From Approval to Execution: Assurance Boundaries in Three Agent Protocols

Agent protocols increasingly carry a record of an approval: a statement that some party authorised an action before it ran. This paper asks a narrow question of three such protocols — does the record establish that what executed is what was approved? — and finds no common answer and no common gap. It extends the four-property receipt decomposition published in Claim-Level Negative Testing for Agent-Governance Evidence (10.5281/zenodo.21418702) into four dimensions suited to cross-protocol comparison: content commitment, authenticated approval, enforcement at execution, and evidence of execution. The decomposition is prior work and is not re-derived here. What is new is the comparison across three independently designed protocols, three refinements the earlier model did not separate — referenced content as distinct from the reference that names it, enforcement as a property of a deployment rather than of a record, and a signed claim as distinct from a corroborated one — and the finding that the established subsets differ. PACT (draft-laxsharma-pact-02) binds referenced content, commits transitively to the evaluated artefact, and carries a signed evaluation claim, while stating plainly that nothing is enforced against its own Facilitator. The CognOS LUMEN v0.1 Decision Passport binds the executed tool and arguments correctly in a document whose hashes do not authenticate its asserted approver. Microsoft's Agent Host Protocol provides behavioural guarantees inside an explicitly declared trusted-host model, and no portable cryptographic evidence outside it. A protocol-neutral conformance corpus accompanies the paper, with positive controls: a deliberately weak checker scores nine of nine against the negative vectors while being no binding at all. Two of the author's own findings were withdrawn publicly during preparation and are logged with the methodological controls adopted in response. Not peer-reviewed. No claim of independent validation, certification, adoption, or production effectiveness is made. Views are the author's own.

Authors

Publication Details

Journal
arXiv (Cornell University)
Published
2026-09-19
DOI
https://doi.org/10.5281/zenodo.22847474
Primary Topic
Security and Verification in Computing
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

From Approval to Execution: Assurance Boundaries in Three Agent Protocols

Michael K. Saleme
arXiv (Cornell University)
Security and Verification in Computing
preprint

From Approval to Execution: Assurance Boundaries in Three Agent Protocols

Michael K. Saleme
preprint en

Abstract

Agent protocols increasingly carry a record of an approval: a statement that some party authorised an action before it ran. This paper asks a narrow question of three such protocols — does the record establish that what executed is what was approved? — and finds no common answer and no common gap. It extends the four-property receipt decomposition published in Claim-Level Negative Testing for Agent-Governance Evidence (10.5281/zenodo.21418702) into four dimensions suited to cross-protocol comparison: content commitment, authenticated approval, enforcement at execution, and evidence of execution. The decomposition is prior work and is not re-derived here. What is new is the comparison across three independently designed protocols, three refinements the earlier model did not separate — referenced content as distinct from the reference that names it, enforcement as a property of a deployment rather than of a record, and a signed claim as distinct from a corroborated one — and the finding that the established subsets differ. PACT (draft-laxsharma-pact-02) binds referenced content, commits transitively to the evaluated artefact, and carries a signed evaluation claim, while stating plainly that nothing is enforced against its own Facilitator. The CognOS LUMEN v0.1 Decision Passport binds the executed tool and arguments correctly in a document whose hashes do not authenticate its asserted approver. Microsoft's Agent Host Protocol provides behavioural guarantees inside an explicitly declared trusted-host model, and no portable cryptographic evidence outside it. A protocol-neutral conformance corpus accompanies the paper, with positive controls: a deliberately weak checker scores nine of nine against the negative vectors while being no binding at all. Two of the author's own findings were withdrawn publicly during preparation and are logged with the methodological controls adopted in response. Not peer-reviewed. No claim of independent validation, certification, adoption, or production effectiveness is made. Views are the author's own.

arXiv (Cornell University)
Peace, Justice and strong institutions
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.