[Openid-specs-risc] Proposed agenda for tomorrow's meeting

toshiyuki sato tomsato at myauberge.jp
Tue Jul 28 18:15:11 UTC 2026


Regarding CEAP at IETF

Wanted to flag two other list threads where CAEP came up directly, in case
they're useful context beyond the WISE conversation itself.

1. agentproto / agent2agent list, prep for the WG-forming BoF (July 9–10)

Stephen Farrell raised a charter-level concern: the draft charter treats
agents as deterministic, but AI agents aren't, and that has implications
for the security model — different privileges could be requested despite
identical visible inputs. Orie (BoF chair) pointed at CAEP directly as
relevant prior work in response. Chris Hood (AGTP) gave the most developed
answer: keep the protocol layer deterministic and cryptographically
checkable (identity, authority, delegation, attribution), and push agent
nondeterminism up to a policy layer above it — explicitly naming CAEP-style
continuous evaluation as the fit for that policy layer, distinct from the
protocol's own guarantees.

2. OAuth WG list, "Continuous Access Evaluation and Conditional Access
Control for Clients" (July 2–3)

Judith Kahrer asked whether CAE should extend to clients, with an MFA-style
step-up analogy. A few points worth having on your radar:

- Yaron Zehavi and Mohamad Khalil-Yossif both pushed back on the
step-up/MFA framing as the wrong model for AI-driven clients, favoring
shorter-lived grants plus CAEP-style signals instead.
- Khalil-Yossif drew a distinction worth noting: CAEP and shorter grant
lifetimes answer "should this client continue to hold access," but not "did
the human principal actually authorize this specific high-risk action,
verifiably, after the fact." He's submitted a separate survey to
secdispatch, "Authorization Evidence for High-Risk Actions," addressing
that second question — may be worth a look as an adjacent, complementary
effort.
- Pieter gave the fullest response in the thread — endorsing Shared Signals
as the right building block for adjusting access to changing risk, and
explicitly floating a "Workload Identity Security Event (WISE) profile" as
a next step. Worth knowing this thread looks like WISE's actual point of
origin, about a week before the announcement to this list.


Above are some of the responses. SSF came up in other conversations during
various sessions and WISE would be very welcomed by IETF agentic folks.


Best,
Tom Sato

2026年7月28日(火) 9:26 Atul Tulshibagwale via Openid-specs-risc <
openid-specs-risc at lists.openid.net>:

> Hi all,
> Here's the tentative agenda for tomorrow's meeting. Please respond if you
> have any additions, changes, or feedback about it:
>
>
>    - CAEP Interop Profile review period has begun
>    - Device management PR
>    <https://github.com/openid/sharedsignals/pull/329> update
>    - WISE Proposal <https://identitymonk.github.io/openid-wise/>
>    discussion in issue 344
>    <https://github.com/openid/sharedsignals/issues/344>
>    - WISE Proposal "Condition bounded credentials" clarification - Issue
>    345 <https://github.com/openid/sharedsignals/issues/345>
>
> Thanks,
> Atul
> _______________________________________________
> Openid-specs-risc mailing list
> Openid-specs-risc at lists.openid.net
> https://lists.openid.net/mailman/listinfo/openid-specs-risc
>


-- 

Tom Sato
佐藤俊之
代表取締役CEO
マイオーベルジュ株式会社
090-6315-1325
tomsato at myauberge.jp
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260729/bf0ddba9/attachment.htm>


More information about the Openid-specs-risc mailing list