Section map

September 15, 2026 · View on GitHub

A reader's guide to the Internet-Draft: what each section defines and which registry (REGISTRY.md) it governs. Section numbers track the current revision (-03); Git history preserves prior revision numbering.

Companion document: draft-mih-scitt-agent-action-capsule-sel-disc-00.md profiles the selective-disclosure extension point. It defines the _sd_alg/_sd vocabulary, commitment encoding, disclosure syntax, and verifier checks (SD-1 through SD-6).

Companion document: draft-mih-scitt-agent-action-capsule-disclosure-envelope-00.md profiles the out-of-band disclosure of digest-only fields — currently model_attestation.compute_attestation.agent_input_digest and .agent_output_digest (-02 §5.3, Observation mode). It defines the capsule/disclosures wrapper vocabulary, the disclosure-eligible field table, and the verifier checks (DE-1 through DE-3). Unlike the selective-disclosure companion, it never modifies the Capsule payload or its capsule_id; the wrapper is a sibling structure entirely outside the signed bytes.

I-D sectionDefinesRegistry governed
§1 IntroductionThe may/did distinction; the three design commitments (effect-state binding, a Capsule on every verdict, independent verifiability)
§2 ConventionsBCP 14 terminology; Capsule and Producer Envelope definitions
§3.1 Producer EnvelopeIndependent COSE_Sign1 over the raw 32-byte Capsule ID; exact Ed25519 headers; signer authorization outside the cryptographic verdict
§3.2 SCITT registrationDistinct RFC 9943 registration statement over the same raw Capsule ID; Receipt and VDS verification remain substrate concerns
§3.x OutcomesAsynchronous consequences represented as new Capsules with independent identities and envelopes
§4 Registries (summary)The six registry-governed vocabularies, stated once with the binding invariantall six
§5.1 IdentityFormat 4 declared jcs, chain-committed Capsule ID, and fail-closed rejection of every other format or canonicalization declaration
§5.2 Effect Recordeffect.status, the confirmed-effect binding (request/response digests), effect.type, irreversibility_class, effect_attestation and the validity matrixeffect.type, irreversibility_class, effect_attestation
§5.3 Assuranceattestation_mode / effect_mode / ledger_mode as independently-rederivable claims
§5.4 Dispositiondecision, approver (closed enum), the honest human_disposed flag, reason_digest, expiry_policydisposition.decision
§5.4.1 verdict_classThe terminal-verdict reason-class vocabularyverdict_class
§5.4.2 OrthogonalityThe pairing rule between verdict_class and effect_mode
§5.4.3 A Capsule on every verdictWhy refusals and blocks are recorded as affirmative evidence
§5.4.4 Chained CapsulesThe chain block, HITL-resolution-as-supersedes, the open-items predicatechain.relation
§6 VerificationIndependent Capsule Class-1, Producer Envelope, authorization, and Receipt verification responsibilities
§7 ConformanceThe two verifier classes (Class 1 / Class 2)
§8 Manifest-dependent materialConstraint Records and the Class 2 (manifest-aware) checks
§9 Extensibility / namespacingThe not-registry-governed, producer-local vocabularies
§10 Related WorkAdjacent SCITT/agentic-governance drafts
§11 Future WorkReserved extension direction
§12 IANA ConsiderationsThe six payload-vocabulary registries plus Capsule JSON and raw Capsule-ID media typesall six
§13 Security ConsiderationsTamper-evidence vs recorder honesty; observed-and-bound; upstream spoofing; digest leakage

The normative registry definitions and seeded values are in §12 of the I-D; REGISTRY.md is the interim registry of record that mirrors them.