Skip to content

Cross-org agent commerce fixture (authority-chain-referenced mode), pending in-toto/attestation#549 #4

@tomjwxf

Description

@tomjwxf

Tracking issue for a cross-org agent commerce fixture demonstrating the authority-chain-referenced mode of decision receipts (operator-signed + delegation_chain_root), per the §6 sidebar in microsoft/agent-governance-toolkit Tutorial 33 (#1197, merged).

Shape

  • Two organizations: operator A and operator B.
  • Shared compliance regulator as the external verifier.
  • Authority chain from root delegation, through a sub-delegation, into the final action executed by agent under operator B on behalf of operator A's principal.
  • delegation_chain_root field populated once in-toto/attestation#549 merges the delegationChainRoot: DigestSet field upstream.

Contribution status

@aeoess offered to contribute this fixture as soon as in-toto#549 lands. Coordinating here; will merge as a worked example alongside:

Blockers

None on our side. Waiting on upstream in-toto merge. Revisit when #549 lands.

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions