[Openid-specs-risc] Call notes
Atul Tulshibagwale
atul.tulshibagwale at crowdstrike.com
Tue Jul 28 18:50:04 UTC 2026
Hi all,
The notes for today's call are stored here
<https://github.com/openid/sharedsignals/wiki/WG-Meeting:-2026%E2%80%9007%E2%80%9028>.
They are copied below for your convenience.
Thanks for participating,
Atul
---
WG Meeting: 2026-07-28 <#Agenda>Agenda
- Administrative:
- Contribution agreement
<https://openid.net/intellectual-property/openid-foundation-contribution-agreements/>
- Note Well
<https://openid.net/wp-content/uploads/2025/06/OIDF_Groups-Activities-Events-Note-Well_Final_2025-06-12.pdf>
- CAEP Interop Profile review period has begun
<https://openid.net/public-review-period-for-proposed-openid-caep-interoperbility-profile-final-specification/>
- Device management PR <https://github.com/openid/sharedsignals/pull/329>
update
- WISE Proposal <https://identitymonk.github.io/openid-wise/> discussion
in issue 344 <https://github.com/openid/sharedsignals/issues/344>
- WISE Proposal "Condition bounded credentials" clarification - Issue 345
<https://github.com/openid/sharedsignals/issues/345>
- IETF Update
<#Attendees>Attendees
- Yair Sarig (Omnissa)
- Atul Tulshibagwale (CrowdStrike)
- Apoorva Deshpande (Okta)
- Tom Sato (MyAuberge)
- John O'Leary (WinMagic)
- Thi Nguyen-Huu (WinMagic)
- Sergei Nikitin (WinMagic)
- Jack Zaldivar (Databricks)
- George Fletcher (Independent)
- Jeff Lombardo (AWS)
- Debayan Basu (Independent)
<#Notes>Notes <#WISE-Proposal>WISE Proposal
- (Jeff) WISE is not meant for a transactions. Original poster wants
ensure we mention that this is not for transactional credentials.
- (Jeff) This could be an interesting input for another agentic AI
related proposal
- (Jeff) We're only focusing on workloads, which could be cron-jobs or
even LLM-based workloads.
- (Apoorva) SET RFC already clarifies that this cannot be a "credentials
token". Since this is an SET, it is already covered.
- (Jeff) The commenter's point is valid that it is not meant for
transaction credential events. This could be another profile of SSF.
- (Jeff) The 2nd part of the issue is about privacy. When we say
something has changed about a workload identity, it could mean an IP, …
- (Jeff) Describing those elements might violate privacy of those
identities. I'm working on a variation of this proposal, which addresses
this issue.
- (Jeff) We leave it to the implementers to decide what to do about it.
- (Tom) A couple of more points:
- (Thank you first of all)
- This is only about the credential of the workload, but what I
needed was a way to communicate changes to mandates, lifecycle, etc. Can
this be done in WISE, or should it be parallel to WISE.
- (Jeff) I like the idea, but it could be a different profile of SSF,
with the mandate lifecycle, etc.
- (Jeff) Mandate is like a mission / charter / intent in the context
of an agent. The mandate might change, which prevents the client from
obtaining new tokens, etc. This feels like a different profile.
- (Tom) Are you working sample / reference code?
- (Jeff) Someone was working on it (I saw it in another issue)
- (Jeff) I'm working on first stabilizing the draft.
- (Jeff) Once it is stable, we can work on demo artifacts. Even do an
interop event.
- (Atul) I will send out an email asking if anyone has a contrary
opinion to including this as a working output of the SSWG. This is because
there seems to be sufficient engagement within the WG for this proposal.
- (Jeff) There are things we are doing to align with CAEP and RISC, so
that the profile doesn't feel very different.
- (Jeff) I've updated the draft to address issue #345. You can take a look
at the "-3" draft
<https://github.com/identitymonk/openid-wise/tree/Draft-03>. URL coming
soon. It's on a branch right now.
<#IETF-Update>IETF Update
- (Tom) There was a lot of talk about CAEP / SSF at the IETF.
- (Tom) Great to see the new proposal from Jeff
- (Tom) I'll put together a list of places where CAEP was mentioned.
- (Jeff) The audit BoF were interested in using SSF to communicate audit
signals.
<#Profiles-of-SSF>Profiles of SSF
- (Atul) Do profiles live in SSWG or wherever the application area is?
- (Jeff) IITP
<https://docs.google.com/document/d/1vyZBFspaUaTwKieEEVQkiu-j7RK6g0uaYQRQR1D0pEk/edit?tab=t.0>
is an upcoming proposal that will face this question
-
<#Action-Items>Action Items
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260728/eb182703/attachment.htm>
More information about the Openid-specs-risc
mailing list