_id — anchor to admission TARpredecessor_rcr_id — chain linkageThree coordinated extensions: GPIL (cross-runtime governance compatibility at three interoperability levels), ELP (eight evidence classes, HOT/WARM/COLD retention tiers), and FVP (OEP forensic packages, two-plane verification, key identity fingerprinting). Adds 26 invariants bringing the total to 40.
A cryptographically sealed, self-contained forensic ZIP package. Contains everything needed to verify a complete authority chain offline, years after the issuing system is decommissioned: