<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.2.3) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-gilda-wimse-agent-audit-record-02" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="Agent Audit Record">An Audit Record Format for AI Agent Authorization Decisions</title>
    <seriesInfo name="Internet-Draft" value="draft-gilda-wimse-agent-audit-record-02"/>
    <author fullname="Sankalp Gilda">
      <address>
        <email>sankalp.gilda@gmail.com</email>
      </address>
    </author>
    <date year="2026" month="October" day="04"/>
    <area>Applications and Real-Time</area>
    <workgroup>Workload Identity in Multi System Environments</workgroup>
    <keyword>audit</keyword>
    <keyword>agent</keyword>
    <keyword>attestation</keyword>
    <keyword>tamper-evident</keyword>
    <abstract>

<t>This document defines a record format for AI agent authorization decisions. The format is one in-toto predicate type, signed inside a DSSE envelope. It carries the seven minimum audit fields that the WIMSE AI Identity Management System framework requires, and two properties that make those fields checkable: a canonicalization contract, and both the authorization decision and the observed effect with a derived three-valued agreement between them. That framework places the record format out of scope and takes no IANA action. This document supplies the format. It defines no policy.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-gilda-wimse-agent-audit-record/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Workload Identity in Multi System Environments Working Group mailing list (<eref target="mailto:wimse@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/wimse/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/wimse/"/>.
      </t>
    </note>
  </front>
  <middle>

<section anchor="introduction">
      <name>Introduction</name>
      <t>This document defines one record format for the audit events that Section 11 of <xref target="AIMS"/> requires, and it defines nothing else. It specifies no policy model, no compliance criteria and no retention rule, and it does not extend or amend <xref target="AIMS"/>.</t>
      <t>The goals are:</t>
      <ul spacing="normal">
        <li>
          <t>to make an audit record from one deployment comparable with one from another;</t>
        </li>
        <li>
          <t>to make "tamper-evident" a property a verifier can test on the bytes it holds;</t>
        </li>
        <li>
          <t>to carry the authorization decision and the observed effect in one signed record, so a disagreement between them is detectable;</t>
        </li>
        <li>
          <t>to give the seven minimum fields of Section 11 of <xref target="AIMS"/> one member each.</t>
        </li>
      </ul>
      <t>Policy belongs to a deployment, and a record format belongs to everyone who has to read the record. Two implementations that each satisfy Section 11 in their own format produce audit trails that cannot be compared, correlated across a service boundary, or checked by a party that trusts neither producer. Section 11 asks for all three.</t>
      <t>Comparable has a narrow meaning here. Two records are comparable when a third party holding both can decide, from the bytes alone, whether they describe the same request, whether their decisions agree, and whether either was enforced.</t>
      <t>The consequence is concrete: two deployments that each hash a request differently cannot join their records on a request digest, so a delegation that crossed between them is reconstructable in neither log.</t>
      <t>Section 11 of <xref target="AIMS"/> is normative about the existence of agent audit records and silent about their form. It requires that "deployments <bcp14>MUST</bcp14> produce durable audit logs covering authorization decisions and subsequent remediations", that "Audit records <bcp14>MUST</bcp14> be tamper-evident and retained according to the security policy of the deployment", and that audit events record seven minimum fields.</t>
      <t>Section 12 then places the policy model and document format out of scope, stating that they are "not recommended as a target for standardization within this specification". Section 13 places compliance criteria out of scope, and Section 16 records no IANA actions. <xref target="rationale"/> sets out the canonicalization contract and the reason the decision and the observed effect belong in one record.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>

</section>
    <section anchor="terminology">
      <name>Terminology</name>
      <t>The following terms are used throughout this document. Two of them, <em>observer</em> and <em>decision point</em>, are defined here; the rest are taken from the documents named beside them.</t>
      <dl>
        <dt>Agent, Tool, Service, Resource, LLM:</dt>
        <dd>
          <t>as <xref target="AIMS"/> uses them.</t>
        </dd>
        <dt>Agent identifier:</dt>
        <dd>
          <t>a WIMSE identifier as defined in <xref target="WIMSE-ID"/>.</t>
        </dd>
        <dt>Statement, subject, predicate:</dt>
        <dd>
          <t>as <xref target="IN-TOTO"/> uses them.</t>
        </dd>
        <dt>Observer:</dt>
        <dd>
          <t>the party that produces a record under this document. An observer watches from a layer the agent cannot address. A host-side view of a guest filesystem, a hypervisor-level read of guest state, and kernel-level supervision below the observed process are such layers. An in-process library, a wrapper the agent links, and an importer holding another party's log are not.</t>
        </dd>
        <dt>Decision point:</dt>
        <dd>
          <t>the party that evaluated the authorization request, whatever its architecture.</t>
        </dd>
        <dt>Interval:</dt>
        <dd>
          <t>the period between the before-state and the after-state that one record covers.</t>
        </dd>
        <dt>Tier:</dt>
        <dd>
          <t>the degree to which a record's own members corroborate what it claims about how it was observed. A verifier derives the tier under the rule in <xref target="observation"/> and never reads it from the record.</t>
        </dd>
      </dl>
      <t>Every digest in this document is written as lowercase hexadecimal in the algorithm the record declares in its <tt>hashAlgorithm</tt> member.</t>
    </section>
    <section anchor="audit-record-specification">
      <name>Audit Record Specification</name>
      <t>A record is an in-toto Statement <xref target="IN-TOTO"/> carried in a DSSE envelope <xref target="DSSE"/>. Its <tt>predicateType</tt> is</t>
      <artwork><![CDATA[
=========== NOTE: "\" line wrapping per RFC 8792 ============

https://probityai.github.io/agent-evidence-vectors/predicate/v1/\
agent-audit-record
]]></artwork>
      <t>Seventeen required predicate members and one optional member are defined in <xref target="members"/>. Each of the seventeen is required unless a rule in that section makes it conditional, no member has a default, and a verifier <bcp14>MUST NOT</bcp14> supply one for an absent member (vectors <tt>F1</tt> and <tt>EV3</tt>). Two members are conditional on a sibling value, <tt>resource.argumentsDigest</tt> and <tt>correlation.externalAnchor</tt>, and each is specified where it is defined. The optional member is <tt>oversight</tt> (<xref target="oversight"/>); its absence says nothing about whether a person acted.</t>
      <t>A verifier <bcp14>MUST</bcp14> reject a value outside any closed vocabulary this document defines, and <bcp14>MUST NOT</bcp14> ignore the member (vector <tt>V1</tt>). The closed vocabularies reuse terms registered in <xref target="VOCABULARY"/>.</t>
      <section anchor="canonical">
        <name>Canonical form</name>
        <t>Two implementations derive the same bytes from the same Statement only if they agree on the serialization and on what makes a Statement malformed. Both are fixed below.</t>
        <section anchor="json-profile">
          <name>JSON profile</name>
          <t>Producers and verifiers <bcp14>MUST</bcp14> canonicalize the Statement with <xref target="RFC8785"/>, and the signature covers those bytes and no other serialization (vector <tt>T2</tt>). Producers and verifiers <bcp14>MUST</bcp14> enforce the <xref target="RFC7493"/> I-JSON safe-integer profile: an integer of magnitude at or above 2^53 makes the Statement malformed (vector <tt>T5</tt>).</t>
        </section>
        <section anchor="duplicate-members-and-nesting-depth">
          <name>Duplicate members and nesting depth</name>
          <t>A member name repeated at any depth makes the Statement malformed. A verifier <bcp14>MUST</bcp14> reject such a Statement and <bcp14>MUST NOT</bcp14> retain any one occurrence (vector <tt>T3</tt>). A Statement nested deeper than 128 levels <bcp14>MUST</bcp14> be rejected (vector <tt>T4</tt>).</t>
        </section>
      </section>
      <section anchor="subject">
        <name>Subject convention</name>
        <t>A record carries two subject entries. The first is the request, by digest: its <tt>name</tt> is the correlation identifier and its <tt>sha256</tt> digest is the request digest defined in <xref target="members"/>. The second is the after-state root of the interval the predicate carries, and its <tt>name</tt> is the first entry's <tt>name</tt> with the suffix <tt>/after</tt>.</t>
        <sourcecode type="json"><![CDATA[
"subject": [
  { "name": "urn:example:corr:7f3a",
    "digest": { "sha256": "9f86d081884c7d659a2feaa0c55ad015..." } },
  { "name": "urn:example:corr:7f3a/after",
    "digest": { "sha256": "60303ae22b998861bce3b28f33eec1be..." } }
]
]]></sourcecode>
        <t>A verifier <bcp14>MUST</bcp14> bind on the <tt>digest</tt> map and <bcp14>MUST NOT</bcp14> bind on either <tt>name</tt>. A name is a correlation identifier a producer chooses; a digest is a value a verifier recomputes from the bytes it holds. The names exist so that a reader can tell the two entries apart.</t>
        <t>The second entry <bcp14>MUST</bcp14> be present if and only if the predicate carries an interval (vectors <tt>S1</tt> and <tt>I1r</tt>), and its digest <bcp14>MUST</bcp14> equal the interval's after-state root (vector <tt>S2</tt>).</t>
        <t>A decision that permitted nothing, and a decision that was denied, still carry an interval whose before-state and after-state roots are equal and whose write set is empty (vector <tt>A2</tt>). A consumer therefore reads an absence of effect from the members of a record it holds, and never from a record it does not have.</t>
      </section>
      <section anchor="timestamps">
        <name>Timestamps and correlation</name>
        <t>Every time value in a record <bcp14>MUST</bcp14> be an <xref target="RFC3339"/> date-time. A producer <bcp14>SHOULD</bcp14> express it in UTC with the "Z" offset, so that two records from different deployments sort together without a conversion step. The correlation identifier is the first subject entry's <tt>name</tt>, so one identifier binds the request digest, the interval and the record.</t>
      </section>
      <section anchor="tamper">
        <name>Tamper-evidence</name>
        <t>A record satisfies the tamper-evidence requirement of Section 11 of <xref target="AIMS"/> when all three of the following hold.</t>
        <t>The DSSE pre-authentication encoding covers the <xref target="RFC8785"/> canonical bytes of the whole Statement, and every one of the seven minimum fields is inside that pre-image.</t>
        <artwork><![CDATA[
DSSE PAE = "DSSEv1" SP len("application/vnd.in-toto+json") SP
           "application/vnd.in-toto+json" SP
           len(JCS(statement)) SP JCS(statement)
]]></artwork>
        <t>The request digest, the ordered write chain of the effect, and both <tt>agreement</tt> values are recomputable from other members of the same record. A verifier therefore still refuses a record that the key holder altered and signed again (vector <tt>T1</tt>).</t>
        <t>The canonical form is fixed as in <xref target="canonical"/>, so two verifiers derive identical bytes from identical documents. Any one of the three failing is a refusal.</t>
        <t>This document does not address the retention half of the Section 11 requirement. Retention is a property of a deployment, and a record cannot assert it about itself. A record under this document <bcp14>SHOULD</bcp14> state that in its <tt>doesNotAssert</tt> member, so that a reader need not infer coverage.</t>
      </section>
      <section anchor="mapping">
        <name>Mapping to the seven minimum fields</name>
        <table>
          <name>The seven minimum fields of Section 11 and the members that carry them</name>
          <thead>
            <tr>
              <th align="left">Section 11 field</th>
              <th align="left">Members</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">authenticated agent identifier</td>
              <td align="left">
                <tt>agent.id</tt>, <tt>agent.credentialDigest</tt>, <tt>agent.authentication</tt>, <tt>agent.signers</tt></td>
            </tr>
            <tr>
              <td align="left">delegated subject, when present</td>
              <td align="left">
                <tt>delegation.subject</tt>, <tt>delegation.subjectKind</tt>, <tt>delegation.authorityDigest</tt></td>
            </tr>
            <tr>
              <td align="left">resource or tool being accessed</td>
              <td align="left">
                <tt>resource.kind</tt>, <tt>resource.id</tt>, <tt>resource.binding</tt>, <tt>resource.argumentsDigest</tt></td>
            </tr>
            <tr>
              <td align="left">action requested and authorization decision</td>
              <td align="left">
                <tt>decision</tt>, <tt>evaluation</tt> and <tt>effect</tt>, with the derived <tt>agreement</tt>, and <tt>oversight</tt> when present</td>
            </tr>
            <tr>
              <td align="left">timestamp and correlation identifier</td>
              <td align="left">
                <tt>correlation</tt> and the interval timestamps</td>
            </tr>
            <tr>
              <td align="left">posture assessment or risk state</td>
              <td align="left">
                <tt>posture</tt>, carrying both vantages and <tt>assessedAt</tt></td>
            </tr>
            <tr>
              <td align="left">remediation or revocation events and cause</td>
              <td align="left">
                <tt>remediation</tt></td>
            </tr>
          </tbody>
        </table>
        <t>Each field also carries an evidence partition in <tt>fieldEvidence</tt>, stating whether the observing substrate covered the value or the producer asserted it. All seven fields can be recorded by an agent about itself. A record that says which ones were is checkable; a record that does not say is not.</t>
        <t>The fourth field pairs an action with a decision, and this format carries <tt>decision</tt>, <tt>effect</tt> and the derived <tt>agreement</tt> together. A record whose decision and effect disagree is well formed, and the disagreement is visible in signed bytes:</t>
        <sourcecode type="json"><![CDATA[
"decision": { "action": "write", "reported": "deny" },
"effect":   {
  "observed": "occurred",
  "writes": [ { "path": "/srv/ledger/settlements.jsonl" } ]
},
"agreement": "disagree"
]]></sourcecode>
        <t>A log that carries the decision alone records that case as a clean denial, because it has no other value to disagree with.</t>
      </section>
      <section anchor="verifying">
        <name>Verifying a record</name>
        <t>A verifier holds a DSSE envelope and reaches a verdict from the bytes inside it. The checks below are the ones this document has already stated, in the order a verifier can apply them without reading a member twice.</t>
        <t>The envelope's signature comes first, over the <xref target="RFC8785"/> canonical bytes of the whole Statement. A statement whose signature does not verify is malformed, and nothing further is read from it. A verifier scored against <xref target="vectors"/> reports it as malformed (vector <tt>T2</tt>).</t>
        <t>The JSON profile comes second: the safe-integer bound of <xref target="RFC7493"/>, no member name repeated at any depth, and no nesting past 128 levels. Each of the three makes a Statement malformed, so a verifier that finds one of them has nothing further to check.</t>
        <t>Membership comes third. Every one of the seventeen required members is present unless a rule in <xref target="members"/> makes it conditional on a sibling value, and every value sits inside the closed vocabulary its member declares.</t>
        <t>The recomputes come last, and a signature cannot supply them. The three that <xref target="tamper"/> requires come first: a verifier derives the request digest from the four members <xref target="members"/> names and compares it with the first subject entry, it replays the write chain from the before-state root and compares the result with the second subject entry, and it derives both agreement values from the members they are functions of.</t>
        <t>A fourth recompute binds the prior commitment rather than the record's content. A verifier recomputes the commitment digest, checks that the commitment precedes the interval, and checks that the commitment key is absent from <tt>agent.signers</tt>.</t>
        <t>The tier follows from those results. A verifier reads the five clauses of <xref target="observation"/> against the members it has just checked and assigns <tt>authoritative</tt> or <tt>voluntary</tt> itself.</t>
        <t>This document requires no particular order and no particular reporting shape. A verifier that stops at the first failure and a verifier that reports every failure are both conformant.</t>
      </section>
    </section>
    <section anchor="members">
      <name>Predicate members</name>
      <sourcecode type="json"><![CDATA[
{
  "recordId": "...",
  "tier": "authoritative",
  "hashAlgorithm": "sha256",
  "agent": {
    "id": "spiffe://prod.example.org/ns/payments/sa/reconciler",
    "credentialDigest": "...",
    "authentication": "wimse-wpt",
    "signers": ["..."]
  },
  "delegation": {
    "subject": "user:alice@example.org",
    "subjectKind": "user",
    "authorityDigest": "..."
  },
  "resource": {
    "kind": "tool",
    "id": "mcp://files/write",
    "binding": "digest-bound",
    "argumentsDigest": "..."
  },
  "decision": {
    "action": "write",
    "requestDigest": "...",
    "reported": "deny",
    "decisionPointId": "pdp://prod.example.org/authz-1",
    "policyDigest": "...",
    "reportedAt": "2026-09-19T11:04:02Z"
  },
  "evaluation": { "status": "evaluated" },
  "effect": {
    "observed": "occurred",
    "interval": {
      "beforeRoot": "...",
      "afterRoot": "...",
      "baseResolution": "supplied",
      "openedAt": "2026-09-19T11:04:01Z",
      "sealedAt": "2026-09-19T11:04:06Z"
    },
    "pathScope": ["/srv/ledger/"],
    "writes": [
      {
        "path": "/srv/ledger/settlements.jsonl",
        "preStateDigest": "...",
        "postStateDigest": "...",
        "requestDigest": "...",
        "inScope": true
      }
    ]
  },
  "agreement": "disagree",
  "correlation": {
    "id": "req:7f3a91c4",
    "scope": "cross-party",
    "timeBasis": "beacon-anchored",
    "externalAnchor": { "kind": "rfc3161", "digest": "..." }
  },
  "posture": {
    "reported": "sinkhole",
    "reportedDigest": "...",
    "observed": "allowlist",
    "observedDigest": "...",
    "assessedAt": "2026-09-19T06:00:00Z",
    "agreement": "disagree"
  },
  "remediation": [
    {
      "cause": "session-revoked",
      "signalReceivedAt": "2026-09-19T11:04:07Z",
      "enforcedAt": "2026-09-19T11:04:09Z",
      "enforcement": "session-terminated",
      "postEnforcementEffect": "none",
      "postEnforcementRoot": "..."
    }
  ],
  "observation": {
    "vantage": "below-observed",
    "coverage": { "scopeComplete": true, "gaps": [] },
    "priorCommitment": {
      "committedAt": "2026-09-19T11:03:58Z",
      "witnessNonce": "...",
      "commitmentDigest": "...",
      "keyid": "...",
      "sig": "..."
    }
  },
  "fieldEvidence": {
    "agent": "producer-asserted",
    "correlation": "producer-asserted",
    "decision": "producer-asserted",
    "delegation": "producer-asserted",
    "posture": "substrate-covered",
    "remediation": "substrate-covered",
    "resource": "substrate-covered"
  },
  "doesNotAssert": ["..."],
  "issuedAt": "2026-09-19T11:04:11Z"
}
]]></sourcecode>
      <section anchor="hashalg">
        <name>Record identity and hash algorithm</name>
        <t><tt>recordId</tt> is the producer's identifier for this record. It is opaque to a verifier except where the commitment digest is recomputed, which reads it as one of its four inputs.</t>
        <t><tt>hashAlgorithm</tt> names the algorithm every digest in the record is taken under. One value governs the whole record: the subject digests, the credential, authority, policy and posture digests, the interval roots, the write pre-state and post-state digests, and the commitment digest are all taken under it.</t>
        <t>A record carrying digests in two algorithms is therefore not representable, and that is the point. A verifier comparing two roots has to know they were taken under the same algorithm, and a per-member choice would let a producer choose which comparison a reader could make.</t>
        <t><tt>issuedAt</tt> is the time the producer sealed the record, and it is at or after the interval's <tt>sealedAt</tt> because the record cannot be issued before the interval it describes has closed.</t>
        <t>A verifier that does not implement the declared algorithm cannot recompute anything the record binds. It has no verdict to reach on such a record, and reporting that it could not read one is the honest outcome rather than a refusal on the record's content.</t>
      </section>
      <section anchor="identity-delegation-and-resource">
        <name>Identity, delegation and resource</name>
        <t><tt>agent.id</tt> carries the WIMSE identifier verbatim, and <tt>agent.credentialDigest</tt> the digest of the credential the identifier was read from. <tt>agent.authentication</tt> is the mechanism, over the closed set <tt>wimse-wpt</tt>, <tt>http-message-signature</tt>, <tt>mtls</tt>, <tt>oauth-access-token</tt>, <tt>none</tt>, drawn from Section 9 of <xref target="AIMS"/>. <tt>agent.signers</tt> is the set of key identifiers the agent signs its own records with, as the observer knows them, and it <bcp14>MAY</bcp14> be empty.</t>
        <t><tt>delegation.subjectKind</tt> is one of <tt>user</tt>, <tt>system</tt>, <tt>none</tt>. Field 2 of Section 11 is the only conditional one, so an absent delegated subject is conformant and is spelled <tt>subjectKind</tt> of <tt>none</tt> beside a <tt>subject</tt> of the literal <tt>none</tt>.</t>
        <t>A <tt>subjectKind</tt> of <tt>none</tt> beside any other subject value is malformed and a verifier <bcp14>MUST NOT</bcp14> prefer either member (vector <tt>F2</tt>). <tt>delegation.authorityDigest</tt> is required unconditionally, and a decision taken under no authority carries the digest of the explicit deny-all document.</t>
        <t><tt>resource.kind</tt> is one of <tt>path</tt>, <tt>uri</tt>, <tt>tool</tt>, the three shapes the single category of external endpoints in Section 4 of <xref target="AIMS"/> takes. <tt>resource.binding</tt> of <tt>digest-bound</tt> <bcp14>MUST</bcp14> carry <tt>argumentsDigest</tt>, and <tt>not-bindable</tt> <bcp14>MUST NOT</bcp14> carry it in any spelling, including <tt>null</tt> and the empty string (vectors <tt>F3</tt>, <tt>F3b</tt> and <tt>F3c</tt>).</t>
        <t>Where a decision point can canonicalize the arguments of a call, it <bcp14>SHOULD</bcp14> bind them by digest. A tool call whose arguments it cannot canonicalize has nothing to bind, so that call is representable and it cannot reach the strongest tier.</t>
      </section>
      <section anchor="decision-effect-and-agreement">
        <name>Decision, effect and agreement</name>
        <t><tt>decision.reported</tt> is one of <tt>permit</tt>, <tt>deny</tt>, <tt>permit-with-conditions</tt>. <tt>decision.requestDigest</tt> <bcp14>MUST</bcp14> equal the first subject entry's sha256 digest and <bcp14>MUST</bcp14> equal the <xref target="RFC8785"/> digest over the members <tt>action</tt>, <tt>argumentsDigest</tt>, <tt>resourceId</tt> and <tt>resourceKind</tt> (vector <tt>F4</tt>). The hashed object holds <tt>argumentsDigest</tt> exactly when <tt>resource.binding</tt> is <tt>digest-bound</tt>. Under <tt>not-bindable</tt> it holds the other three members and no <tt>argumentsDigest</tt> member at all, so every conforming implementation derives one digest for a given request (vector <tt>A6</tt>). Altering the action, the resource or the arguments after signing therefore breaks a recompute even where the signature was applied again.</t>
        <t>Each write carries <tt>requestDigest</tt>: the request digest of the request the observer attributes the write to, or the literal <tt>unattributed</tt> where the observer cannot attribute it. An attribution is an observation, and an observer that cannot tie a write to a request says so rather than guessing.</t>
        <t><tt>effect.observed</tt> describes this record's request, not the whole interval, and it is one of <tt>occurred</tt>, <tt>none</tt>, <tt>unknown</tt>. It <bcp14>MUST</bcp14> be derivable from the write set: <tt>occurred</tt> when at least one write is attributed to <tt>decision.requestDigest</tt>; <tt>none</tt> when no write is attributed to it and no <tt>unattributed</tt> write lies inside <tt>pathScope</tt>; and <tt>unknown</tt> otherwise. A write attributed to a different request belongs to that request's record and does not enter this one's value (vectors <tt>A7</tt> and <tt>T1</tt>). A value of <tt>none</tt> beside an empty write set requires the before-state and after-state roots to be equal (vector <tt>E1</tt>).</t>
        <t>The ordered write chain <bcp14>MUST</bcp14> reproduce the after-state root from the before-state root (vector <tt>E2</tt>). A <tt>baseResolution</tt> of <tt>empty-tree</tt> <bcp14>MUST</bcp14> carry the empty-tree constant for the declared hash algorithm (vector <tt>E3</tt>).</t>
        <t>A member of <tt>pathScope</tt> <bcp14>MUST NOT</bcp14> contain a glob metacharacter, and a universal scope is the single literal <tt>/</tt> (vector <tt>V2</tt>). A write outside <tt>pathScope</tt> <bcp14>MUST</bcp14> carry <tt>inScope</tt> of <tt>false</tt>, which is derived from the path and never a producer opinion (vector <tt>V3</tt>).</t>
        <t><tt>agreement</tt> is one of <tt>agree</tt>, <tt>disagree</tt>, <tt>not-exercised</tt>, <tt>indeterminate</tt>, <tt>one-sided</tt>, and it <bcp14>MUST</bcp14> be derivable from <tt>decision.reported</tt> and <tt>effect.observed</tt> by the table below (vectors <tt>D1</tt>, <tt>D2</tt> and <tt>D3</tt>). <tt>posture.agreement</tt> <bcp14>MUST</bcp14> be derivable from the two carried postures on the same terms: <tt>agree</tt> when they are equal byte for byte, <tt>disagree</tt> when both are present and unequal (vector <tt>F6</tt>).</t>
        <table>
          <name>Deriving agreement from the reported decision and the observed effect</name>
          <thead>
            <tr>
              <th align="left">decision.reported</th>
              <th align="left">effect.observed</th>
              <th align="left">agreement</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">
                <tt>permit</tt> or <tt>permit-with-conditions</tt></td>
              <td align="left">
                <tt>occurred</tt></td>
              <td align="left">
                <tt>agree</tt></td>
            </tr>
            <tr>
              <td align="left">
                <tt>deny</tt></td>
              <td align="left">
                <tt>none</tt></td>
              <td align="left">
                <tt>agree</tt></td>
            </tr>
            <tr>
              <td align="left">
                <tt>deny</tt></td>
              <td align="left">
                <tt>occurred</tt></td>
              <td align="left">
                <tt>disagree</tt></td>
            </tr>
            <tr>
              <td align="left">
                <tt>permit</tt> or <tt>permit-with-conditions</tt></td>
              <td align="left">
                <tt>none</tt></td>
              <td align="left">
                <tt>not-exercised</tt></td>
            </tr>
            <tr>
              <td align="left">any</td>
              <td align="left">
                <tt>unknown</tt></td>
              <td align="left">
                <tt>indeterminate</tt></td>
            </tr>
          </tbody>
        </table>
        <t>A permit allows an action and does not require it, so a permitted call that failed or was never made is <tt>not-exercised</tt>, and a deny that leaked is <tt>disagree</tt>. The two are different facts and an incident review needs to tell them apart (vector <tt>A9</tt>). An unattributed write inside <tt>pathScope</tt> leaves the observer unable to rule the request's effect in or out, so the record says <tt>indeterminate</tt> rather than choosing (vector <tt>A8</tt>).</t>
        <t>The table never produces <tt>one-sided</tt>. <tt>one-sided</tt> is in the closed set and this version never produces it, because <tt>decision</tt> and <tt>effect</tt> are both required and neither side can be absent. It is reserved so that a version admitting a record with one side missing does not have to change a closed vocabulary, and a record carrying it under this version is malformed (vector <tt>D2</tt>).</t>
        <t>A verifier <bcp14>MUST NOT</bcp14> reject a record because either agreement value is <tt>disagree</tt>, <tt>not-exercised</tt> or <tt>indeterminate</tt> (vectors <tt>A3</tt>, <tt>A8</tt> and <tt>A9</tt>). A disagreement is the record working, and what it means for admission is a consumer policy decision.</t>
      </section>
      <section anchor="evaluation">
        <name>Evaluation</name>
        <t><tt>evaluation</tt> says whether the decision point evaluated the request at all. <tt>evaluation.status</tt> is one of <tt>evaluated</tt>, <tt>not-evaluated</tt>. A decision point that could not evaluate still reports what it enforced in <tt>decision.reported</tt>, so a record from a verifier that lost an input and denied carries <tt>deny</tt>, and beside an effect of <tt>none</tt> derives <tt>agree</tt>. Without this member that record is byte-for-byte the record of a correctly enforced denial (vectors <tt>A2</tt> and <tt>A10</tt>), and an incident review cannot tell the two apart. The construction follows Section 5 of <xref target="EVALUATION"/>, which requires a verifier's own record of a refusal to make the same distinction.</t>
        <t>Under <tt>not-evaluated</tt> the member <bcp14>MUST</bcp14> carry <tt>unavailableInput</tt>, a non-empty array naming each input the decision point could not obtain, each at most once, from the closed set <tt>standing-source</tt>, <tt>key-source</tt>, <tt>consumption-state</tt> (vectors <tt>EV1</tt> and <tt>EV4</tt>). Under <tt>evaluated</tt> it <bcp14>MUST NOT</bcp14> carry <tt>unavailableInput</tt> in any spelling (vector <tt>EV2</tt>).</t>
        <t><tt>evaluation</tt> is not an input to <tt>agreement</tt>. "Could not evaluate" is not a decision, so it is not a fourth value of <tt>decision.reported</tt>, and the agreement table is unchanged: a leak during an outage is still <tt>disagree</tt>. A verifier <bcp14>MUST NOT</bcp14> reject a record because <tt>evaluation.status</tt> is <tt>not-evaluated</tt>, whatever <tt>decision.reported</tt> is. A permit recorded as <tt>not-evaluated</tt> is a decision point failing open, and the format represents it so that it can be found. The evidence class of <tt>evaluation</tt> is the one <tt>fieldEvidence</tt> declares for <tt>decision</tt>.</t>
      </section>
      <section anchor="oversight">
        <name>Oversight</name>
        <t><tt>oversight</tt> is optional. When present it records the kind of act a person took on this request before or at the decision, so that a permit bound to a user confirmation (Section 10.7 of <xref target="AIMS"/>) says whether that person observed the request, checked a stated property of it, chose, or released an action already within authority they held. The four kinds are those of <xref target="OVERSIGHT-ACTS"/>, Sections 2.3 to 2.9.</t>
        <t><tt>oversight.act</tt> is required in the member and is one of <tt>observation</tt>, <tt>check</tt>, <tt>decision</tt>, <tt>release</tt> (vector <tt>OV1</tt>). <tt>oversight.recordDigest</tt> is optional and, when present, is the digest of the overseer's own signed record, bound as <tt>delegation.authorityDigest</tt> binds the authority document. No other member is defined, and a verifier <bcp14>MUST</bcp14> reject an <tt>oversight</tt> member carrying one (vector <tt>OV2</tt>). The act is producer-asserted: its evidence class is the one <tt>fieldEvidence</tt> declares for <tt>decision</tt>, and a verifier does not resolve <tt>recordDigest</tt>.</t>
      </section>
      <section anchor="correlation-posture-and-remediation">
        <name>Correlation, posture and remediation</name>
        <t><tt>correlation.scope</tt> is one of <tt>producer</tt>, <tt>cross-party</tt>, and it is required because Section 11 asks systems to "correlate events across Agents, Tools, Services, Resources and LLMs", which a producer-scoped identifier cannot do. A record a producer distributes beyond its own deployment <bcp14>SHOULD</bcp14> carry a scope of <tt>cross-party</tt>.</t>
        <t><tt>correlation.timeBasis</tt> of <tt>beacon-anchored</tt> <bcp14>MUST</bcp14> carry <tt>externalAnchor</tt>, and <tt>asserted</tt> <bcp14>MUST NOT</bcp14> carry it (vector <tt>F5</tt>). <tt>externalAnchor.kind</tt> is one of <tt>rfc3161</tt>, <tt>transparency-log</tt>, <tt>opentimestamps</tt>, of which <xref target="RFC3161"/> and <xref target="RFC9162"/> define the first two. No offline validation rule for an anchor token is defined here, and vector <tt>N1</tt> records both readings a conforming verifier can reach.</t>
        <t><tt>posture.reported</tt> and <tt>posture.observed</tt> are over the closed set <tt>no_network</tt>, <tt>allowlist</tt>, <tt>sinkhole</tt>, <tt>unsafe_bypass_egress</tt>, each with a digest pinning the posture document. <tt>posture.assessedAt</tt> carries the time the assessment was made, which <xref target="rationale"/> gives the reason for. A consumer weighing either posture <bcp14>SHOULD</bcp14> read <tt>assessedAt</tt> beside it.</t>
        <t><tt>remediation</tt> carries one member per event. Its <tt>cause</tt> is one of <tt>session-revoked</tt>, <tt>risk-elevated</tt>, <tt>subject-disabled</tt>, <tt>token-replay-suspected</tt>, <tt>policy-changed</tt>, <tt>operator-action</tt>. Its <tt>enforcement</tt> is one of <tt>access-attenuated</tt>, <tt>session-terminated</tt>, <tt>tokens-discarded</tt>, <tt>privileges-reduced</tt>, <tt>reevaluated</tt>, <tt>not-enforced</tt>. In each member <tt>enforcedAt</tt> <bcp14>MUST</bcp14> be at or after <tt>signalReceivedAt</tt> (vector <tt>F7</tt>).</t>
        <t>A verifier <bcp14>MUST NOT</bcp14> reject a record because <tt>enforcement</tt> is <tt>not-enforced</tt> (vector <tt>A4</tt>). A record carries that value when a remediation signal arrived and enforcement did not follow it.</t>
        <t><tt>postEnforcementEffect</tt> and <tt>postEnforcementRoot</tt> make the Section 11 delay requirement checkable by a third party. A revocation that arrived, was recorded, and was followed by an observed effect is a recorded enforcement failure. This document defines no bound on the delay, because Section 11 carries no unit for "undue", and vector <tt>N2</tt> records that case as indeterminate.</t>
      </section>
      <section anchor="observation">
        <name>Observation and tier</name>
        <t><tt>observation.vantage</tt> is one of <tt>below-observed</tt>, <tt>peer</tt>, <tt>self</tt>. An observer that could not read part of <tt>pathScope</tt> <bcp14>SHOULD</bcp14> name that path in <tt>coverage.gaps</tt>, because the tier recompute below reads the gap list and not the observer's confidence. <tt>observation.priorCommitment</tt> is the observer's commitment, made before the interval opened, to the before-state and to a nonce the observer chose.</t>
        <t>Its <tt>committedAt</tt> <bcp14>MUST</bcp14> be strictly before the interval's <tt>openedAt</tt> (vector <tt>C2</tt>). Its <tt>commitmentDigest</tt> <bcp14>MUST</bcp14> recompute as the <xref target="RFC8785"/> digest over <tt>authorityDigest</tt>, <tt>beforeRoot</tt>, <tt>recordId</tt> and <tt>witnessNonce</tt> (vector <tt>C3</tt>). Its <tt>keyid</tt> <bcp14>MUST NOT</bcp14> appear in <tt>agent.signers</tt> (vector <tt>C1</tt>), and that disjointness is the one byte-pure discriminator between an observer and a self-observing party.</t>
        <t><tt>doesNotAssert</tt> is the negative-scope member the sections above refer to: an array of explicit statements about what this record does not claim. A record under this version <bcp14>SHOULD</bcp14> carry two entries. The first entry records that it makes no claim about retention. The second records that it makes no claim that the reported decision is the decision the policy engine evaluated.</t>
        <t><tt>fieldEvidence</tt> carries exactly the seven keys named in the mapping table, each one of <tt>substrate-covered</tt> or <tt>producer-asserted</tt>. Both terms are reused unchanged from the field-evidence partition registered in <xref target="VOCABULARY"/>, as the four posture values above are reused from its containment-posture terms. A missing key is malformed (vector <tt>FE1</tt>), and no key may declare <tt>substrate-covered</tt> while <tt>vantage</tt> is <tt>self</tt> (vector <tt>FE2</tt>).</t>
        <t><tt>tier</tt> is one of <tt>voluntary</tt>, <tt>authoritative</tt>. A verifier <bcp14>MUST</bcp14> recompute it and <bcp14>MUST NOT</bcp14> take the declared value as the tier. Vectors <tt>TI1</tt> through <tt>TI5</tt> each declare <tt>authoritative</tt> while failing one clause, so a verifier that reads the declared value passes all five.</t>
        <t>A record is <tt>authoritative</tt> if and only if all five of these hold, and <tt>voluntary</tt> otherwise: <tt>vantage</tt> is <tt>below-observed</tt> (vector <tt>TI1</tt>); <tt>priorCommitment</tt> is present and complete (vector <tt>TI2</tt>); <tt>pathScope</tt> is non-empty (vector <tt>TI3</tt>); <tt>coverage.scopeComplete</tt> is true or every gap names a path outside <tt>pathScope</tt> (vector <tt>TI4</tt>); and <tt>resource.binding</tt> is <tt>digest-bound</tt> (vector <tt>TI5</tt>).</t>
        <t>A record declaring <tt>authoritative</tt> that fails a clause is malformed, and a verifier <bcp14>MUST NOT</bcp14> downgrade it to <tt>voluntary</tt> (vector <tt>TI1</tt>). Downgrading would let a producer emit an authoritative-shaped record and rely on the verifier to relabel it.</t>
        <t>The opposite mismatch is well formed. A record declaring <tt>voluntary</tt> while meeting all five clauses is not malformed, and a verifier reads it at the tier the recompute gives. Treating the two directions differently is deliberate: a producer that over-claims is relying on somebody else to correct it, and a producer that under-claims is not.</t>
        <t>A verifier <bcp14>MUST NOT</bcp14> read a <tt>voluntary</tt> record as evidence that its content corresponds to any independently observed fact (vector <tt>A5</tt>).</t>
      </section>
      <section anchor="worked">
        <name>A worked reading of the example</name>
        <t>The record at the head of <xref target="members"/> reports a write that was denied and happened anyway. Each rule above lands on one of its members.</t>
        <t><tt>decision.reported</tt> is <tt>deny</tt>, and the single write is attributed to the record's own request, so <tt>effect.observed</tt> derives as <tt>occurred</tt>. The third row of the agreement table maps that pair to <tt>disagree</tt>, which is the value the record carries, so the derivation holds and vector <tt>D1</tt> does not apply.</t>
        <t><tt>posture.reported</tt> is <tt>sinkhole</tt> and <tt>posture.observed</tt> is <tt>allowlist</tt>. Both are present and they are unequal, so <tt>posture.agreement</tt> derives as <tt>disagree</tt>, which is again the carried value.</t>
        <t>The tier recompute passes all five clauses. <tt>vantage</tt> is <tt>below-observed</tt>; <tt>priorCommitment</tt> carries all five of its own members; <tt>pathScope</tt> holds one entry; <tt>coverage.scopeComplete</tt> is true with no gaps; and <tt>resource.binding</tt> is <tt>digest-bound</tt>. The declared <tt>authoritative</tt> is therefore the tier a verifier derives.</t>
        <t><tt>evaluation.status</tt> is <tt>evaluated</tt> and the member names no unavailable input, so vector <tt>EV2</tt> does not apply. The record carries no <tt>oversight</tt> member and claims nothing about a human act.</t>
        <t>The ordering checks hold on the timestamps as written. Vector <tt>C2</tt> tests the first: <tt>committedAt</tt> at 11:03:58Z falls strictly before <tt>openedAt</tt> at 11:04:01Z. Vector <tt>F7</tt> tests the second: <tt>enforcedAt</tt> at 11:04:09Z falls two seconds after <tt>signalReceivedAt</tt> at 11:04:07Z.</t>
        <t>The single write lies under <tt>/srv/ledger/</tt>, the one member of <tt>pathScope</tt>, so its <tt>inScope</tt> of true is derived from the path and vector <tt>V3</tt> does not apply. <tt>fieldEvidence</tt> carries all seven keys, so vector <tt>FE1</tt> does not apply, and <tt>vantage</tt> is not <tt>self</tt>, so vector <tt>FE2</tt> does not either.</t>
        <t>What the record says, read whole, is that a write was denied and happened anyway, that the posture the decision point read was not the posture an observer saw, and that a revocation signal was enforced two seconds after it arrived. All three are well formed, and a verifier accepts the record.</t>
      </section>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>A record is checkable for internal coherence and says nothing about the world outside its own bytes. Where a consumer needs a fact about that world, it has to establish that fact somewhere else.</t>
      <section anchor="the-vantage-claim-is-not-self-proving">
        <name>The vantage claim is not self-proving</name>
        <t>The vantage claim in a record is an assertion about the world, and the record makes it coherent with its own members without making it self-proving. A consumer that requires the vantage to be true <bcp14>MUST</bcp14> anchor the observer's key out of band, exactly as it would anchor any signer. Such a consumer <bcp14>MUST</bcp14> read <tt>authoritative</tt> as coherence with a claimed <tt>observation.vantage</tt>, and never as proof of one (vector <tt>A5</tt>).</t>
      </section>
      <section anchor="a-producer-that-observes-only-itself">
        <name>A producer that observes only itself</name>
        <t>A producer that observes only itself can satisfy every field of this format, and the <tt>observation.priorCommitment</tt> member raises the cost of doing so. It binds the before-state, the authority and the record identifier under the observer's signature before the interval opens. A forgery therefore has to be decided on before the forger knows what it will be lying about.</t>
        <t>It does not reduce the cost to zero, and a producer holding two keys satisfies every clause. That residual is detectable by a key inventory outside the record and by no function of the bytes inside it. A consumer that depends on the vantage <bcp14>SHOULD</bcp14> keep such an inventory.</t>
      </section>
      <section anchor="withheld-rows">
        <name>Withheld rows</name>
        <t>A record can omit a remediation event, or a claimed access that the observer saw, and no function of a Statement detects a row that was never written. No quantity of extra carried material changes that, because extra material is material a withholding producer also declines to carry.</t>
        <t>The <tt>coverage</tt>, <tt>fieldEvidence</tt> and <tt>doesNotAssert</tt> members exist so that a blind spot travels where the observer is honest about it. An observer that knows of a blind spot <bcp14>SHOULD</bcp14> record it in the <tt>doesNotAssert</tt> member. None of these members is a defence against a producer that conceals one.</t>
      </section>
      <section anchor="well-formed-disagreement">
        <name>Well-formed disagreement</name>
        <t>A disagreement between the reported decision and the observed effect is well formed, as is a disagreement between the two postures, and as is a remediation event recording that enforcement did not occur. A verifier <bcp14>MUST</bcp14> accept all three (vectors <tt>A3</tt> and <tt>A4</tt>). A format that refused to represent a failed enforcement would mean that no record ever reports one. This clause prevents that.</t>
      </section>
      <section anchor="a-decision-that-was-not-evaluated">
        <name>A decision that was not evaluated</name>
        <t>A record whose <tt>evaluation.status</tt> is <tt>not-evaluated</tt> is well formed beside any reported decision, and a verifier <bcp14>MUST</bcp14> accept it (vector <tt>A10</tt>). A deny that was not evaluated is a decision point failing closed, and a permit that was not evaluated is one failing open. Both are facts an audit trail exists to carry. A consumer <bcp14>SHOULD</bcp14> treat a <tt>not-evaluated</tt> permit as an enforcement failure for policy purposes, and this document leaves that to the consumer.</t>
      </section>
      <section anchor="revocation-without-a-bound">
        <name>Revocation without a bound</name>
        <t>Section 11 of <xref target="AIMS"/> requires that revoked or downgraded authorization be enforced "without undue delay" and specifies no bound. This document carries <tt>signalReceivedAt</tt> and <tt>enforcedAt</tt>, and defines no bound of its own. A record with an arbitrarily large gap between them is well formed. A consumer <bcp14>SHOULD</bcp14> set a bound on that gap as policy and read a record that exceeds it accordingly.</t>
      </section>
      <section anchor="relationship-to-other-tamper-evidence-mechanisms">
        <name>Relationship to other tamper-evidence mechanisms</name>
        <t>A signature over canonical bytes detects an editor who cannot sign. A trusted timestamp <xref target="RFC3161"/> adds an assertion about when the bytes existed, and an append-only log <xref target="RFC6962"/> <xref target="RFC9162"/> adds an assertion that they were published. This document requires neither, and a deployment <bcp14>MAY</bcp14> carry a record under this format in such a log.</t>
        <t>None of the three detects a producer that signed a false record. The recomputes in <xref target="tamper"/> address that case.</t>
      </section>
      <section anchor="two-implementations-that-both-differ-from-the-canonical-form">
        <name>Two implementations that both differ from the canonical form</name>
        <t><xref target="rationale"/> gives the mechanism by which two implementations can share a serialization that is not <xref target="RFC8785"/>. Neither party can see the failure from inside it. Every signature each of them produces verifies for the other, and the records fail only for a third party that canonicalizes correctly.</t>
        <t>A consumer therefore derives the canonical bytes itself and does not accept a producer's report of them. <xref target="canonical"/> is normative for that reason, and vector <tt>T2</tt> is the member that tests it.</t>
      </section>
    </section>
    <section anchor="privacy-considerations">
      <name>Privacy Considerations</name>
      <t>A record under this document carries an agent identifier, a delegated subject, a resource identifier and a set of paths. The delegated subject in particular may identify a natural person. Deployments <bcp14>SHOULD</bcp14> consider which of these a given consumer needs before distributing a record. The <tt>doesNotAssert</tt> member is the place to record what a distributed record deliberately omits.</t>
      <t>The format binds five documents by digest and carries none of them: the credential, the authority document, the policy, and both posture documents. A consumer that needs their content <bcp14>SHOULD</bcp14> resolve them out of band.</t>
      <t>That separation is deliberate and is the privacy-preserving default, because it lets a record travel to a party entitled to verify the decision without carrying the material the decision was made from. A consumer entitled to the decision receives the digest and resolves the document only if it needs the content.</t>
    </section>
    <section anchor="iana">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions. The predicate type is a URI under a namespace the author controls and requires no registration to be used, consistent with the in-toto Attestation Framework's treatment of predicate type identifiers <xref target="IN-TOTO"/>.</t>
      <t>A registered identifier would be the alternative. It is not proposed here, because a record carries its predicate type inside the bytes its producer signed. A later revision <bcp14>SHOULD NOT</bcp14> move the URI once records carrying it exist, since moving it invalidates every signature over them.</t>
    </section>
  </middle>
  <back>
<references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="AIMS">
          <front>
            <title>AI Identity Management System</title>
            <author fullname="Pieter Kasselman" initials="P." surname="Kasselman">
              <organization>Defakto Security</organization>
            </author>
            <author fullname="Jeff Lombardo" initials="J." surname="Lombardo">
              <organization>AWS</organization>
            </author>
            <author fullname="Yaroslav Rosomakho" initials="Y." surname="Rosomakho">
              <organization>Zscaler</organization>
            </author>
            <author fullname="Brian Campbell" initials="B." surname="Campbell">
              <organization>Ping Identity</organization>
            </author>
            <author fullname="Nick Steele" initials="N." surname="Steele">
              <organization>OpenAI</organization>
            </author>
            <author fullname="Aaron Parecki" initials="A." surname="Parecki">
              <organization>Okta</organization>
            </author>
            <date day="15" month="September" year="2026"/>
            <abstract>
              <t>This document proposes best practices for authentication and authorization of AI agent interactions. It leverages existing standards such as the Workload Identity in Multi-System Environments (WIMSE) architecture and OAuth 2.0 family of specifications. Rather than defining new protocols, this document describes how existing and widely deployed standards can be applied or extended to establish agent authentication and authorization. By doing so, it aims to provide a framework within which to use existing standards, identify gaps and guide future standardization efforts for agent authentication and authorization.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-wimse-aims-00"/>
        </reference>
        <reference anchor="WIMSE-ID">
          <front>
            <title>Workload Identifier</title>
            <author fullname="Yaroslav Rosomakho" initials="Y." surname="Rosomakho">
              <organization>Zscaler</organization>
            </author>
            <author fullname="Joseph A. Salowey" initials="J. A." surname="Salowey">
              <organization>Palo Alto Networks</organization>
            </author>
            <date day="6" month="July" year="2026"/>
            <abstract>
              <t>This document defines a canonical identifier for workloads, referred to as the Workload Identifier. A Workload Identifier is a URI that uniquely identifies a workload within the context of a specific trust domain. This identifier can be embedded in Workload Identity Credentials, including X.509 certificates and JWT-based tokens, to support authentication, authorization, and policy enforcement across diverse systems. The Workload Identifier format ensures interoperability, facilitates secure identity federation, and enables consistent identity semantics.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ietf-wimse-identifier-03"/>
        </reference>
        <reference anchor="RFC3339">
          <front>
            <title>Date and Time on the Internet: Timestamps</title>
            <author fullname="G. Klyne" initials="G." surname="Klyne"/>
            <author fullname="C. Newman" initials="C." surname="Newman"/>
            <date month="July" year="2002"/>
            <abstract>
              <t>This document defines a date and time format for use in Internet protocols that is a profile of the ISO 8601 standard for representation of dates and times using the Gregorian calendar.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3339"/>
          <seriesInfo name="DOI" value="10.17487/RFC3339"/>
        </reference>
        <reference anchor="RFC7493">
          <front>
            <title>The I-JSON Message Format</title>
            <author fullname="T. Bray" initials="T." role="editor" surname="Bray"/>
            <date month="March" year="2015"/>
            <abstract>
              <t>I-JSON (short for "Internet JSON") is a restricted profile of JSON designed to maximize interoperability and increase confidence that software can process it successfully with predictable results.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="7493"/>
          <seriesInfo name="DOI" value="10.17487/RFC7493"/>
        </reference>
        <reference anchor="RFC8785">
          <front>
            <title>JSON Canonicalization Scheme (JCS)</title>
            <author fullname="A. Rundgren" initials="A." surname="Rundgren"/>
            <author fullname="B. Jordan" initials="B." surname="Jordan"/>
            <author fullname="S. Erdtman" initials="S." surname="Erdtman"/>
            <date month="June" year="2020"/>
            <abstract>
              <t>Cryptographic operations like hashing and signing need the data to be expressed in an invariant format so that the operations are reliably repeatable. One way to address this is to create a canonical representation of the data. Canonicalization also permits data to be exchanged in its original form on the "wire" while cryptographic operations performed on the canonicalized counterpart of the data in the producer and consumer endpoints generate consistent results.</t>
              <t>This document describes the JSON Canonicalization Scheme (JCS). This specification defines how to create a canonical representation of JSON data by building on the strict serialization methods for JSON primitives defined by ECMAScript, constraining JSON data to the Internet JSON (I-JSON) subset, and by using deterministic property sorting.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8785"/>
          <seriesInfo name="DOI" value="10.17487/RFC8785"/>
        </reference>
        <reference anchor="IN-TOTO" target="https://github.com/in-toto/attestation/blob/main/spec/README.md">
          <front>
            <title>in-toto Attestation Framework Specification</title>
            <author>
              <organization>in-toto</organization>
            </author>
            <date year="2026"/>
          </front>
        </reference>
        <reference anchor="DSSE" target="https://github.com/secure-systems-lab/dsse">
          <front>
            <title>Dead Simple Signing Envelope</title>
            <author>
              <organization>Secure Systems Lab</organization>
            </author>
            <date year="2026"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="EVALUATION">
          <front>
            <title>Verifier-Side Evaluation Semantics for Delegated Authority Chains</title>
            <author fullname="Wes Jackson" initials="W." surname="Jackson"/>
            <date day="30" month="September" year="2026"/>
            <abstract>
              <t>Delegation chain specifications describe the shape of conveyed authority. They leave the verifier's half of the exchange underdetermined. Two verifiers can check the same chain, both report success, and enforce different policy. This document states what a verifier must do: the explicit inputs evaluation depends on, how those inputs behave when their sources are stale or unavailable, and four rules that keep evaluation fail-closed. The rules are drawn from the Grant &amp; Autonomy Lifecycle (GAL) and Provenance &amp; Trust Context (PTC) specifications and from a public reference implementation.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-jackson-wimse-evaluation-03"/>
        </reference>
        <reference anchor="OVERSIGHT-ACTS">
          <front>
            <title>Terminology for Human Oversight Acts in Automated and Agentic Systems</title>
            <author fullname="Andreas Ehstand" initials="A." surname="Ehstand">
              <organization>Independent Researcher</organization>
            </author>
            <date day="26" month="September" year="2026"/>
            <abstract>
              <t>Records produced by automated and agentic systems often represent human oversight as a single, undifferentiated event, such as an approval flag or a confirmation. Such a record does not say whether the person was shown an output, determined whether a named property of it holds, chose a course of action, or permitted an action, and consumers of the record may treat a confirmation click as if it were a check. This document defines terms for four kinds of human oversight act (observation, check, decision, and release) and for related concepts: the oversight act and the overseer, the named property, standing authority, the oversight record, the undifferentiated approval, the check step, error detectability, the fail-open check step, and the check test. It states what a record of each kind of act is, and is not, evidence of, and relates the terms to existing vocabularies. The document defines terminology only. It specifies no protocol, data format, procedure, or measurement method.</t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-ehstand-oversight-acts-00"/>
        </reference>
        <reference anchor="RFC3161">
          <front>
            <title>Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)</title>
            <author fullname="C. Adams" initials="C." surname="Adams"/>
            <author fullname="P. Cain" initials="P." surname="Cain"/>
            <author fullname="D. Pinkas" initials="D." surname="Pinkas"/>
            <author fullname="R. Zuccherato" initials="R." surname="Zuccherato"/>
            <date month="August" year="2001"/>
            <abstract>
              <t>This document describes the format of a request sent to a Time Stamping Authority (TSA) and of the response that is returned. It also establishes several security-relevant requirements for TSA operation, with regards to processing requests to generate responses. [STANDARDS-TRACK]</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="3161"/>
          <seriesInfo name="DOI" value="10.17487/RFC3161"/>
        </reference>
        <reference anchor="RFC6962">
          <front>
            <title>Certificate Transparency</title>
            <author fullname="B. Laurie" initials="B." surname="Laurie"/>
            <author fullname="A. Langley" initials="A." surname="Langley"/>
            <author fullname="E. Kasper" initials="E." surname="Kasper"/>
            <date month="June" year="2013"/>
            <abstract>
              <t>This document describes an experimental protocol for publicly logging the existence of Transport Layer Security (TLS) certificates as they are issued or observed, in a manner that allows anyone to audit certificate authority (CA) activity and notice the issuance of suspect certificates as well as to audit the certificate logs themselves. The intent is that eventually clients would refuse to honor certificates that do not appear in a log, effectively forcing CAs to add all issued certificates to the logs.</t>
              <t>Logs are network services that implement the protocol operations for submissions and queries that are defined in this document.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="6962"/>
          <seriesInfo name="DOI" value="10.17487/RFC6962"/>
        </reference>
        <reference anchor="RFC9162">
          <front>
            <title>Certificate Transparency Version 2.0</title>
            <author fullname="B. Laurie" initials="B." surname="Laurie"/>
            <author fullname="E. Messeri" initials="E." surname="Messeri"/>
            <author fullname="R. Stradling" initials="R." surname="Stradling"/>
            <date month="December" year="2021"/>
            <abstract>
              <t>This document describes version 2.0 of the Certificate Transparency (CT) protocol for publicly logging the existence of Transport Layer Security (TLS) server certificates as they are issued or observed, in a manner that allows anyone to audit certification authority (CA) activity and notice the issuance of suspect certificates as well as to audit the certificate logs themselves. The intent is that eventually clients would refuse to honor certificates that do not appear in a log, effectively forcing CAs to add all issued certificates to the logs.</t>
              <t>This document obsoletes RFC 6962. It also specifies a new TLS extension that is used to send various CT log artifacts.</t>
              <t>Logs are network services that implement the protocol operations for submissions and queries that are defined in this document.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="9162"/>
          <seriesInfo name="DOI" value="10.17487/RFC9162"/>
        </reference>
        <reference anchor="VECTORS" target="https://github.com/probityai/agent-evidence-vectors">
          <front>
            <title>Agent evidence conformance vectors</title>
            <author>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
        <reference anchor="VOCABULARY" target="https://github.com/probityai/agent-evidence-vocabulary">
          <front>
            <title>Agent evidence vocabulary</title>
            <author>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
      </references>

<section anchor="rationale">
      <name>Design rationale</name>
      <t>Two requirements of this document are not derivable from Section 11 of <xref target="AIMS"/> on its own: the canonicalization contract, and carrying the observed effect beside the reported decision. Neither is restated normatively here.</t>
      <section anchor="the-canonicalization-contract">
        <name>The canonicalization contract</name>
        <t>The word "tamper-evident" appears once in <xref target="AIMS"/> and is not defined there. Read narrowly it means a record whose alteration is detectable, which a signature provides. Two gaps remain.</t>
        <t>A signature over a serialization is only as good as the agreement on which bytes were signed, and that agreement is a property of a written contract between two implementations; neither one's code establishes it. Two implementations can agree with each other on a canonical form and both differ from <xref target="RFC8785"/>, and no amount of signing or hash-chaining detects that.</t>
        <t>Each verifies its own records and rejects the other's, or worse, accepts a record whose meaning it has silently changed. A canonicalization contract is therefore part of the tamper-evidence requirement; it is not an implementation detail, and <xref target="canonical"/> makes it normative.</t>
        <t>A signature also says nothing about the producer. The party that holds the signing key can alter a record and sign it again, and every signature check still passes.</t>
        <t>Detecting that requires fields whose values are recomputable from other fields in the same record, so that an internally inconsistent record is refusable regardless of who signed it. A hash chain catches an alteration by a party with no signing key; only a recompute catches the key holder, and <xref target="tamper"/> specifies three of them.</t>
      </section>
      <section anchor="the-decision-and-the-observed-effect">
        <name>The decision and the observed effect</name>
        <t>The fourth of the seven minimum fields pairs "action requested and authorization decision". A record carrying only the decision is a self-report: it states what an enforcement point concluded, and a deployment that mis-enforces its own conclusion produces a clean audit trail of the decision it failed to apply. Section 11 asks for enough to "reconstruct agent behavior and authorization context after execution", and behaviour is not reconstructable from a decision.</t>
        <t>This document therefore requires both sides in one record: the decision as reported by the enforcement point, and the effect as observed. It also requires a three-valued <tt>agreement</tt> between them, which a verifier derives from the two values; it is not a claim the record makes. A decision reported as denied beside an effect observed as having occurred is then a refusable inconsistency in signed bytes. Today it is undetectable.</t>
        <t>The same construction applies to the sixth field. Section 8 of <xref target="AIMS"/> defines posture assessment as an evaluation performed at credential provisioning, while the sixth field asks for the posture "influencing the decision".</t>
        <t>A conformant record may therefore carry a posture that was accurate at issuance and inaccurate at decision time, with nothing in the record to say which. Carrying <tt>posture</tt> as the decision point read it, beside the posture as it was observed and its <tt>assessedAt</tt>, makes that difference visible without constraining either value.</t>
      </section>
      <section anchor="why-the-tier-carries-five-clauses">
        <name>Why the tier carries five clauses</name>
        <t>Each clause of the tier recompute closes one route by which a record could claim an observer's vantage while carrying nothing that distinguishes it from a self-report.</t>
        <t><tt>vantage</tt> of <tt>below-observed</tt> is the claim itself, and the four clauses under it make the claim cost something. The prior commitment binds the before-state before the interval opens, so a producer cannot decide after the fact what it saw. A non-empty <tt>pathScope</tt> means the record names the ground it covers. A complete coverage claim, or a gap list naming only paths outside that ground, means the record does not quietly exclude the interesting part. And a digest-bound resource means the arguments of the call are pinned.</t>
        <t>Dropping any one of them admits a record that carries the authority of the rest while resting on nothing. That is why the corpus in <xref target="vectors"/> carries one reject member per clause.</t>
      </section>
    </section>
    <section anchor="vectors">
      <name>Conformance vectors</name>
      <t>The table below is the conformance corpus for this format. Each row gives a member identifier, the accept member it derives from, its input, and the verdict a conforming verifier reaches. A reject differs from the accept member in its <tt>from</tt> column by one mutation, so refusing every input scores nothing on this corpus.</t>
      <t>An accept member has no parent and its <tt>from</tt> column reads <tt>root</tt>. An indeterminate member has more than one conforming verdict and its row gives each.</t>
      <t>Every row names the rule it tests. Three rules this document adds have no member in the table: the binding on the digest map in <xref target="subject"/>, the <xref target="RFC3339"/> requirement in <xref target="timestamps"/>, and the single hash algorithm of <xref target="hashalg"/>. An implementation <bcp14>SHOULD</bcp14> be run against every member of the corpus before it is described as conforming to this document, and the three rules above are checked by reading them.</t>
      <t>The corpus travels with the predicate schema: the revision of this document that freezes the predicate type URI is the revision that publishes these members in <xref target="VECTORS"/>, in that repository's manifest layout.</t>
      <table>
        <name>The conformance corpus, one member for every normative rule this document adds</name>
        <thead>
          <tr>
            <th align="left">id</th>
            <th align="left">from</th>
            <th align="left">what it is</th>
            <th align="left">expected</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">root</td>
            <td align="left">every member present, <tt>permit</tt> beside <tt>occurred</tt>, all five tier clauses met</td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A2</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>deny</tt> beside <tt>none</tt>, equal roots, empty write set</td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A3</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>deny</tt> beside <tt>occurred</tt> and <tt>agreement</tt> of <tt>disagree</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> plus a remediation event with <tt>enforcement</tt> of <tt>not-enforced</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A5</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>vantage</tt> of <tt>self</tt>, no prior commitment, <tt>tier</tt> of <tt>voluntary</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>binding</tt> of <tt>not-bindable</tt>, <tt>argumentsDigest</tt> absent from the record and from the request-digest preimage, <tt>tier</tt> of <tt>voluntary</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>A7</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A2</tt> plus one in-scope write inside the interval attributed to a different request, roots and chain moved to match</td>
            <td align="left">valid, <tt>agreement</tt> of <tt>agree</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>A8</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A2</tt> plus one in-scope <tt>unattributed</tt> write inside the interval, <tt>effect.observed</tt> of <tt>unknown</tt></td>
            <td align="left">valid, <tt>agreement</tt> of <tt>indeterminate</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>A9</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> with <tt>permit</tt> beside an empty write set, equal roots, <tt>effect.observed</tt> of <tt>none</tt></td>
            <td align="left">valid, <tt>agreement</tt> of <tt>not-exercised</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>A10</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A2</tt> with <tt>evaluation.status</tt> of <tt>not-evaluated</tt> and <tt>unavailableInput</tt> of <tt>standing-source</tt></td>
            <td align="left">valid, <tt>agreement</tt> of <tt>agree</tt></td>
          </tr>
          <tr>
            <td align="left">
              <tt>A11</tt></td>
            <td align="left">root</td>
            <td align="left">
              <tt>A1</tt> plus <tt>oversight</tt> with <tt>act</tt> of <tt>check</tt> and a <tt>recordDigest</tt></td>
            <td align="left">valid</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>A1</tt> with the whole <tt>agent</tt> member removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>subjectKind</tt> of <tt>none</tt> beside a named subject</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>digest-bound</tt> with <tt>argumentsDigest</tt> removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F3b</tt></td>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">
              <tt>not-bindable</tt> carrying <tt>argumentsDigest</tt> of <tt>null</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F3c</tt></td>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">
              <tt>not-bindable</tt> carrying <tt>argumentsDigest</tt> of the empty string</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F4</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>action</tt> changed, <tt>requestDigest</tt> left at its original value</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F5</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>beacon-anchored</tt> with <tt>externalAnchor</tt> removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F6</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">two unequal postures declared as <tt>agree</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>F7</tt></td>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">
              <tt>enforcedAt</tt> one second before <tt>signalReceivedAt</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>effect.observed</tt> edited to <tt>none</tt>, writes intact, signed again with the real key</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">serialized in declaration order, not <xref target="RFC8785"/> order</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a member name repeated at depth three</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T4</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">nesting 129 levels deep</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>T5</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">an integer of magnitude exactly 2^53</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>D1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>agreement</tt> of <tt>disagree</tt> with both sides agreeing</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>D2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>agreement</tt> of <tt>one-sided</tt> with both values present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>D3</tt></td>
            <td align="left">
              <tt>A9</tt></td>
            <td align="left">
              <tt>agreement</tt> of <tt>disagree</tt> beside <tt>permit</tt> and <tt>none</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>S1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">second subject entry removed, interval left present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>S2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">second subject entry's digest set to the before-state root</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>I1r</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">interval removed, second subject entry left present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with <tt>vantage</tt> of <tt>self</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with no prior commitment</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with an empty <tt>pathScope</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI4</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared with a coverage gap inside <tt>pathScope</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>TI5</tt></td>
            <td align="left">
              <tt>A6</tt></td>
            <td align="left">
              <tt>authoritative</tt> declared on <tt>A6</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>C1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">commitment <tt>keyid</tt> added to <tt>agent.signers</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>C2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>committedAt</tt> one second after <tt>openedAt</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>C3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>witnessNonce</tt> changed, <tt>commitmentDigest</tt> left at its original value</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>E1</tt></td>
            <td align="left">
              <tt>A2</tt></td>
            <td align="left">
              <tt>observed</tt> of <tt>none</tt> with a non-empty write set</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>E2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a second write whose pre-state is not the first write's post-state</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>E3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">
              <tt>empty-tree</tt> under sha256 carrying the sha1 constant</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>V1</tt></td>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">
              <tt>enforcement</tt> of <tt>quarantined</tt>, outside the closed set</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>V2</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a <tt>pathScope</tt> member carrying a glob metacharacter</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>V3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">a write outside <tt>pathScope</tt> carrying <tt>inScope</tt> of <tt>true</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>FE1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">six of the seven <tt>fieldEvidence</tt> keys present</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>FE2</tt></td>
            <td align="left">
              <tt>A5</tt></td>
            <td align="left">
              <tt>substrate-covered</tt> declared beside <tt>vantage</tt> of <tt>self</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>EV1</tt></td>
            <td align="left">
              <tt>A10</tt></td>
            <td align="left">
              <tt>not-evaluated</tt> with <tt>unavailableInput</tt> removed</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>EV2</tt></td>
            <td align="left">
              <tt>A2</tt></td>
            <td align="left">
              <tt>evaluated</tt> carrying <tt>unavailableInput</tt> of <tt>standing-source</tt></td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>EV3</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">the <tt>evaluation</tt> member removed, which is the shape of a revision 01 record</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>EV4</tt></td>
            <td align="left">
              <tt>A10</tt></td>
            <td align="left">
              <tt>unavailableInput</tt> of <tt>network</tt>, outside the closed set</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>OV1</tt></td>
            <td align="left">
              <tt>A11</tt></td>
            <td align="left">
              <tt>oversight.act</tt> of <tt>approval</tt>, outside the closed set</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>OV2</tt></td>
            <td align="left">
              <tt>A11</tt></td>
            <td align="left">
              <tt>oversight</tt> carrying a member this document does not define</td>
            <td align="left">malformed</td>
          </tr>
          <tr>
            <td align="left">
              <tt>N1</tt></td>
            <td align="left">
              <tt>A1</tt></td>
            <td align="left">an anchor token digest carried with no offline validation rule defined</td>
            <td align="left">indeterminate</td>
          </tr>
          <tr>
            <td align="left">
              <tt>N2</tt></td>
            <td align="left">
              <tt>A4</tt></td>
            <td align="left">enforcement forty days after the signal, ordering intact</td>
            <td align="left">indeterminate</td>
          </tr>
        </tbody>
      </table>
    </section>
    <section numbered="false" anchor="document-history">
      <name>Document History</name>
      <t>Changes in -02:</t>
      <ul spacing="normal">
        <li>
          <t>A required <tt>evaluation</tt> member records whether the decision point evaluated the request, and under <tt>not-evaluated</tt> names the unavailable inputs from a closed set (<xref target="evaluation"/>). Under -01 a verifier that lost its standing source and denied wrote a record identical to a correctly enforced denial. <tt>decision.reported</tt> and the agreement table are unchanged.</t>
        </li>
        <li>
          <t>An optional <tt>oversight</tt> member records the kind of act a person took behind a decision, and may bind the overseer's own signed record by digest (<xref target="oversight"/>).</t>
        </li>
        <li>
          <t>A record conforming to -01 is malformed under -02, because it carries no <tt>evaluation</tt> member and no member has a default (vector <tt>EV3</tt>). The predicate type URI does not change: no revision has yet frozen it, and the corpus in <xref target="VECTORS"/> is regenerated against this revision.</t>
        </li>
        <li>
          <t>Eight members are added to <xref target="vectors"/>: <tt>A10</tt>, <tt>A11</tt>, <tt>EV1</tt> to <tt>EV4</tt>, <tt>OV1</tt> and <tt>OV2</tt>.</t>
        </li>
      </ul>
      <t>Changes in -01:</t>
      <ul spacing="normal">
        <li>
          <t>The request-digest preimage under <tt>not-bindable</tt> is stated: three members, with no <tt>argumentsDigest</tt> member in any spelling. Under -00 the text named four members and forbade the fourth, so the preimage was open and three spellings gave three digests.</t>
        </li>
        <li>
          <t>Each write carries the request digest it is attributed to, or <tt>unattributed</tt>. <tt>effect.observed</tt> describes this record's request, and it gains <tt>unknown</tt> for an unattributed write inside the scope. A write that belongs to another request no longer changes this record's agreement.</t>
        </li>
        <li>
          <t><tt>agreement</tt> gains <tt>not-exercised</tt>, for a permit beside no effect, and <tt>indeterminate</tt>, for an effect the observer could not attribute. Under -00 a permitted call that was never made read as <tt>disagree</tt>, the value a leaked deny also takes.</t>
        </li>
        <li>
          <t>A statement whose signature fails is malformed, so <xref target="verifying"/> and vector <tt>T2</tt> report the same verdict.</t>
        </li>
        <li>
          <t>Six members are added to <xref target="vectors"/>: <tt>A7</tt>, <tt>A8</tt>, <tt>A9</tt>, <tt>F3b</tt>, <tt>F3c</tt> and <tt>D3</tt>.</t>
        </li>
      </ul>
      <t>-00 was the first revision.</t>
    </section>
    <section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>Cliff Singletary pointed out that -01 could not record a decision point that was unable to evaluate, and proposed the separate member that leaves <tt>decision.reported</tt> and the agreement table untouched. Andreas Ehstand asked whether the human act behind a permit belongs in this format and proposed the member that names its kind.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA6V963rbyJXgfz4Flv7R6V6SsiRf1ZOZUSw58Wzb7rXUnS+Z
yYQgWZLQBgEGBUpmbOdZ9ln2yfZcq04BoOzOzjczLYNAXc/9Op1OR23Rlu4k
G59W2el2VbTZO7esm1X2sm7WeZtd1U12+io7vXZVCy+0N3VT/D1vi7rKztyy
8PCHH4/yxaJxtziKvBcHGo+Weeuu62Z3khXVVT0areplla9hzlWTX7XT66Jc
5dO7Yu3dNMfPpzl+Pm3o8+nDo5HfLtaFx6na3Qa+e3V++XJUbdcL15yMVjD6
yWgJy3CV3/qTrG22bgRrOR7ljctxTZtNWSxpzT7LqxUsLC+nl8XajUd3dfP+
uqm3G3jvj/B3Weer7NUKVlG0O1hv9npbtkV2sfOtW2fn1W3R1NUafoZNv3c7
+Hx1MsqmGS2Z/sAd0B9t63xLs+I/23y9cc3U3RY4+OjWVVtYdpb9s5NnGZ8F
fVhU19nvcSB8vs6LEp7Tgf574dqrWd1c4w95s7yBH27aduNPDg7wPXxU3LqZ
vnaADw4WTX3n3QGNcDAejXK6dtwnjJJlV9uy5AscX+TV+7zcZL/HOxzTr07m
9/zTjK7336/x6WxZr2G4iiALpsX9n756fQE3Oj2jNSgYwP+H3/4Iv51PX531
fqczLK4K18Bb716+OD4+fn7Cfz599PxY/nz29Nlj/PPVm+nl28u3J7Q8Bfei
mrZ1W2en8Zqylw3sCiEiu9gAbF8J0PC+2ry5du1Jpsd3XbQ32wVu6UDGOjBX
frAo6wUecXXgYayDd+enZ6/PZ+sVjRUOlP5nmsHJxyXxdATW2dHDoyfwz7OL
i/N0+WcOQOWiWG9KB/+5rhACAEBcWW/cF9fr3XLbuKknuPLTMl8crLx39yzt
gr4QSPTZD/mit8oRIre52POfT3/46fTy1ds3fH2/5Mv3vq7kBt1tXm4FObK3
P5+/u3j1+z9cTk9fXAo0uBs4yWo1rW9d44vrG6AKy9bLdR8+OZQ7fvL8yZH8
+fyQ//z5/MXl23cX6XkxXWLsW7oMyAUtFv++dcu2bvwXT23T1AvAy7w4YCql
g01lAJz67YvT3/30w+m7P907+229zBdbQL7d/8ekYYzRaDoFcrPwbQNHNBpd
3hQ+Axq7RUqRrdxVUTmgexnT0+wqoes0qly60vWV0vVZdnnj9AMYtK5cpniz
adwK8cMRHZpkcEeVW8HPHhYIsyHIZk4gcpa9arNl3jQFrKSFMb0DApiti6pY
b9dMPDNA53KFP8Nk+A5hP64xUMTXeQXrpW0JTbwKGNu4v22LxvkJUfj2DlcI
MzctTwljrvP3sNib2judannjlu/zBV5RDsur6gp2VOoxAIzQifKIi7q9oWUN
nxXPCj/XC++aWzgJd3UFcJHdwV3C6CvXFPi0vWkcXB4AP/wjv4Z/0HYWrr1z
cCIwwhpPHS8obG1T5ks5t/QO6y3831Xml7BRXgBs0WdVnb06fXOawdphZTic
BQi/RXYo4/FAdD0KKPD1pgZ+uZsxYK2L1ap0o9GD7BWcR73a0qj7wAxBpA9o
fG54yXjvrVwIEBU6w8ND3MXHj8gKPn/u3GRhV9beIJ1zpWeI8kyl7aKzdb1y
5QQfAPrARgnFl03RwgXkNCL81LgWQQrmbralixPVPEvmPsDvK6B9GdwB/KFr
m+G2XXZd5yVgVAN0bvRdBshAoJVXskfdf1Ov6TxWblPWOzomXFPeIMgxYODP
9F6Om3PN92a8cSoyjAGKBKR38CeQRWKACLcZsh0Yi855sYN/4W5uaoBxGRBx
b/fPgC8IIbhGwW7eGSB7jSBd+GEARlKxghNetrhRWcE1gP8A6gsmwv3vgQac
fe1Q1MtcvryBG/iRL3oBlKW69jh2bo6YL7NL7czLMH2zw1HvbursJqdnDXLT
iF+AMkA/iLnikCI5EsziGjIPT/zVzi65oK0XTVbfVTrphrBFIR9oSVHKKHBn
CGYLJwDh4Exh4saVQFBh9cum9kiy8S4KGGFRb6sVkPoJgiRRLXhrgWAAH7c7
oZnN1gNqVa5ASNLZm5ldZu7fe8LIvCyZFsGBvohAieeRZxVAS30Hx56TXAGj
OT4SPh4C/QSUb+BGcxivgBPnFSHw4bdENhFEEdJWgGoE7RFOc7gXeAoj0KLh
/+3gVQ8IuxBwAQwkkgAgnrwHZx0YFVNSvnp9RY7hDnbkkNkv3UrQl3QFGBAp
A4Aq/HOJBOGEuEaEJHvjcC43BFS0DgB9wI4G3il3epe/1AEE9JQQrcwn17QD
Rh1XumvGQIYHvG+80g4W4UgV8PUtoxJCmV5vWV/DdvYgTYFkTGQxkAyQT+BZ
ug8FcE3cNrysnD9SLFaOfFHSD/oVbAjhmQiukmZe9die1eufLi4DxK+2DBg8
OiwVTxkpFkDEHlmD594u+GZwqjUIGIx644lMeJqslqZEMEnoJA0E9wmiN6ES
vovzApoz+QFJFoUJ4RdwEvg4bmUsEgROmPAsoShD9MvexBGOV1mmbTkTjR24
5gAfBwhBgoMLFkFoR+g2RiDDJayRI+HOEFNZciSMJnE5h73KySJ/IZAEYPCJ
OmMowrGuc4hZpsvChYfvnoRLSIUNEBk/fmxomrx0AInewckp/O0VsQL7AULs
hY99kTUxTVcOJZQb5ZQXdXXL7J2h6gzlh4L+zQQAFPfsjlY/RhiCG6f/Zm/e
0t/vzv/3T6/enZ/h3xd/OP3hh/DHSN64+MPbn344i3/FL1+8ff36/M0ZfwxP
s+TRaPz69E8CYOO3P6JydPrDONNrCnCBFw7wukCMh7vYIHnCGx8paURBO/vd
ix//7/85fAQn/j9A/Tk6PHwOB87/eHb49BH8Awkzz1ZXQKr4nwhSo3yzcXmD
oyAnWOabogWZZoJQ5W+QhxHRB/HmP/Fk/nKS/ctiuTl89K/yADecPNQzSx7S
mfWf9D7mQxx4NDBNOM3keeek0/We/in5t567efgv/1YCtcimh8/+7V9HCEKX
rgEMr4Fy7RhkruqyrO8ILeEn5oBbzwJ9vb2+YRA3d8gMk6nLepJ9J9DbfEfX
8V2A7g3wjfa7CQ3Igu6Kzv57wQcv0AASYRWZp84C+Af8ERkHqV2kPoxGpG5O
ssu6Bkn4gmWISfbO+Xrb4F8//PD6ZHSCdx04BuzFJ59n0cZC74o6Fp/i57pg
AKOPH9VaQ2LyBRAxx/IYEPVfHKpRQWUMk4tlpjP/WzkqfI3oZ5RxhMEYdRYE
I5IHkqM/rZRaoADQgsTkRczOynznRCGhbQr7zlcrOGsgX6cguvh2Ssd5W7g7
YpXZNfHwK2CNbDSB+8puQO+Fo/V1My2BJ5QsRcLr/DKScSGb711TuVLeAv2L
PsPLRxJ2lxI32CHsjwHMb0H0oAV72hPo3vpzWSwaEgjz7K5BZLZ7AmB+L+oT
SF4gx9YNQG2QyUTX4HP9xiN/pungMZz+WQKZA3cgphu3GtAnjKAGb+DxF60n
w2OB+sCWaMorpGkwSBgbuE2dCD/wN7A0N6UzDAwgv4Lv5BmtxCibJF4gH74s
IuCsHIqFSEnvborlTQAa2DOSOFYrPEne9aJucFxcNypPyxJtkCIFAUHEZyhK
6j0hoAQVjJV7ZvYtPlCgdKRfMnrwl3RMAO+kiNIBIdSQvhaQO7Cyc1RVRHLs
Mwn4+w5YdYuyN17inWuWuQcZ3n3Ikbys81LUEqDx13BH7Y0dHxlsmaMwBy/h
Lc1RyD3VN+dyPMRRE8dAYhsFaqHjFZ6gTexDgQAkaM42ICIYHRMRvIb/BuIB
giYsJhCLS0CzOQw+Gv3jH/8Y/Tb+DzKH85Ns/F/jjKg34QHCNyID8MDs2dPn
R5n54LejkVrYglltJra2ot5j1TsICzm4PTz4r1HfQ0HrAvkPZQ6EXxGSV8ZE
ppDGnBiwfcMSkmq2lvgTsMgHeBrnqH+IlOrDJKQcyDzbqiSKEYCNkMOLrLYm
mxCCdF2tCp6X7CMyN6t8MHu+LYP2HEBbmT2bjXZssED9sUKLI16vDPMbOa9s
/vJwTqPMz38+nn/LfDAcACmOYR2sIvliUeK9kVVsks0bYVQzEG6Zy50RCsiw
qiijbQsNNQ0MdFotgQrNefmksUWp15FOCBMXLVsm6JzZttm9CPh9HizO8+w3
gLb6r8+fv/2eqRnue4ma6S7apJhQqO6ZIwyiIAuyLamdp50TbRyyRDxo3DMK
yGw2rUCfLGuUK6J9t4P2Yg3jrYbrKa5B4WONOb2QbP7zId0Cyt+dodFy1jhg
vSLUNO4aFcRGoTCas4mnPwDRWiV4Ul2yjw+CSP8ZSO+A0YRJY9TkWesPpI6e
RVJBUmpxJVoPEW/RBjxqJEFvYDxiYs3wnZtRgPDh6vCOf4fmBwS6q+IDiUlA
JmknD7L/uHj7BrktMvXR6EexljCO6mWJjmn0Ft5KnIuseB8/irfp8+dJ4FZo
MsuR4wlvEtOzmD3YDsl8ON1buLfLI7y3excmhg2ajxaB3i8gs6+mtDufX7kp
ahDXbA/CrZ4wkeZnQFbW+TXoRlsEvpYMngtYbXb034+P5WTT/YazNet8DOvk
Mz3bsqc1pXgAraTQgo7d3iAuCIRWbNoBRYS0m5bAn166f+qE91p0InnJQkKC
ImwToEmIBi+XWyAkiMlxK0SwTs0IuHaHvNKxiJWjhv8sI1EuWiB4/uRQHsmh
ZBcs/iLZE60U0EZk4s+GfQb3CGCR/Az32+Iz8cMUjScKxjxcBK2FCggnzMTx
UOf6liGVieRO5m542d/kR4+fzIOIkYytT/cxpku2ptTVSj+0AlpT162yrUIE
Ppb2AleUHU/iepLF837xCFBIld8I3wi9tleA09n8gCadz0g8yH4Bojsay/GN
T7L/HGXZx2yM38K/xtumOgHpCGnUCZ7NydOr4xzUcnTCjXm78Bp8wAeDnzy/
evZk9fDZ4bNnj5ZPV08eP8+PrlyeP1w+fpyvHh4+ns1m4+xz9nnyFTPxWu+f
78nD44fHuTs6Wjx//uzZk8PF0h0vjp5dHR87tzxcOJ1v9BeWO7qosCiYNuIZ
zVfCN9f5JsUFfUuMiXy4CPmEkyjJ7YWdYFjOgOUCRfPfky9AAUhZmpEhyGq1
2SaEP/VSMDDh3J6NlGgmZQscycfBzVEyDCGOCG5kOaomYtkVcCSYCcgJAEeC
CvCVYAlhHtOHRSWOBK1RpLlQkebVYTP/NgKsbJtp8d+2AuE6AEBtDyMCgbg4
IgJxGu1crOCi4aFFUiKShUpk6Wt3pHxXBToOgLiSCQc9PHb5d8xvuppUd0ks
lPHq2X6On6FmgedJd+rWG1D+wtJPj5hKom0aZBJSdBqaRpQZFQ7Z0CzmunD1
yhpIsVbdQQBhYhQjUdjjG8E9d5PfOiauGMTj0f7LnMbC7McHbfjxs+pS+EgA
tKji4AoqecVsFONJgI1idMMUP8HdBrAX05T7gIBFMAxD/XT5ItKm8Z/HsLsr
OL1JAOTWuE9oZ8GHkLgcPKjqoLBesxyJI6JcmTP3aAgAgCFtRJ4bRtGEflpW
EukorYvc+fEzpAlDDGCS0vBoqlWDK1yDtcDDrcPZ0xPL39hppo7ntvOFKDMs
Be51BrKjSV1Xyl6ibQ5hSEgBKZdwQ1M0UOAeWV+Fc1jWZAUJUpmz8luU9YRE
yRyAFaURRkTRIJgiYcLoZ13fZuE1KkJMWCCTgdTlmGWNaKE/np5nv83G+Pft
4Ti7+BEkjOo34zxGrh3cVquZKNf/E9nc+Ft4TcJ06H/uf7vzMg7/Hy8ufuN1
R9/icFn6iDnM5R6IgEslVYFJxfIGhSs5B0Z5EzgxD57iOaMfUx3lDOQsYn85
wb0hEcYHyK5Zw/Ai3WEaCP8gO2LA6xBLghZ/BA5kYCVrOOzrIrd2fo1rj7Lb
IZHmS+uxYH0HrpIVidyzOBTVn8+M6oDlUUYX5YdxLIIUbTQ+DLZctPEl4MRQ
fpUXpB4XvDHYYl7OevEXShvFkCkoqmEONyA766gGtwzWzbJ34W2aKcQaEJ3e
62BX+6kHLYYsZ6wJA3d05RXe1n47rVJSY9FTUxRu503dntKoaoqa9KWCyjGn
xMhSFBIQpxm1gCq9FntQ8PwNIOfHB2t+C0jVJ3s09Hv2KXstoPhp9Gk6ndL/
wYuGqBD8pAZz+GxOz2bFCkit/L0EqMM38lLMGeGXlETF5wSejZ/j5Oozdqto
UCdyqOINzBndyjN5B8fqP/1fQOk7v4gZt92pqQWnVEMM6oVtXQP8OrJ1LNEE
7fB0oq3mvYwZHhTpP5G7wMfze+07dLRLa0kWRN0TtUJ75r9x4BhUKOIa0yH4
KbBmjcMyBIkB2pp90nOFNQVJoidlpJdufpkHRhm1nyis4KCb2pN5AFHHe+Z8
ICwX/r1gBAwo78AaSb4LERW3edUCjLDUM+cR3Oo03FvwndOQDi0+zP3YlU27
yNHwQ1cY3sbPP55w2OJvx5dfF62j+1SiLREuEnC0HqPwhRY5xqi89LWVtoME
gGJ8wWdaZXN6+Vx+m0enuAkAEVs8PsW4gZbs90QBxDUhtrVGRH0R35hSoT6L
jiLgGrxFDQnMK1bokWhJkE2lsRLDlI2trWgMZC9DjbFqd2RwNCGG33e4UiDY
8CXHa6gScwXI0epxbfKiYYF6Gbz6RhtQc1PhNZZAjzZFDMaDcFUDWBCETrMz
VgUSR7wI8xr7RU4I1MrYMhOtX0lwGLyEDi+JYBGmS7zwxKrtOhGrxLxhVIlJ
wEB/euPIk7XChwAYuzGq3WNeEjwDBRxEnLG6aPAtMfKsSOfmgTyaBXCCTd7e
4DsHvrk9KN3q2jUHILK3bL/0M1xUibr2X0Y4TdgOzS7bG6sSjj60APgq5MaT
K6OrKiCIdxzDsSwdxUdVBRrmF44REzWi3EcjIQMzsLJw9AgKzOh+RomDiEOA
sY8PbvXh58RIQGpWz/nCMTM5OUpJcwe1uO1p6yzFIt6QbISg7cWHmYvxmYA/
5fLkYCiRYe+YsAGYiF+KRMhuMGNOjgYKgVL9Bz/m7YnpsL0rlk7wRTcByo21
uaItgVSgSYY04Z8U9BEbfLT2EkLEWQIS82EjoAcrpaiy4h+4Qpxm3YzcxCwD
tok46+HmVBr16DcT+wPFxCLkk7KZ+0Ej7FGQWa1hW86B7SInIkwbozAFFrKK
FazH1jm030Sr2wvW3U0Oa4620dRxxZLsPaZ6CYwzoj2GDpNGGgXitaBEeqQY
3oqgCNsXYe2m2MjGKSQRljKoqKXeOmVfcEPK+nuONWP/HPSrDfqzoqbIOOxR
wg0aYd8rsyMRWC5AnbQz1cOCKQ03mJW5DwK5AX6WycVl10pMud4CHe3Hj6Kh
x3hrHpFQ5sRehfVud0zDgUAgzwonaE+JbXosNVGkKx1ZEMcGbBSTjEL8NiVy
VMJIo19GimTNWmRZS+aQ2JltaeYS42BnshBjzpsk6SpyLtFVe7arVsPyrrYV
B74BZJE5T7h3uChjVtk0BYbv1ut10dLoILHcqFchmlS+oZDUVojPkBWVTfth
GFXKhSAHpde8AhC9BO3DJwIpb/6er1BrLrw6eukQOpqJgCUFPbAZJhwWUkq+
At/ZR75SA9UtQn9OOjvRoE6MhBBCe/DCFn/ZwnMNhCbw97gkEHtUkaHY1zlK
f/PbutyCuNzs5iq8dbXngAKYR4By6BIRUdkT0znznKkxCZ43+cZ1bBIoDbY1
WiRbA+OoxZO0n/rX6XWl7kwlwpuNk/BpTVZqKRjjx15YASixgnBGnCJZiCHq
FclC6DkgMQhvCx8kR8U/JSEg+I44JuhHunoUzth/UdCofoN2TA6pWM3E5UGp
hJU/2ORs1jzw+QHFMi+BJwUHSFchtovMeHlRKx5rSuP0btPqKwKGKNHRl3+B
x+SJGUfVNi44uoXGAHLNSV6CEPHvZslh2Kgm68t2UUZP1iWHeVW3jbO+l1FQ
gdZR+OjWyw2cGwWVHYiMyz+LrsyCJk4zJT4d1pCqzb01WDlavujK0vxYqPng
6fdkbfVayeA/YnQYA9ZmtRm6fzyqv08P9UOOgr53rlP6AbMJpw+fTw+fXx4e
njx8dPLw6M9xc1HHF88ZgO8WIWAc4tLG+qoqBnIKexUDvBGhieFtvAbiMe+A
uaTrxQNFJ8rgLwuQ6zHSstzqkUvC1Sq+A8JqtX+3h3+Ob3qXl/vffPJnzh/8
rEcM/OQCo7UJIaxeM/6LvBJVIJlCd5t9rUI0MR80jkS5oUuVO/ft/W/cA4Jy
L7ohSuvmp5/pvxHZh1Uz+slYZLqUC6Ymr+zzw+WjgPky2ZgyMqYU9ai/ofnm
d7kvCNgWoCzV1TSnuKMIRmk8EkOoEoDmaomJq6jIrpLt0n54J2LviUu1aOiL
6j1qJ120GcQpC+w5Muay8G33x2G6G6xJHah7+OTk4UP43z+HN4dV4kgLg2Ep
AFxALtJyaVeOMvunaKV6b7GE5NnyHQguaKvYhwNPDbZons++d5/339XV6ypa
CvwmKhJexUs5j6+fK1kZgwLp9r5mqcNIoZbQcGzEnHjTYtJj4IL7moYbVHYp
xm2hewipmLlVulbRAyDrOt8Qdv8lEgWUOl8Eoc4SOBb19hHe45PHz8yBgRwN
qp5/A0zc9aheFBqHMXkMomSx6j2FK+4dEcNOYv8zjExEkLGa86ZqzounZBF+
/3uGSd73kpEi9r8WsXYcLJFTsURGZLXIcN97QYAYeCnyeOsgifIP/VZ4v92L
BIfAXkaf2Wz14IHG9BaaYo3iKSe7hZDhjw/wAfwbpMu5CpQhSkcPBbQWYwvn
pN9Ck6YoeQwTyDf539iKZURg92HpNq3EaA6qNpoKR+rPaiJ21hA4nQcbASrO
pIoWFbyKSnM3qJn10TQm2vXCrEOMNG6SMi/IfTXL3lZqVr7GG6m8sRnxJ2Jk
ESWTB/XsMI3y7iQLcuRE08Pw5NUlkHwW/AcUrTExOvEmCezYUN4C/TN8r+bY
/pGidkGe9Lg9tEd1AtLIqCij0dHc1fHgvMCA+GA5QU1sJ2jyNol0CiwoNCbq
Emvs5KXDAAmKR5Gk3PcV50bs2JhuFxqcwmEtagTBoAIxnQAHxtzZu3pbrjKg
kv3QJQEkWYOXfE0ON6Kv0MaDQKQYFaCe4kgStwJLagZ2gmmh8BpaiUJjN0Jo
riLePJh+DfzFRGFegtg9Urgg8wXnhfHhsUUpDTtOnQ4hTFft1GhkWhmckImj
GSOvdmx2M6sj0wbhtpiq1XDMKdXkC9GgTHsoUX9uNd2CjptnzDlGXk76Bi3K
lCJJ5ilrMgnecI1369lPiMRp+YiJTbvlZTCphQsO3trEft9LeYL9LeB7gbZ9
fl1xgBCaib0xvsNXF4fESK5gEZ7t8QjrYazdEjZe+LWxaYv5EEO15kFBRqcP
5joALngQy4BMqHEQf1m3pcf/1jjNlN250xakL3IWoVQD/101+Z0Y3NTZ99wG
48x6XupCa3vQtsl4FPYpNJf8aGypQVqNWTjqFUE7HeUfRtce7BCJACeGBXx6
ffonRAgKSkPk3OPf1oIlsJQ5avC4NU7eCpucZS/JyXbU8WjKRihSMLXuOrZT
h+SHnlNeEsrFXsNLpkyEEqnDPFkgrozWoel7eXhhroBTYi4uTC0LRpT+0iAY
Q0JIokuSeDfrN9iX5QHU+yrmznczCV5S4N+9YQNpXoo5vHLXj2Q0FB2IRxgr
9aEleOQ+YIgTEbxqN0X+FZL+SDixwQgWAFC1xWvfNgX+B20x84nxTJAdT8AX
6BI6TqRoGUUwilaXuWpFLIx4oQLMoyREjUqwzAYCH2gd1pwz1+QC9JTPu7EQ
QmKAJE5xBOSn83hP/BGHHuKFE4BRtGhRLcstOcvm1bYso8+XgzhBnsTfTLbO
MR7Iy+OFhEy8PF6SJ+mPJI6Z26KNk4Oulw4R1s6xQvBLSVZ8ie+hYGNy34Rg
dZQBKKIE3xW3WhylCGmZyVTW+YPZ0TBsDAmigQj6jASiJCNwM+RJdMltU1cE
WGgMZT5xFnzq4uQmcFUVlwgNvzBTxTsFMYrc5bCaaof/5SdTJGzTgAl+Psvs
SMb8Me8GEg9HcLJJNshxGtYdP7NeTkUf5RZqMp6zSZBijXqQF4AX5XyCCn3A
NCcShEeaWoRiNqB8zUtlJ3NvZEAkmFYS0YdQBNOvEhSZZT8ReejggYYLM5kW
iYA8jDbtpB5YgSbctRkBqZd6MEqzKc4uSWEKniGq5CNuLxTmqKJNiFMy0dFP
KDoaowxVXOKznqhXKsZUJbjD4qGXYm5Rrl4A2L7XoEYWxihiJSpM0fOH0kTO
5kZ2n8wk+EacaBocksLdyZBvTyiuPk24ct4CGVkEXxQP3tYT3VTgWtsqvLqa
mxWHkTR8UN9in3gVHmg4oiZ0522IeslNkretqgMYTVnRvCZTgoVidODGrQyJ
udpI8ZF9MNrP1O4yN1K10WW/8TH5hqYLCmDqVytaSx3U3mwELDgclG6qOUnQ
GoJO4BbjYePxeqwQF8eRWOgWNJvccyo0v0fqhp45HsA+avO9Cg40EmDLnu+L
NqBT5zrpfaolJu7sebBAw+hEOHSPjKV3hSdvGX+ZTpObiHi9MVO2SRxl9Pyb
UIyFq6lo1a6q1RBT2Be8xIJP5HWnT4WcUYQvqqEcIdYXoYRbxiwIU/nmq3Iq
uHoH0+RAGs5jYPFQ8LSksmkRHaIO3fyRexzgcRrJz5invgiWQGhj0xaIZSJ/
BAmBfqLUjjavYvW2oCJ2jENx0mPJZxEKq1IXQ4ORXEA1ozS87LqsF/B2C+Qp
xyIwGODLEuK2KjAYE46OS9sViWQWiMuB4UQ/y575PDWftrcCEbbEq8AncpWX
HvGRjQGFD9Fx4axxFJOYYuwI9aaokqTNn/kYbGCdoQL0lEQEMZYzOWin7oNr
AEmZPgCbc8EOTXpa5aggxWoelaBhcjEko5hIWEPbFnznLCZxDFdElLNDnPbs
SD4+o7RIDUadmb3dQ7XQnqPp/vKlD9m8aLuhnOMTPRSmQiGugjEHI7MIBPEP
e2z89kKzezVgB1e7rTpY9/IJXcmnrHc22aescy7wJAZ/mJBvCftWIY/CCvaI
dxhSG6n0p7A/+p5EQ3zI9Gbfr8n3cdO/ZglhghS8OMQaNIZPhjZ/6sJcEgZ8
hndL0XfhZEypCjnJL1VrGlMUIq83yzlQJEa1JmRcSC1AuQSFxZy4Jef+5BxO
4ahCI4o8jJfrfEW0oodRqndWUsEEWCbGjbC0KYcrEVJo3yQDrLKiKyw7G0qp
VEuuMdY4qg2D6QfMnSQzcc3piEYafE50CdVcw+6E0/aYJq5MQ62CbANfImKh
TQ3D0IxQBizOlGlskOyJQhRMdCTzdG/XCkBkCTUqISz5WeBSTB34dEPpHUOO
ZvYfnOjUtUmF+GRNX+uMhreshs8Ys5yE78dImGBaYGLMVgo6RInbZrOMuhuQ
KhAMxrwRXUW+QpBKQmZDQU4akAqOo/HbJh1yrGEOmiPF7Xbi9nqZMWI/L1qb
/aIrKAbjOM80LbRvmwk1I9T6Kqcmx9AJWkuhu8dmiHx0wMIISmQUAEDgexAg
7gV1Gzi74yrkWoKRrbpYQFLKTa6kgLvmFkvmqPg+AmUmRfw8hHhkHx/EeA90
P9kMDwm5j/kAHVNFWqdIRUrW/GY2WWTGMSQJpw4fh6MLD+gk0qlY/Qg2bH03
pKVxeJcei7qpKdGhz7CF6tkqst2AMYC8lunRZssoxsnANvqfbBCUgBeFWiYW
Ud5V3XauNPCPEnBNkKqx1ix5qz8MWfEUNjAl5mxAgG0/6H4lHT/skiPbLXSp
XHF6+FCzqQeIq6pzNumbk70l+VUqY+I1aOyh2uQes00u1iDHsGZ1G4okHw/1
G2uJ1rxk9ixoMd4gtQAOANngysqjkbFORAAxhpZE6gRCfos194GmvsKLw/sB
eKmmrGzAS/kOHZRU45hq2ND1DoB2BLV6gdL0hN/Haig1KYNLW2nVegioSiRM
MGUrBEL3e7cz/2LUpLI4rFxYunD+c6ztQ6Yf2b/Zu8qm0UrZ33fXamm0iJ+Z
/iWIXkhmo8I76rRRBp1l4xc9zBuHj0yqjK9FKecfJFI36oBDqBhqjwW6J5VY
PZq3iRWsMFoaRQose8r11ZAT59f0FpMAK2f8Gtq+h0p1AM6UWxs2UlL+Oste
IbMp7w3DtLkDapp9ijFr8Tgk2SgYW8lmq1yWDa7Ijq/QiMfoGkvvl7n3lsZa
BxeS307uV6xThowkigjMK95q1h6wiliqCQDIpPNR4AF7IYDC2dw+U0wWZ39f
cDIEVSTVEk5tXb9nvaXwxjBBprm60SDfBMpE1pAT5xwLsnCgH4pMjQUV50XF
MbidHs6eWkfCt13+xsUhcEVBtDZ8bRKjoSXJJkngLegFIAMTTghEoxGJUUEC
lwQdqRobfTGkkd3AhWgzgG1D5+Ql5Qct97TstIkD0lvZms+OZse4/6PZ85m9
mVm+7HiMRHxUIy07z4IJLRoAiVDhftncHhPdZGfGMPCWy1+ZWfnGjcMqFAHL
q1WaVDtRuExtojSWC3yjUxyd7zv39zvKYlpAPOtYwPJNnWTCm7plwxXalH5U
SR6rBkKoIIonaQ7mSI33Ofste/FNXFKog7m/HlN7Szaqnq9LEKvnyZ1IqbEY
yDWJubLktg+RVABNthqcZyXKOmVkSwQwMaRzbk20AfqU6HbrpUufFAThEF7m
Qiot12qnmqmea676UHTVx6qrrEP+8MNrrGat5SjDidPKVzYuQKSfVW3yMY3h
CcUQNcEv3K6WgjQIjqbdgDjgpDaMWNPwXOxZzDqnGOJc2TzWiXRNDWmD9ffm
Cj9DDstolnlMeJmO0PfcStQseW0bUCcwv6da7qZlTbnkyJZiXjU8gW/4dLmQ
C3wq1Tbp39gjBr1ihEvGxwayJSPd1RXVkgTOVKzy0CEilDykRWYUKmFwkgr2
8t51d29AUFLWIqorpTCK9qO+piTxsZEGB8HQ1rHh6eNoxEMSPBgIUtV/rVyL
Shl5+DT+l2IgJIqYPRCYDfjXxW4DV/ZXrJbq8QxJmNRMY6Z8m6JSt1SMUgvk
KpoGTSa69eKHeCmT7H5HmYwrNwkXZguHX5ucM6oJDkeWFB26c0DkSFSWfgey
KoF5iqlJMuNFDyokVMAkvetKTa8JrPZGGC7lSIkyJIDZiVsm7lP491Og+beq
OIrrdorSH0iNK449AOCZcoLb1G+xSKW8zcrwVKRKgW44E9C1xFsrizGxy6l5
mSN5sA1VFZTXfmRzWIXHhcHmVzI/2vmAYzkPy0MyIxUc+rqwqHa4noqhRY5t
HkOwo3HYRr/Nu1Hd1pv89FfbPnpHka7PGLUesQmjW2wPxSrWAKSJha2dwGtF
xYz8AZTIGecD1GClg5VPAazBYHGDwJ0I8XlULw3bAcEBVEFbEynUEeC2H6bV
Bu8qVHhg2ZNXPJHoMpb4xTaTe1lwqG7Q6/kSK+i4dMeSmtZtKWRaB0lCsZbw
h21Mhviqnj98sa0KdjON4cutG3fo6NHciOgmbz6xXYkuEAVEVlQQhEAtMEmF
KH7Gf84k5j5BojT4nuM4JHrMlVfztLh4x/BDRIcMwB33lxAlSqdmUR5dSmj/
CSVrMHJ/PkmCQNsk71O8NDF/Er7IkKpronliNuYoyCsWzWaJ9DzrpARE7ct+
q79O2K4+FHjKeUwTLbDTL9pds4Fj2XX6o9aAhcCJssYkhEgyULghK9LAtBg0
qxlUBsNfkDhrhozZCHMVkkMwa7/ulw2UmXel9QmChSaDMVHUMHhCbJsbYZd0
HJZE+Q9GHor9F7pRlPHrQzWOcexu4bHHDE1khXCyx204ahzDFQgj0GUm5dRt
mIQkigMcT2PxFKYiGN+UFl2SOSpSYW4dy6jRKOi0wrSXmrEcOtjWVGGWjVkU
OycRe6GKgg/FkvPWBlZEtYCKrw/XjlLreSLZmnKQtlQqBUyl1KPQesHYHwxn
kbWESllJWdMvfBpSpvteMFUbY9HG0AbGVdcoYQamiiff0aOUOmq4FB82xvwA
GGnLB9WVtcgVR9xL1LWIKN38EfEadvW8uRRKjq0tqCr0Kpq4TKY/LnU6ULXn
vuLRIa6XzAcqqWkhOIIeM6vUxvAaK4BAM9WPaI0IG+qgkST1AV/Ky/OAQXBn
+N4636mSOng6IIgCh51btsBU3w4qFkokzgnjiGnmk24a+lDFYqVFRadMcavy
QAi5kIKqsb/ALPtZLbKXrw7R3kw9SPBfj+cMAmGXnXx43mEw6lWagD9YfyOy
ms5aNiRXU/4IJvHP0i4A3Tk7hVf1K7GmYMeCuhTpxObqh4ihk86NdDi0KYIC
h/Ht9yTI9vibDRFYStqc/fKIv4wsm+zEaps3Lx7Ti4FtJ3l4TDQbrjrFgYXI
pKUIBjP9odgUM/wjHD6JubwnPNJ++FiE56S7A8UBd64j+M+5+BBXG+oVrhmK
Dl/Vd9V1Q152tsKb20ovYZadybtUtGsoBcdRJEA0NQqTwUBspbxi7qG2AwSG
ETwxwaTMARJY7KaQqg3QCPSrA2VYY9OXTnEqw1DM4ZgtMG6snWO/sIKpVqgQ
x8H+c4oJaW0U39RBxshOWi3wGHi1VXWaus4VjTJT21uOTAxlsUAtkJqUhtPj
/icw9VQ6lRAbLcXMB8i8dot6taNemeS1Zr8cGYIlUyoZilisGYvLkQ2rYjl+
bg9Ob8vYCoVlhlQcXoDf1BUHTKD7B0X4DTYzo70GLQQjLoziptXlMbirbt4T
cDBYhZwAqjkAkj7//jmWymlWehc30pvH1qZRv2wIFk0rK0su5IZETVzwXb6T
qkZkE2K+VeZco8imIMoUs70x49Y9ayLb9gRgRh9rcFSKzR9o9lDUKjt10QId
Aom0ABCqjdjbUc6u69YCacKrglI0HD0aYwhChBzhIhckuzG5alLOXSJQOCaM
y49y0TGj150B24o1S7FO0bDhiziwWqz2mcGI5wQbl+n6YIl+CC2TADE+vYGY
Nnt+Q5vnarFkcZPwNjoKWwonInyHUyoxmd3P0oZ4WKiZaNinmnwF4FIGxoeO
YEmC8FcwLTL5gaiEqujXMyEGrSAh9Li/zRENZLFfXyr1+ibeTuOiTItNCmcl
K0LwMbOXmK7XupW74JZd9kCXYpz7/hMSGZgypu1e8uxmu2Yfmg3rperSXFUJ
70CZlyn/mYfWTSrKkf5KfXxN8e6TjnYMaBkS84FMlqXvKcpGM5a3qaJInObl
UzuNFoZL7Hbxw+c6DTWloHf9fkNe/O7pn7UgvyVsFCnOutzc1hiRTCxjfU2t
J+K592ncLkHsvdG6Jia3d/n7VK48FARFVSsBIlQnOuOo0GpQGX9jnaHzsYVA
NllTllVQIUO43oRZLOUUiAOS3Ml8iPfzp0lUSoPC1A8f4fE5myp519oKfH5n
O6FaG6PYRW1r3QEIKYIdkuuscoYOUuBexVBDDdCGvWltbBkVvbrQtq0vaoqa
ZFeBTxWPaCRFeyLZi3CdyxrpD0olVPO737aJkizqBlFVhHMlrFQakoIGKBku
OB848DNnWUUHQekBR5lolTLsNu2RsRb+RsVubFMDwhmnwlAnc66gTxyVwEis
CwJLZKwBWQ1NNYxTnddMGwNOlGGtnoyg6e6ivCHvmxKGNxztShygw1VCFU54
XcIZ7aI6nSDyTq6ErpYTIghpSZRUV1pqdkQlXdrOLsgbryaQnOsGkiIhn1IE
EVnNZtkFJ5mHdYiOnffZEabHB3gQHxedJLKuIduwbUmRk5O8plLqiTPdSqkd
GZ0350X9pfpzFAr9xbfIJ6itxqU0HKUrk+wWKv7GW73fxiuktckLH0oIckjD
qqZSdjWFzca4BGvOnXQiFTqAZPzWsUCDudaYoLbPjEwmHfjp2nEyisgLgkUL
J/3DiZmaMfgLyRLX+Mo7jLiCT1gbIiQgY7ONOwgZNnQIMMXfXVP3VCPtmInE
jUxvsYmFpA2SOIeyBME90A5MPSCuhP0uo8OGrFTUAIpyioXMmCOkSM0dSiBa
UlJl9F7x3S6+sRYVkisU48RE+t65jRRhqOISGFgx3BNje1Al8EnpD5id9PPE
H0YOUYogijjDPsfIdvr8o7MlW/6VT4ncTVTrQ/QvRrYgIb2pMxDYuT4NZ2M3
eZC9AQOofZrEZfNKohuFXw4vkZ1D/s4J/fWKY31wLFCO0iy5tFpOYtmJPBNE
aLTxdUQIEgUGGxf0mxphgVhgRRvkv01OvcQGkiMLr+UvtPT4gPeJYZ8O1owa
vODaPKfQllBDC8QzroxBztTCpdaQzDylHGfXdIBlHR2cGlJEASvg71OxxtqY
cWp3ZGPIbcvXr04l6dcc14XuGxrRV1OQBMe9ejk70C0nFmqTDPl7Sanum3RZ
cjHtaZJ4eol4Fje0xE8Ku7ziTtJ1jKck0YIyXOwCmP1hVD1/WWlLoUw6ybI9
A++BPbRi3YNBOVgJv1I21W8oZQNoV4YacHr+14Widi7HFqXoXfCwoVGO0YYK
UZw4h91rCk9vvfcGr3JojKkRhLRt/zjU5NTEvdo+kpIOlFEHWETeomTsNrTC
UmhBxBYtfmg26xyXZkRxL4S+q50kWfEcbbbNBhuumaL/wQUfEofyVk1GuoSZ
FPoK4nvsKkUKPPauHey2ZOQ4AlOKc0HqH+zA3cYcmPKqCsFYpyG3PscCjFkC
l76sMWCgG1AQ0hgGlExKDIra6kTSH7oRCME4YvsZkLiHzslFATfXFCBrlTlI
EGSlNxRjPWA67t4oJTfZeAc4IxwGZcRY0UuspbbzA9Y7c2IoXgqxKXd6SxyE
RyXMWw0C7TbLCmWAiGdH4aqWjPqkrn3gsQBfALKYMXdThxLh8C3V4mi21Gsl
NjpJwudWq0HNQlM2ZSZCg4BmVMgf5JIpibTYH4GGfPKcIvBsNF5/eJUmpPTX
ZksqlOvBSazbzBp1TPULIZBYLUjjH/vuZKHDRShTBeuEmzDcUGh5lFRS5qcd
pDLKIlaNNdiWpGA3OURDwfXYokniWUQFHGifS69Q/CC7BUxSR9KZajTaFz0X
YAWlS7ZhtgMTka5xQ0XhOv1otX4bgosJmACRQQPvqDU8DeBEKlfaRY7cKLhy
Gf4Iry52CFjHjEBhBz7kntfxaqPA7GkW1pe4HoeJidKjjcVjfMxMIr/GQO9C
W+e+i0SikSV5qsrvbQlE5nG6p1naIYxPkSL/b53sjr2sXpmhaecQa37FLCw2
3BVaB7y4zZf3WESGWm6ZzjvdrlUTQpxek6k8CyVLOi1kcy31hRY3r2bgXkGs
ypZORw+8DIMYSYAAp8yZDbPszLRC1BAP2Z5211EZVQuwdGwyohyG+Gib4slL
HBaBQ4nCMl9ysq0KP8S3Y7x1cE5Gzxx6r4CLa5MGISqsSZOpPrR4ixWQ2Koc
7M6xxwUXY7G1IlPVW8eaZDGoxHTa6wbn+r6+KFnLN65ognsu6AsckE8YaQwx
tDNqKg93mWtVlngCmqtBS2K4nG44/ZY7P0t3edPdpnSt7dRHWhBHjDEKU9G+
kuViaa+SmDJVvAjZDRwNI8pd+qpEGkuNPXMedpLkk4ZFjiT7Q2sGluG5YpWG
NhTmcG0RwuzV6ZvTDqJmHx8UeZV/7vYikFKK9AWH/QpqxWa17W4jTXp/evdK
0DxnX8gm18ohBDC0iKYuvSw+tjngcB25SzaxbElGJnzzbbAGsqmGOklmpy1S
IP7mZQPzocf1G8/Srfbu7K7T1AD8+PHVm+nl28u31E/+NIkZMiURSc1ZyD5K
suIiydS0biS+mNxE4e4ceq9wlSRfF0y4ewuKrVcCcTd1PImhI5Bglgc1Tyts
xBm6wNe1tLTH46+5fSnzJJvzTeLQBF0gKLKRrZQVcUkuCEakjgBHnGM0mk6n
gHrL9wg+Zw7fyQKHB9iJ3B4AiHrLhmBhHyyEAahyqc/aqdOxR/CvKxWeT1Ju
qDIBQVWuHT4TDOwq66IADmr4UYbgZH3OWwssstzR7UYD+d51MN29w4sfJ8Jy
O5ZIS8/3RIKY7FJIFh8L53GQMICdMEFor2BX9R1ZYyWRPU8VYoJMQwvV4BfT
e+LFkq18RaEfd+xfRdMD1+fqSfBdCawQszAQhuu6XmkkWLR1IImjKRmeSWZm
OLYeHJu5323vKba2cKBRGerLit+HygtcZWlZw/0GPwfh02xQmKXmXqF1mUh/
MhCVDUx6rQaOZiVfI4AG42K+Bh2MKI/WTgO6h2WKplRWifkPS+9i/6AYjiBm
dguRMqX8RT4Q8fMbT3ZPADGMlVMnVQciEEwEy5GK+6Lk0BYJoiTOsw+EUz+5
xpCTArK/VfL3NqG56leua0FEnkj2kxVEg+Mn4FoHDskIusdTpqRSuFKUt2NJ
Pr0ItHrTrSOqxNMiIwASNFSBryl/nXIrOtSQ3HmSQM1xFLDKM7rKYJ8LLE36
N/JFfEWLYW3ObAoSaQJnMNNWwYeIZKAynDE63LhQwILqf1/nzYo6hlESWq3K
IdvsqXAWF/paYnSaCOGRiJCfgI9TAzHMOX4vNMDElugwuIHY4FjvO6ib0dxi
u2avI1n9ksE1aUt5X6drblY5/hUdXMednByJXys7sh5RLHI6Mg85yTSgXLw+
HeOZVkmgWqjR8GfMAnTB68JrrlAkA/wVGxFVJdUmjdboJwcR1xiKEqEQy1EG
3UxS1PlcRbG6mExKLZG4iIVoYwt3k98WdTNwZCROfmjFue4+uCV3mNEiH/Th
tlFyYMaOoB8NpL0WWJH2BJQi6ovcm9AkdrA8STee+8jZpapY7y6i9q61VX2A
MhLriOCY0hwEqlPC47RNqbXSRU7ba1aXlCFjcpAQyxDCnzrDk9ouYVcx5KJf
S0VRJcfS6yTjacydUPRYp5xjkwIVWe663VCBotarfCfr3FZRptBwGiRTSeET
LvbpQ4/r4oO2jo3Q9ywR7tRUOtB+WKzQsfwOEBAtGN3aGuYkzuAZUckfjpvt
TB8B3gaYjIvqCu6iWqq4GAmBWGW0cna4FesOVkNejG0RE36OZ056aEuV8nON
9igq+1P0eRRrN1EyywwubfzQEvtj+JplL5Q0hYbMKoQNRdZwSasg9saDJue0
gXxJQvdJnupEuLMk/XAwMOxGO+gGvZfAQAQcEcg0EBF9cDdS4K+QCgBkUTMh
iCIGiYtIZY00epH8JuwPaWpKQdsFlFOqTcqa5NJU1umvfmgGj0DdQwVnSWpC
Xr5VwVHJlKH1GBcYAqwGEvTU7CDhMGSos4VKgCRqBLd2uYg5l/wRxQBgVA6t
TLXtTrPG4cCI/QENWrwutJyQhH6KYzC9ICgkSEMXfH6HJCgmHtiATtZCDJDG
ZibXDfkhKJQH4xfZyCFZDuqz5t2K/z4kD0rBIWK6ZMgz0Qno0qCRJ/3Jgx0U
aLajgk8fiNvGowiNYRvyW69CNjkHjka7Yhw7qSTOqmdZcihvUVWULHUGisuG
y+zYlq5rLulmTUrddszRhhZqG/tWwFMXiwXq6gAGbPm+E1SCUTdbMebH1rw2
eVzSlE0OuQSIoBL/QokbIrN4hrFNMw9kC+5xomcRzEjhM1lB6K7DlkYNSodv
2O4f2iRb4y6dAJus9dc2YZeTjBvTUvCs4o929BiuWiAto1mIk4Y3SLAM/+1M
yZaFOf48hyHL7ZoEX4r93LZS7YNEAeCYRNlIKeDCT9QgOaokWpSHTwUZSNWZ
TmxpVDOijdQ2mZ2zNuZYQpeTe5PMYjvSmhE9Z1koPQ8+JJkg3oRUdGDHBz6O
KMs9hcWmj8CGsjk+7PbPJvcYVR+MfZmFWRG4sDgm8dkh9ZpNlmvAcoJXscaj
2ow/s3fv+Ph5dPOyaYAcVSFQWbXsNobydur/kmSh/aE+8/mlWqg2AcDNVSGI
hK81hvsa/BKKykKQluBeceBeOHKSd8wpxXW25iBjaqFWR1rsQvqIKEGXceYQ
iqN2z2g59DDAOtdC6WIS7JnZOMYT5v+7850ByPSI9sJQN/HWhF+oh9OLcyME
4FAm5fmLy7fvqKRSUanaS7lONTUEANpQXOFtl/mOY90+AeZnnxgJPwXmAjN/
wnxcKjjRrW6rFW5PD7EeLBWU/pTeUqiJFErQipBji5uH7ASWO4TxAmeF0cju
yUVssQRgmEXq3upoUh6dq/hKz6tuOe50sGM7GG6ALrAzbKypyzVqokrBjTlC
kd1k6EfdoTegGw4GDvGcST0KLrRo61Gkgz8eXnci7UgoOVKxjkSCVTwoBzVN
Pu3M8WR4jqQrSdJcYaAjRNIB2ogAeJDmGan7Uy0Y07hiDbv4ulU+TVZ5JMdM
baAqSTxPauYm4tYX68hPpCg7GavJAoMW/BUXd8REQVnMpAcWtvAylkP90iIH
K+QPrHkykLdFjYpiSeY9K+oVav5E9VkHL7mDp/2y9h0sG16TVpLes6CB+tIU
sNU5K0GPfgxZGCNN8hmoGkno0Klf+ZVXd3g4iMc22YcXmEvvJSkvJ4ajeVoz
LoHdlzS00M14+Hjb3BaCCzzEAGzHwPfJpKzzQEd2oC91iuIiAOpk7w92bAdL
k4Zlp10k378wbA4UaEmnFUvQ6/oD0qqpB9HAkMt/dkgyItleRv3BH9m9S+kk
NcJPus1PstJdUcouGQCb4rrAnBHObuwP/dgO3SuNJkCeFkW752CfmNHQUKW1
60O9/NiZz0eI7g3zlIfhbdtMLqpmzbUsND+sH1HXG+8ygegeTcAoMuksIqya
m0ojcSOfoMZEUZ5kQAYQu0oyU/fns4Cvri8uI8H7ZzZLuXWTbhwSPx4Y1CJA
bvMFUXhy5Gnk2HlaH8qM/TEsIFWiIR4ePQeQITlxhaH1/a8sjIgP4ZqlXGCI
VdGikqx5LUf//fi4P8RZcgN7RRU6W2OlpceDKHF2dM+ApoR7HFFcKBqP3B9R
zvf5/UtU6UtZEZF25SidIS8OEzggsE2aXykmTSLvJ+Tdu8iLoy+M+I1XTQml
yqE6RsIzOgO/OmzMyLFDq65vcPX3r5UqeZg7StOWAiHYJyIODXj01QMOiJdD
Ax5/9YBB1rAGrIERH339iNGOdU1aba+KxsDwjy2X2Tc80BZ5pfP9C3sj5mS0
mhNo5kIIOzWc+iMlV5Ek9RoaLZm1MYW3P05yA2nZqcjg+vWvfg2PO5dd85KH
ZEG5j2iltIpZdzS781x3Krms5KyNXYyLmJHKFZzotW+8bW3cnyA5EtveiM29
0i4vCVKBZ4exx1FvyJ8PBxhqpG7AohtMR6pI47W5XKYEZ3/Q9CBSw25ap3eo
N9LAgCmH29/5KMpTSd8jzMUckibOEzJcfEhdvt2sJ0qL20vUXur1P1ahtlty
KWChcoqvIW3nekOsZ3T1B6aRfQViryB2rpfD/zFDxbP7an2kN7a9JzzIpPB5
qhV0amxQNRxtSCD2ooeHqn4PTPUoOZbhJcfCsF8Lum/DcfN/OxW8SdvaoE8w
L3/VqEfDo84tJoTw56TgpPoepJBvb+w3Foa7hXuF42sGoTLAfbV/NTjsU8cy
zBMdGVKR5O/UGMixwhCa6Oth4XsSy0SwyDwwdGy/dDnoA5jYcglXodpUDC+X
XkFdQzL2YXqQnemjPxQejYgwXbXFodzqt2PKZMD3XkhGJcjh04dHJ6PRd2Tn
l2rZw1AsvZx/ZVcWtt5uB5tpRIt5r8aHV3ehAbPffPxoWsZ8Dj0qpoA3g21U
kCUqFmfikDIdVe6aujVxpexRWeYSqry33clsbyu2NHRP2tRSWRoNE8NzrmJV
+oGKJF/XtGDhborKdlzmY0aXurbkvbeUvQlWh1ON3RXgUAUUxANsrfJ4zkk5
vq0c/1ES/W0rrgwAkoT2GedLrkHktlnIsVawH7Czx2qSdKwnHPQsRBRH3Dmy
aP4dS3kb/4H18gXLO0d6gZBH0e6r4MaQ8pW3ElPzXXZOvShCG1p0+6uQaJyG
J0yjJ0z8JsLQUJBEEj4Riku6ElLJWQcXDwkXL/cbXS0qma65XlpDnGRJt9wQ
CLG/X26nYUtEqofsc8HAJLZIkcPdtuEFMFjkK03XxxiyUCEqLJeCIjZOI9Co
I7dM5UHavw1ZWLQqTwfd72prCIrCLXs9EgMx+b9TO+1ssIrWF3q/SgMBAgRj
uL3iSvH7270RH0ApLLar5Cyv2Os0rzhGUTcDN4O/UeVcTXK3awrkBA/G6uKy
uG4/PM6X0vYkLHfBHHwGUtOm24RS9iVhTyZKsDH1j8OeLYAMN/DrtO3jPMm0
4hb5n7n2pbbsowRgihXjPutEh0JlWVEoYgQpVzlMixt6xkRMKAHwkjhwm3cl
OVwhLFS8uzjXBUjDX4PbT6V92oQMJNJffSJmTzres2PEajyeOy2NShpPpCXA
pk+XCFRYJYlwcg+XLourK1gZemfRtcJ81lEtGz5qJMm2RrX0khjqYYaLif0G
lQszSISUC1YGKBEoTU+TJORfw/m2VVtvl5TaeVqtMBUuO78hdowBZIg7RpQI
1bYiawtAzMhTVDYwor9su1oWLJD9Iwudjf4fz1kBJw3NAAA=

-->

</rfc>
