[Openid-specs-risc] Call notes

Atul Tulshibagwale atul.tulshibagwale at crowdstrike.com
Tue Jul 28 18:50:04 UTC 2026


Hi all,
The notes for today's call are stored here
<https://github.com/openid/sharedsignals/wiki/WG-Meeting:-2026%E2%80%9007%E2%80%9028>.
They are copied below for your convenience.

Thanks for participating,
Atul

---
WG Meeting: 2026-07-28 <#Agenda>Agenda

   - Administrative:
      - Contribution agreement
      <https://openid.net/intellectual-property/openid-foundation-contribution-agreements/>
      - Note Well
      <https://openid.net/wp-content/uploads/2025/06/OIDF_Groups-Activities-Events-Note-Well_Final_2025-06-12.pdf>
   - CAEP Interop Profile review period has begun
   <https://openid.net/public-review-period-for-proposed-openid-caep-interoperbility-profile-final-specification/>
   - Device management PR <https://github.com/openid/sharedsignals/pull/329>
   update
   - WISE Proposal <https://identitymonk.github.io/openid-wise/> discussion
   in issue 344 <https://github.com/openid/sharedsignals/issues/344>
   - WISE Proposal "Condition bounded credentials" clarification - Issue 345
   <https://github.com/openid/sharedsignals/issues/345>
   - IETF Update

<#Attendees>Attendees

   - Yair Sarig (Omnissa)
   - Atul Tulshibagwale (CrowdStrike)
   - Apoorva Deshpande (Okta)
   - Tom Sato (MyAuberge)
   - John O'Leary (WinMagic)
   - Thi Nguyen-Huu (WinMagic)
   - Sergei Nikitin (WinMagic)
   - Jack Zaldivar (Databricks)
   - George Fletcher (Independent)
   - Jeff Lombardo (AWS)
   - Debayan Basu (Independent)

<#Notes>Notes <#WISE-Proposal>WISE Proposal

   - (Jeff) WISE is not meant for a transactions. Original poster wants
   ensure we mention that this is not for transactional credentials.
   - (Jeff) This could be an interesting input for another agentic AI
   related proposal
   - (Jeff) We're only focusing on workloads, which could be cron-jobs or
   even LLM-based workloads.
   - (Apoorva) SET RFC already clarifies that this cannot be a "credentials
   token". Since this is an SET, it is already covered.
   - (Jeff) The commenter's point is valid that it is not meant for
   transaction credential events. This could be another profile of SSF.
   - (Jeff) The 2nd part of the issue is about privacy. When we say
   something has changed about a workload identity, it could mean an IP, …
   - (Jeff) Describing those elements might violate privacy of those
   identities. I'm working on a variation of this proposal, which addresses
   this issue.
   - (Jeff) We leave it to the implementers to decide what to do about it.
   - (Tom) A couple of more points:
      - (Thank you first of all)
      - This is only about the credential of the workload, but what I
      needed was a way to communicate changes to mandates, lifecycle, etc. Can
      this be done in WISE, or should it be parallel to WISE.
      - (Jeff) I like the idea, but it could be a different profile of SSF,
      with the mandate lifecycle, etc.
      - (Jeff) Mandate is like a mission / charter / intent in the context
      of an agent. The mandate might change, which prevents the client from
      obtaining new tokens, etc. This feels like a different profile.
      - (Tom) Are you working sample / reference code?
      - (Jeff) Someone was working on it (I saw it in another issue)
      - (Jeff) I'm working on first stabilizing the draft.
      - (Jeff) Once it is stable, we can work on demo artifacts. Even do an
      interop event.
   - (Atul) I will send out an email asking if anyone has a contrary
   opinion to including this as a working output of the SSWG. This is because
   there seems to be sufficient engagement within the WG for this proposal.
   - (Jeff) There are things we are doing to align with CAEP and RISC, so
   that the profile doesn't feel very different.
   - (Jeff) I've updated the draft to address issue #345. You can take a look
   at the "-3" draft
   <https://github.com/identitymonk/openid-wise/tree/Draft-03>. URL coming
   soon. It's on a branch right now.

<#IETF-Update>IETF Update

   - (Tom) There was a lot of talk about CAEP / SSF at the IETF.
   - (Tom) Great to see the new proposal from Jeff
   - (Tom) I'll put together a list of places where CAEP was mentioned.
   - (Jeff) The audit BoF were interested in using SSF to communicate audit
   signals.

<#Profiles-of-SSF>Profiles of SSF

   - (Atul) Do profiles live in SSWG or wherever the application area is?
   - (Jeff) IITP
   <https://docs.google.com/document/d/1vyZBFspaUaTwKieEEVQkiu-j7RK6g0uaYQRQR1D0pEk/edit?tab=t.0>
   is an upcoming proposal that will face this question
   -

<#Action-Items>Action Items
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260728/eb182703/attachment.htm>


More information about the Openid-specs-risc mailing list