[Openid-specs-risc] Proposed agenda for tomorrow's meeting
Atul Tulshibagwale
atul.tulshibagwale at crowdstrike.com
Mon Aug 3 16:58:22 UTC 2026
Thanks Brian,
I'm curious about the envisioned use of SSF in AIMS, and I'll put it on the
agenda for tomorrow. It'll be great for the SSWG to support this effort as
needed.
Atul
On Tue, Jul 28, 2026 at 3:51 PM Brian Campbell via Openid-specs-risc <
openid-specs-risc at lists.openid.net> wrote:
> Maybe also worth mentioning that the AI Agent Authentication and
> Authorization [datatracker.ietf.org]
> <https://urldefense.com/v3/__https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHix-QfMDO$> draft
> (sometimes also known as the AIMS or klrc draft) discusses SSE/CAEP/RISC in
> a section on Agent Monitoring, Observability and Remediation
> [datatracker.ietf.org]
> <https://urldefense.com/v3/__https://datatracker.ietf.org/doc/html/draft-klrc-aiagent-auth-03*section-11__;Iw!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHiyo3wTzU$>
> .
>
> I'm not sure that part is fully formed or meaningfully deployable right
> now. But it's there in a draft that's garnered some attention and hopefully
> poised for the next steps in the IETF process.
>
> On Tue, Jul 28, 2026 at 11:15 AM toshiyuki sato via Openid-specs-risc <
> openid-specs-risc at lists.openid.net> wrote:
>
>> Regarding CEAP at IETF
>>
>> Wanted to flag two other list threads where CAEP came up directly, in
>> case they're useful context beyond the WISE conversation itself.
>>
>> 1. agentproto / agent2agent list, prep for the WG-forming BoF (July 9–10)
>>
>> Stephen Farrell raised a charter-level concern: the draft charter treats
>> agents as deterministic, but AI agents aren't, and that has implications
>> for the security model — different privileges could be requested despite
>> identical visible inputs. Orie (BoF chair) pointed at CAEP directly as
>> relevant prior work in response. Chris Hood (AGTP) gave the most developed
>> answer: keep the protocol layer deterministic and cryptographically
>> checkable (identity, authority, delegation, attribution), and push agent
>> nondeterminism up to a policy layer above it — explicitly naming CAEP-style
>> continuous evaluation as the fit for that policy layer, distinct from the
>> protocol's own guarantees.
>>
>> 2. OAuth WG list, "Continuous Access Evaluation and Conditional Access
>> Control for Clients" (July 2–3)
>>
>> Judith Kahrer asked whether CAE should extend to clients, with an
>> MFA-style step-up analogy. A few points worth having on your radar:
>>
>> - Yaron Zehavi and Mohamad Khalil-Yossif both pushed back on the
>> step-up/MFA framing as the wrong model for AI-driven clients, favoring
>> shorter-lived grants plus CAEP-style signals instead.
>> - Khalil-Yossif drew a distinction worth noting: CAEP and shorter grant
>> lifetimes answer "should this client continue to hold access," but not "did
>> the human principal actually authorize this specific high-risk action,
>> verifiably, after the fact." He's submitted a separate survey to
>> secdispatch, "Authorization Evidence for High-Risk Actions," addressing
>> that second question — may be worth a look as an adjacent, complementary
>> effort.
>> - Pieter gave the fullest response in the thread — endorsing Shared
>> Signals as the right building block for adjusting access to changing risk,
>> and explicitly floating a "Workload Identity Security Event (WISE) profile"
>> as a next step. Worth knowing this thread looks like WISE's actual point of
>> origin, about a week before the announcement to this list.
>>
>>
>> Above are some of the responses. SSF came up in other conversations
>> during various sessions and WISE would be very welcomed by IETF agentic
>> folks.
>>
>>
>> Best,
>> Tom Sato
>>
>> 2026年7月28日(火) 9:26 Atul Tulshibagwale via Openid-specs-risc <
>> openid-specs-risc at lists.openid.net>:
>>
>>> Hi all,
>>> Here's the tentative agenda for tomorrow's meeting. Please respond if
>>> you have any additions, changes, or feedback about it:
>>>
>>>
>>> - CAEP Interop Profile review period has begun
>>> - Device management PR [github.com]
>>> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/pull/329__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHi3Q1aDbV$>
>>> update
>>> - WISE Proposal [identitymonk.github.io]
>>> <https://urldefense.com/v3/__https://identitymonk.github.io/openid-wise/__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHi3hnoZV2$>
>>> discussion in issue 344 [github.com]
>>> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/344__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHi3Nm0262$>
>>> - WISE Proposal "Condition bounded credentials" clarification - Issue
>>> 345 [github.com]
>>> <https://urldefense.com/v3/__https://github.com/openid/sharedsignals/issues/345__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHizps5a1t$>
>>>
>>> Thanks,
>>> Atul
>>> _______________________________________________
>>> Openid-specs-risc mailing list
>>> Openid-specs-risc at lists.openid.net
>>> https://lists.openid.net/mailman/listinfo/openid-specs-risc
>>> [lists.openid.net]
>>> <https://urldefense.com/v3/__https://lists.openid.net/mailman/listinfo/openid-specs-risc__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHi4QXHu2L$>
>>>
>>
>>
>> --
>>
>> Tom Sato
>> 佐藤俊之
>> 代表取締役CEO
>> マイオーベルジュ株式会社
>> 090-6315-1325
>> tomsato at myauberge.jp
>> _______________________________________________
>> Openid-specs-risc mailing list
>> Openid-specs-risc at lists.openid.net
>> https://lists.openid.net/mailman/listinfo/openid-specs-risc
>> [lists.openid.net]
>> <https://urldefense.com/v3/__https://lists.openid.net/mailman/listinfo/openid-specs-risc__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHi4QXHu2L$>
>>
>
> *CONFIDENTIALITY NOTICE: This email may contain confidential and
> privileged material for the sole use of the intended recipient(s). Any
> review, use, distribution or disclosure by others is strictly prohibited.
> If you have received this communication in error, please notify the sender
> immediately by e-mail and delete the message and any file attachments from
> your computer. Thank you.*_______________________________________________
> Openid-specs-risc mailing list
> Openid-specs-risc at lists.openid.net
>
> https://urldefense.com/v3/__https://lists.openid.net/mailman/listinfo/openid-specs-risc__;!!BmdzS3_lV9HdKG8!yZLc87UgphQcKDLtAmcZNw_U7g6OiCv8HM4X4TKoDeqwnUX3AzBcO7t0qXgtrQnWAQ7dg-aze_6fKKbBJv0m25AHv9bf6-md5QQHi4QXHu2L$
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-risc/attachments/20260803/a344869c/attachment.htm>
More information about the Openid-specs-risc
mailing list