Skip to content

docs: connect agent credentials to runtime evidence - #300

Draft
imran-siddique wants to merge 1 commit into
mainfrom
agent/document-agent-credentials
Draft

docs: connect agent credentials to runtime evidence#300
imran-siddique wants to merge 1 commit into
mainfrom
agent/document-agent-credentials

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Closes #267.

What changed

  • adds docs/integrations/agent-credentials.md with the credential / manifest / runtime-evidence division of concerns
  • documents exact-manifest binding, defined stop boundaries, digest-as-claim, verification order, and chain-of-custody limits
  • adds the guide to the integrations index and MkDocs navigation
  • records the addition in the changelog

Why

The remaining CoSAI WS4 follow-up needed one durable integration pattern connecting a credential decision to the exact pre-execution manifest and separately signed runtime evidence. The guide keeps those assurance layers distinct and does not treat a producer-reported stop reason as proof.

The upstream status is explicit: OCSF #1704 and #1724 are open proposals as of August 2026, and unassigned class number 5050 must not be emitted as core OCSF.

Review context

This is the first draft Imran offered in cosai-oasis/ws4-secure-design-agentic-systems#149. Review and co-authorship are invited from @imolloy, @benhylau, @ksingh299, @akolekar-zs, and @rithikha, as proposed in #267.

Validation

  • git diff --check — passed
  • python -m mkdocs build — passed
  • python -m mkdocs build --strict — blocked by 12 pre-existing warnings in unrelated pages; the new guide introduced no warning

No SDK, schema, or conformance behavior changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs: integrations/agent-credentials.md — signed state-at-stop as the #99/#149 bridge

1 participant