From Approval to Execution: Assurance Boundaries in Three Agent Protocols
Agent protocols increasingly carry a record of an approval: a statement that some party authorised an action before it ran. This paper asks a narrow question of three such protocols — does the record establish that what executed is what was approved? — and finds no common answer and no common gap. It extends the four-property receipt decomposition published in Claim-Level Negative Testing for Agent-Governance Evidence (10.5281/zenodo.21418702) into four dimensions suited to cross-protocol comparison: content commitment, authenticated approval, enforcement at execution, and evidence of execution. The decomposition is prior work and is not re-derived here. What is new is the comparison across three independently designed protocols, three refinements the earlier model did not separate — referenced content as distinct from the reference that names it, enforcement as a property of a deployment rather than of a record, and a signed claim as distinct from a corroborated one — and the finding that the established subsets differ. PACT (draft-laxsharma-pact-02) binds referenced content, commits transitively to the evaluated artefact, and carries a signed evaluation claim, while stating plainly that nothing is enforced against its own Facilitator. The CognOS LUMEN v0.1 Decision Passport binds the executed tool and arguments correctly in a document whose hashes do not authenticate its asserted approver. Microsoft's Agent Host Protocol provides behavioural guarantees inside an explicitly declared trusted-host model, and no portable cryptographic evidence outside it. A protocol-neutral conformance corpus accompanies the paper, with positive controls: a deliberately weak checker scores nine of nine against the negative vectors while being no binding at all. Two of the author's own findings were withdrawn publicly during preparation and are logged with the methodological controls adopted in response. Not peer-reviewed. No claim of independent validation, certification, adoption, or production effectiveness is made. Views are the author's own.
Authors
- Michael K. Saleme (ORCID: https://orcid.org/0009-0003-6736-1900)
Publication Details
- Journal
- arXiv (Cornell University)
- Published
- 2026-09-19
- DOI
- https://doi.org/10.5281/zenodo.22847474
- Primary Topic
- Security and Verification in Computing
- Type
- preprint