[Openid-specs-risc] openid/sharedsignals: Comment created on issue 344

github at oidf.org github at oidf.org
Mon Jul 27 21:52:16 UTC 2026


openid/sharedsignals event

Issue Comment created on issue 344
Issue Title: Clarify the authority boundary and correlation guidance for WISE events involving AI agents
https://github.com/openid/sharedsignals/issues/344

Comment: On the boundary question in the first list — sections 4.4 and 4.6 currently take different positions on it. 4.4 tells Receivers to act on compromise events immediately without waiting for additional confirmation. 4.6 says a Receiver should treat a supply-chain event as input to its own policy and should not restrict a workload solely because the event arrived. Both are defensible, but a Receiver implementer reading them together does not know which is the default disposition. Stating it explicitly — the event reports state, the action is Receiver policy, with the compromise events called out as the case where the draft recommends acting without waiting — would answer a good part of what is asked here.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260727/8015e869/attachment.htm>


More information about the Openid-specs-risc mailing list