<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version  (Ruby 3.3.6) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-palanisamy-scitt-aac-otel-00" category="info" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="AAC OTel Extension">OpenTelemetry Correlation Extension for Agent Action Capsules</title>
    <seriesInfo name="Internet-Draft" value="draft-palanisamy-scitt-aac-otel-00"/>
    <author initials="G." surname="Palanisamy" fullname="Govindaraj Palanisamy">
      <organization>Independent</organization>
      <address>
        <email>npgovintarajan@gmail.com</email>
      </address>
    </author>
    <author initials="S." surname="Mih" fullname="Steven Mih">
      <organization>Action State Group, Inc.</organization>
      <address>
        <email>steven@actionstate.ai</email>
      </address>
    </author>
    <date year="2026" month="October" day="02"/>
    <area>Security</area>
    <keyword>SCITT</keyword>
    <keyword>OpenTelemetry</keyword>
    <keyword>agent</keyword>
    <keyword>capsule</keyword>
    <keyword>correlation</keyword>
    <keyword>privacy</keyword>
    <abstract>
      <?line 57?>

<t>This document defines <tt>org.agentactioncapsule.otel</tt>, a namespaced payload
extension for the Agent Action Capsule profile. The extension carries
OpenTelemetry trace and span context alongside a sealed agent-action record so
that the Capsule and the observability spans describing the same action can be
joined after the fact. It maps the OpenTelemetry Generative AI semantic
conventions onto Capsule fields where a mapping is well defined and states
which OpenTelemetry values <bcp14>MUST NOT</bcp14> enter a Capsule at all. The extension does
not alter Capsule verification: a verifier that does not implement it treats
the block as informational.</t>
    </abstract>
  </front>
  <middle>
    <?line 69?>

<section anchor="introduction">
      <name>Introduction</name>
      <t>Agent runtimes emit OpenTelemetry spans for tool calls, model invocations,
and handoffs. The Agent Action Capsule profile
<xref target="I-D.mih-scitt-agent-action-capsule"/> seals the corresponding record at the
effect boundary, and a Class 1 verifier validates it before it is accepted as
evidence. This extension makes the join explicit: the Capsule carries the
trace and span identifiers associated with the action, and the span can carry
the Capsule's derived identifier as an attribute. This extension <bcp14>MUST NOT</bcp14>
change the base Class 1 or Class 2 verification model. A verifier that does
not implement the extension <bcp14>MUST</bcp14> treat the block as informational and <bcp14>MUST</bcp14>
ignore it for verification purposes.</t>
      <t>Two constraints matter. First, this extension <bcp14>MUST NOT</bcp14> alter the Producer
Envelope or the base profile's verification semantics. The protected header of a
Capsule remains closed by the base profile
(<xref target="I-D.mih-scitt-agent-action-capsule"/>, Section "Extensibility"), and all
fields defined here live in the Capsule payload under a namespaced key.
Second, this extension <bcp14>MUST</bcp14> treat OpenTelemetry identifiers as correlation
handles into systems that may hold end-user data. The base profile's admission
tiers apply to each field. In particular, <tt>trace_id</tt> and <tt>span_id</tt> are
clear-safe only when they are non-identifying within the producer's scope. A
trace ID is a lookup key into logs, APM backends, and gateway records that may
hold user data. This profile therefore defines a strict allow-list and an
explicit digest-only alternative rather than treating an opaque identifier as
harmless by default.</t>
    </section>
    <section anchor="conventions-and-definitions">
      <name>Conventions and Definitions</name>
      <t>The key words "<bcp14>MUST</bcp14>", "<bcp14>MUST NOT</bcp14>", "<bcp14>REQUIRED</bcp14>", "<bcp14>SHALL</bcp14>", "<bcp14>SHALL
NOT</bcp14>", "<bcp14>SHOULD</bcp14>", "<bcp14>SHOULD NOT</bcp14>", "<bcp14>RECOMMENDED</bcp14>", "<bcp14>NOT RECOMMENDED</bcp14>",
"<bcp14>MAY</bcp14>", and "<bcp14>OPTIONAL</bcp14>" in this document are to be interpreted as
described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they
appear in all capitals, as shown here.</t>
      <?line -18?>

<t>Capsule, Producer Envelope, derived identifier, <tt>capsule_id</tt>, and the
data-admission tiers (clear-safe, digest-only, never-enters) are used as
defined in <xref target="I-D.mih-scitt-agent-action-capsule"/>. Trace ID, span ID, trace
flags, and tracestate are used as defined in <xref target="W3C.TraceContext"/>.</t>
      <t>This document is written against revision -05 of the base profile. It
addresses the observability gap between a sealed Capsule and the active
OpenTelemetry trace and span without changing the Class 1 or Class 2
verification model of <xref target="I-D.mih-scitt-agent-action-capsule"/>. In particular, trace and span identifiers are correlation handles, not
harmless opaque values; they therefore require explicit allow-listing and
digest-only handling when they may reveal or index user-bearing data. This
extension <bcp14>MUST NOT</bcp14> introduce a new mandatory identity claim: identity is
represented in the base model as operator/developer context rather than an
<tt>agent_id</tt> field. The extension remains payload-only and <bcp14>MUST NOT</bcp14> impose a
mandatory transport or OAuth dependency. Any transaction-token guidance is
informative and <bcp14>SHOULD</bcp14>-oriented so that the base profile remains transport-
neutral.</t>
    </section>
    <section anchor="block">
      <name>The <tt>org.agentactioncapsule.otel</tt> Block</name>
      <t>A Capsule <bcp14>MAY</bcp14> carry a top-level payload member named
<tt>org.agentactioncapsule.otel</tt>. The member name is reverse-DNS namespaced.
<xref target="I-D.mih-scitt-agent-action-capsule"/>'s Section "Namespacing convention"
currently states this rule only for three producer-local vocabularies
(constraint id/check_type, <tt>compliance.framework_tags</tt>, and
<tt>assurance.sources[].kind</tt>); it does not yet generalize the bare-name/
namespaced-name split to top-level payload members; revision -05 left that
section unchanged. This document adopts the same convention for its own
member — bare names reserved for values the base profile seeds, new members
namespaced — and the authors request that -06 generalize the rule explicitly.</t>
      <t>Where the block lives. Until the base profile admits namespaced top-level
members explicitly, the one payload container the base profile already
treats as extensible is <tt>model_attestation.compute_attestation</tt> (see
draft-palanisamy-scitt-aac-runtime). The reference emitter therefore
places this block at
<tt>model_attestation.compute_attestation["org.agentactioncapsule.otel"]</tt>
today (see <xref target="impl"/>), with field names, tiers, and shape exactly as defined
here. A producer <bcp14>MAY</bcp14> place the block at either path. A verifier that
implements this extension <bcp14>MUST</bcp14> recognize the block at either path and <bcp14>MUST</bcp14>
treat the two placements identically; only the JSON path differs.</t>
      <t>The block participates in the derived identifier like every other payload
member: it is canonicalized under JCS <xref target="RFC8785"/> and covered by <tt>capsule_id</tt>.
A verifier that does not implement this extension <bcp14>MUST</bcp14> ignore the block for
verification purposes and <bcp14>MUST NOT</bcp14> fail a Capsule because it is present.</t>
      <table>
        <thead>
          <tr>
            <th align="left">Field</th>
            <th align="left">Type</th>
            <th align="left">Req</th>
            <th align="left">Tier</th>
            <th align="left">Meaning</th>
          </tr>
        </thead>
        <tbody>
          <tr>
            <td align="left">trace_id</td>
            <td align="left">string (32 lowercase hex)</td>
            <td align="left">
              <bcp14>REQUIRED</bcp14></td>
            <td align="left">clear-safe, conditional (see <xref target="privacy"/>)</td>
            <td align="left">The W3C trace ID of the span that observed the action.</td>
          </tr>
          <tr>
            <td align="left">span_id</td>
            <td align="left">string (16 lowercase hex)</td>
            <td align="left">
              <bcp14>REQUIRED</bcp14></td>
            <td align="left">clear-safe, conditional</td>
            <td align="left">The W3C span ID of that span.</td>
          </tr>
          <tr>
            <td align="left">parent_span_id</td>
            <td align="left">string (16 lowercase hex)</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">clear-safe, conditional</td>
            <td align="left">Parent of <tt>span_id</tt>, when known to the producer.</td>
          </tr>
          <tr>
            <td align="left">trace_flags</td>
            <td align="left">string (2 lowercase hex)</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">clear-safe</td>
            <td align="left">W3C trace flags as sampled by the producer.</td>
          </tr>
          <tr>
            <td align="left">tracestate_digest</td>
            <td align="left">string (64 lowercase hex)</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">digest-only</td>
            <td align="left">SHA-256 over the <tt>tracestate</tt> header value as received. <tt>tracestate</tt> <bcp14>MUST NOT</bcp14> be carried in clear (vendor entries may carry identifiers).</td>
          </tr>
          <tr>
            <td align="left">span_name</td>
            <td align="left">string</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">clear-safe, conditional</td>
            <td align="left">The span's name, only when it is a fixed operation name and never user-derived.</td>
          </tr>
          <tr>
            <td align="left">resource</td>
            <td align="left">object</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">see <xref target="resource"/></td>
            <td align="left">A closed subset of OpenTelemetry resource attributes.</td>
          </tr>
          <tr>
            <td align="left">semconv</td>
            <td align="left">object</td>
            <td align="left">
              <bcp14>OPTIONAL</bcp14></td>
            <td align="left">see <xref target="semconv"/></td>
            <td align="left">GenAI semantic-convention attributes admitted by this document, plus <tt>semconv.source</tt> = the conventions repository and commit or release the names are drawn from.</td>
          </tr>
        </tbody>
      </table>
      <t>Additional members under <tt>org.agentactioncapsule.otel</tt> <bcp14>MUST</bcp14> be namespaced (URI or reverse-DNS
prefix). A verifier <bcp14>MUST</bcp14> ignore members it does not recognize.</t>
      <section anchor="resource">
        <name>Resource attributes</name>
        <t>Only the following resource attributes <bcp14>MAY</bcp14> appear under <tt>resource</tt>, and
only when their values are deployment constants rather than per-user or
per-session values:</t>
        <table>
          <thead>
            <tr>
              <th align="left">Attribute</th>
              <th align="left">Tier</th>
              <th align="left">Note</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">service.name</td>
              <td align="left">clear-safe</td>
              <td align="left">Deployment-assigned.</td>
            </tr>
            <tr>
              <td align="left">service.version</td>
              <td align="left">clear-safe</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">service.namespace</td>
              <td align="left">clear-safe</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">deployment.environment.name</td>
              <td align="left">clear-safe</td>
              <td align="left"> </td>
            </tr>
            <tr>
              <td align="left">telemetry.sdk.name / telemetry.sdk.version</td>
              <td align="left">clear-safe</td>
              <td align="left"> </td>
            </tr>
          </tbody>
        </table>
        <t><tt>service.instance.id</tt>, <tt>host.name</tt>, <tt>host.id</tt>, <tt>container.id</tt>, and any
attribute that identifies a machine or process instance are digest-only at
most and <bcp14>SHOULD</bcp14> be omitted: they are stable identifiers with small effective
entropy in most fleets, and the base profile's warning that hashing is not
anonymization applies.</t>
      </section>
      <section anchor="semconv">
        <name>GenAI semantic conventions</name>
        <t>The OpenTelemetry GenAI conventions <xref target="OTEL-GENAI"/> now live in their own
repository (<tt>open-telemetry/semantic-conventions-genai</tt>; the pages in the
main semantic-conventions repository redirect there as of v1.44.0). They
are not yet stable, so <tt>semconv.source</tt> <bcp14>MUST</bcp14> name the repository and the
commit or release the attribute names were taken from; this revision was
written against commit <tt>8c1b98a</tt>.</t>
        <t>Where a Capsule already carries the same fact, this extension does not
duplicate it; where the convention carries a fact the Capsule lacks, the
attribute <bcp14>MAY</bcp14> be admitted under <tt>semconv</tt> at the tier shown. Attributes not
listed are not admitted until a revision classifies them (allow-list stance).</t>
        <table>
          <thead>
            <tr>
              <th align="left">GenAI attribute</th>
              <th align="left">Disposition; note / Capsule counterpart</th>
            </tr>
          </thead>
          <tbody>
            <tr>
              <td align="left">gen_ai.provider.name</td>
              <td align="left">clear-safe; (replaces the retired <tt>gen_ai.system</tt>) <tt>model_attestation.provider</tt> when present; do not carry in both</td>
            </tr>
            <tr>
              <td align="left">gen_ai.request.model / gen_ai.response.model</td>
              <td align="left">clear-safe; <tt>model_attestation.model_id</tt> (<bcp14>RECOMMENDED</bcp14> there); do not carry in both</td>
            </tr>
            <tr>
              <td align="left">gen_ai.operation.name</td>
              <td align="left">clear-safe; <tt>chat</tt>, <tt>execute_tool</tt>, <tt>invoke_agent</tt>, <tt>invoke_workflow</tt>, … — informs <tt>action_type</tt> mapping only</td>
            </tr>
            <tr>
              <td align="left">gen_ai.agent.id / gen_ai.agent.name / gen_ai.agent.version</td>
              <td align="left">clear-safe; corresponds to the Capsule's <tt>developer</tt>; carry only if it adds a version the Capsule lacks</td>
            </tr>
            <tr>
              <td align="left">gen_ai.workflow.name</td>
              <td align="left">clear-safe, conditional; fixed workflow names only; never user-derived</td>
            </tr>
            <tr>
              <td align="left">gen_ai.tool.name / gen_ai.tool.type</td>
              <td align="left">clear-safe; tool identity, not arguments</td>
            </tr>
            <tr>
              <td align="left">gen_ai.tool.call.id</td>
              <td align="left">clear-safe, conditional; joinable by the producer to the effect record; carry only if non-identifying</td>
            </tr>
            <tr>
              <td align="left">gen_ai.usage.input_tokens / output_tokens / reasoning.output_tokens / cache_*.input_tokens</td>
              <td align="left">clear-safe; counts are not content</td>
            </tr>
            <tr>
              <td align="left">gen_ai.request.temperature, top_p, top_k, max_tokens, seed, stop_sequences, reasoning.level, choice.count</td>
              <td align="left">clear-safe; decoding parameters; <tt>model_attestation.decoding</tt> when present</td>
            </tr>
            <tr>
              <td align="left">gen_ai.response.finish_reasons / gen_ai.response.status / gen_ai.output.type</td>
              <td align="left">clear-safe</td>
            </tr>
            <tr>
              <td align="left">gen_ai.response.id / gen_ai.request.previous_response.id</td>
              <td align="left">digest-only; provider-assigned ids are correlation handles into provider logs</td>
            </tr>
            <tr>
              <td align="left">gen_ai.data_source.id / gen_ai.memory.store.id</td>
              <td align="left">clear-safe, conditional; only when a deployment constant naming a store, never a per-user store</td>
            </tr>
            <tr>
              <td align="left">gen_ai.prompt.name / gen_ai.prompt.version</td>
              <td align="left">clear-safe, conditional; small value spaces; if a deployment treats prompt identity as sensitive, digest with a tenant-private salt — an unsalted digest of a small vocabulary is dictionary-recoverable</td>
            </tr>
            <tr>
              <td align="left">gen_ai.input.messages / gen_ai.output.messages / gen_ai.system_instructions</td>
              <td align="left">
                <strong>never-enters</strong>; content; the Capsule commits content by digest through its effect record only</td>
            </tr>
            <tr>
              <td align="left">gen_ai.tool.call.arguments / gen_ai.tool.call.result / gen_ai.tool.definitions</td>
              <td align="left">
                <strong>never-enters</strong>; content</td>
            </tr>
            <tr>
              <td align="left">gen_ai.memory.records / gen_ai.memory.query.text / gen_ai.retrieval.query.text / gen_ai.retrieval.documents</td>
              <td align="left">
                <strong>never-enters</strong>; content</td>
            </tr>
            <tr>
              <td align="left">gen_ai.prompt.variable.* (incl. <tt>gen_ai.prompt.variable.user_name</tt>)</td>
              <td align="left">
                <strong>never-enters</strong>; template variables carry user data by construction</td>
            </tr>
            <tr>
              <td align="left">gen_ai.conversation.id, mcp.session.id, <tt>session_id</tt>, enduser.<em>, user.</em></td>
              <td align="left">
                <strong>never-enters</strong>; end-user or session identity; excluded, not digested</td>
            </tr>
            <tr>
              <td align="left">gen_ai.evaluation.* (name, result, score.*, explanation)</td>
              <td align="left">out of scope; judgments about a run belong to the reasoning/judging extension, not to a correlation block; a Capsule's own verdict is in the base profile's disposition</td>
            </tr>
            <tr>
              <td align="left">gen_ai.client.* / gen_ai.server.* metrics, mcp.*.session.duration</td>
              <td align="left">out of scope; metrics are not per-action facts</td>
            </tr>
          </tbody>
        </table>
      </section>
      <section anchor="evidence-store">
        <name>Relationship to evidence stores and evidence exchange</name>
        <t>This extension is a correlation profile for a Capsule, not a general
observability ingestion format and not an evidence-exchange protocol. A
local evidence store <bcp14>MAY</bcp14> index the relationship between a Capsule and
OpenTelemetry records without placing all OpenTelemetry metadata in the
Capsule. Likewise, an evidence bundle <bcp14>MAY</bcp14> carry or selectively disclose the
correlated OpenTelemetry record under its own authorization and disclosure
rules.</t>
        <t>The presence of this block therefore says only that the Capsule producer
bound a correlation handle to the Capsule. It does not establish that every
relevant span was captured, that the span is independent of the Capsule
producer, or that the span's semantic interpretation is correct.</t>
      </section>
      <section anchor="replay">
        <name>Capsules produced from exported telemetry</name>
        <t>A Capsule <bcp14>MAY</bcp14> be produced after the fact from spans already exported to an
observability backend, for example when an operator onboards an existing
deployment by replaying its telemetry. Such a Capsule <bcp14>MUST</bcp14> carry the base
profile's <tt>provenance_mode</tt> block with <tt>mode: "backfilled"</tt>
(<xref target="I-D.mih-scitt-agent-action-capsule"/>, Section "Provenance mode and backfilled records"), and
the <tt>source_ref</tt> of that block <bcp14>SHOULD</bcp14> identify the exported span record the
Capsule was derived from. The fields of <tt>org.agentactioncapsule.otel</tt> are
then taken from the exported span rather than from a live context, and the
same tiers and allow-list apply.</t>
        <t>The base profile caps the time rung of a backfilled Capsule at what its
<tt>provenance_mode</tt> supports. A backfilled Capsule that cites a span therefore
records that the span existed when the replay ran; it does not record that
the Capsule was sealed when the span was emitted. Verifiers and coverage
reports <bcp14>MUST</bcp14> present replayed and contemporaneous Capsules separately.</t>
      </section>
    </section>
    <section anchor="reverse">
      <name>The reverse join: Capsule identifier on the span</name>
      <t>A producer that emits both a span and a Capsule for one action <bcp14>SHOULD</bcp14> set
the span attribute <tt>aac.capsule_id</tt> to the Capsule's derived identifier once
sealed, so that observability tooling can locate the sealed record from the
trace. The attribute name is proposed for registration in the OpenTelemetry
semantic-conventions registry.</t>
      <t>The span attribute is advisory. A verifier <bcp14>MUST</bcp14> recompute <tt>capsule_id</tt> from
the Capsule; a span attribute that disagrees with the recomputed value is a
defect in the span, not in the Capsule.</t>
    </section>
    <section anchor="verification">
      <name>Verification</name>
      <t>This extension defines no verification behavior beyond the base profile's
Class 1 and Class 2 verifier checks (Sections 6 and 8.2 of
<xref target="I-D.mih-scitt-agent-action-capsule"/>). Specifically:</t>
      <ul spacing="normal">
        <li>
          <t>The presence, absence, or content of <tt>org.agentactioncapsule.otel</tt> does not change the
verdict of Class 1 or Class 2 verification as established by the sealed
Capsule and the verifier's acceptance checks.</t>
        </li>
        <li>
          <t>A verifier <bcp14>MAY</bcp14> use <tt>trace_id</tt> and <tt>span_id</tt> to locate corroborating spans
but <bcp14>MUST NOT</bcp14> treat the existence of a span as evidence that the recorded
action occurred; spans are self-reported by the same producer. A coverage
or assurance report <bcp14>MUST NOT</bcp14> count a same-producer span as independent
corroboration of the Capsule it correlates with.</t>
        </li>
        <li>
          <t>Hex fields <bcp14>MUST</bcp14> be validated for length and case when present; a malformed
value renders the block informational-only and <bcp14>SHOULD</bcp14> be reported.</t>
        </li>
      </ul>
    </section>
    <section anchor="privacy">
      <name>Privacy Considerations</name>
      <t>The base profile's data-admission tiers govern every field in this block. This
section states what the tiers mean for OpenTelemetry values because the
intuition that an opaque identifier is harmless does not hold here.</t>
      <t><strong>Trace and span identifiers are correlation handles.</strong> A trace ID is
clear-safe only when it is non-identifying on its own: it names an execution,
not a person. But a trace ID is also a lookup key into every system that
indexed the same trace — request logs, APM backends, gateway access logs — and
some of those systems hold end-user data. Committing a trace ID in clear into a
record that may later be disclosed to a third party therefore gives that party
a key into systems the disclosure never covered. Producers <bcp14>MUST</bcp14> classify trace
and span IDs as clear-safe only when the observability systems they index do
not themselves hold end-user identity, or when disclosure of the Capsule is
confined to parties that already hold access to those systems. Otherwise the
IDs <bcp14>MUST</bcp14> be carried as digests, or a pairwise correlation identifier <bcp14>MUST</bcp14> be
used instead.</t>
      <t><strong>What the block's fields must never be.</strong> Regardless of tier, no field of
<tt>org.agentactioncapsule.otel</tt> <bcp14>MAY</bcp14> carry: prompt or completion content; message bodies; tool
arguments or results; end-user identifiers or session identifiers, in clear or
as a digest; OpenTelemetry baggage entries <xref target="OTEL-BAGGAGE"/>; <tt>tracestate</tt> in
clear; or resource attributes that identify a natural person or a single
device. Hashing is not anonymization for low-entropy values (base profile,
"Data-Admission Tiers"); the digest-only tier is for content that must be
provable later, not for identifiers that must be hidden.</t>
      <t><strong>Allow-list stance.</strong> Adapters implementing this extension <bcp14>SHOULD</bcp14> admit
only the attributes enumerated in this document and default-deny all others,
per the base profile's adapter allow-list pattern. New GenAI attributes added
by later convention versions are not admitted until a revision of this
document classifies them.</t>
    </section>
    <section anchor="security-considerations">
      <name>Security Considerations</name>
      <t>The block is covered by the Capsule signature, the derived identifier, and the
verifier acceptance path used to seal and accept the Capsule. It <bcp14>MUST NOT</bcp14> be
altered without detection. It adds no authority: a span is the producer's own
telemetry, and the join it enables is between two records from one party.
Corroboration from a second party is provided by the base profile's
<tt>assurance.cross_party_rung</tt> mechanism (Section 5.4.1 of
<xref target="I-D.mih-scitt-agent-action-capsule"/>), not by this extension.</t>
    </section>
    <section anchor="impl">
      <name>Implementation Status</name>
      <t>This section records the status of known implementations of this
extension at the time of posting, per <xref target="RFC7942"/>. It is to be removed
before publication as an RFC.</t>
      <t>capsule-emit (Apache-2.0, Python): ships an OpenTelemetry SDK
<tt>SpanExporter</tt> that seals effect spans as Capsules and writes this block.
It applies the allow-list in <xref target="semconv"/> as default-deny and carries
<tt>trace_id</tt>, <tt>span_id</tt>, <tt>parent_span_id</tt>, and <tt>span_name</tt> as SHA-256 digests
unless a deployment opts into clear values, taking the conservative branch
of <xref target="privacy"/> by default. It places the block under
<tt>model_attestation.compute_attestation</tt> as described in the block section.
The exporter is accompanied by a leak test that runs the real block builder
against a deliberately poisoned allow-list to show the leak, then against
the real table to show none.</t>
    </section>
    <section anchor="registration">
      <name>Conformance Vectors</name>
      <t>This is a tier-2 (per-profile) extension in the sense of
<xref target="I-D.mih-agent-accountability-conformance"/>: it defines its own semantics
and must-fail cases on top of the tier-1 binding conformance that
<xref target="I-D.mih-sokolov-scitt-payload-binding"/> (CPB) defines for every AAC
payload member. This document is not itself a binding-layer artifact and
does not register a <tt>type</tt> in the CPB Artifact Type Registry; that registry
governs the <tt>type</tt> field of typed digest references (for example, an
<tt>attestation_refs</tt> entry in the runtime extension), a different and
narrower thing than a named payload extension like this one.</t>
      <t>As of this writing, the registry structure for tier-2 (per-profile)
conformance artifacts is explicitly not yet specified —
<xref target="I-D.mih-agent-accountability-conformance"/> states plainly that this is
"TBD in a future revision." This document therefore cannot cite a settled
registration procedure for itself, and does not assert one. What it does
provide now, so that registration is a formality once the tier-2 registry
exists rather than a rewrite, is the two-sided conformance-vector set that
document's discipline (Section 5) requires of any record profile: positive
vectors with pinned values, and must-fail vectors that a conformant
implementation <bcp14>MUST</bcp14> refuse rather than merely mismatch.</t>
      <t>Positive vector (<bcp14>MUST</bcp14> be accepted, and <bcp14>MUST</bcp14> reproduce the same <tt>capsule_id</tt>
under JCS <xref target="RFC8785"/> canonicalization as any other payload member):</t>
      <sourcecode type="json"><![CDATA[
{
  "org.agentactioncapsule.otel": {
    "trace_id": "4bf92f3577b34da6a3ce929d0e0e4736",
    "span_id": "00f067aa0ba902b7",
    "trace_flags": "01",
    "resource": { "service.name": "support-agent" },
    "semconv": {
      "source": "open-telemetry/semantic-conventions-genai@8c1b98a",
      "gen_ai.provider.name": "local",
      "gen_ai.operation.name": "execute_tool"
    }
  }
}
]]></sourcecode>
      <t><bcp14>MUST</bcp14>-FAIL vectors (a conformant implementation <bcp14>MUST</bcp14> reject the field, or
<bcp14>MUST</bcp14> treat the block as informational-only per <xref target="block"/> and <xref target="privacy"/>):</t>
      <artwork><![CDATA[
// (a) malformed trace_id: 31 hex characters, and mixed case.
{ "org.agentactioncapsule.otel": {
    "trace_id": "4BF92F3577b34da6a3ce929d0e0e473",
    "span_id": "00f067aa0ba902b7" } }

// (b) tracestate carried in clear; MUST be a digest or absent.
{ "org.agentactioncapsule.otel": {
    "trace_id": "4bf92f3577b34da6a3ce929d0e0e4736",
    "span_id": "00f067aa0ba902b7",
    "tracestate": "congo=t61rcWkgMzE" } }

// (c) semconv member outside the allow-list in {{semconv}}.
{ "org.agentactioncapsule.otel": {
    "trace_id": "4bf92f3577b34da6a3ce929d0e0e4736",
    "span_id": "00f067aa0ba902b7",
    "semconv": { "gen_ai.input.messages":
                 [{"role": "user", "content": "…"}] } } }
]]></artwork>
    </section>
    <section anchor="iana-considerations">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions. The <tt>org.agentactioncapsule.otel</tt> member
name is a namespaced payload member per <xref target="block"/> and is not IANA-governed.
Registration of this document as a conforming tier-2 profile awaits the
registry work noted in <xref target="registration"/>; this document requests no IANA
action for it. Registration of the <tt>aac.capsule_id</tt> span attribute is
requested of the OpenTelemetry semantic-conventions registry, not IANA.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-combined-references">
      <name>References</name>
      <references anchor="sec-normative-references">
        <name>Normative References</name>
        <reference anchor="RFC8785">
          <front>
            <title>JSON Canonicalization Scheme (JCS)</title>
            <author fullname="A. Rundgren" initials="A." surname="Rundgren"/>
            <author fullname="B. Jordan" initials="B." surname="Jordan"/>
            <author fullname="S. Erdtman" initials="S." surname="Erdtman"/>
            <date month="June" year="2020"/>
            <abstract>
              <t>Cryptographic operations like hashing and signing need the data to be expressed in an invariant format so that the operations are reliably repeatable. One way to address this is to create a canonical representation of the data. Canonicalization also permits data to be exchanged in its original form on the "wire" while cryptographic operations performed on the canonicalized counterpart of the data in the producer and consumer endpoints generate consistent results.</t>
              <t>This document describes the JSON Canonicalization Scheme (JCS). This specification defines how to create a canonical representation of JSON data by building on the strict serialization methods for JSON primitives defined by ECMAScript, constraining JSON data to the Internet JSON (I-JSON) subset, and by using deterministic property sorting.</t>
            </abstract>
          </front>
          <seriesInfo name="RFC" value="8785"/>
          <seriesInfo name="DOI" value="10.17487/RFC8785"/>
        </reference>
        <reference anchor="I-D.mih-scitt-agent-action-capsule">
          <front>
            <title>An Agent Action Capsule Profile for SCITT</title>
            <author fullname="Steven Mih" initials="S." surname="Mih">
              <organization>Action State Group, Inc.</organization>
            </author>
            <date day="26" month="September" year="2026"/>
            <abstract>
              <t>   This document defines a SCITT statement profile for recording what an
   AI agent did: the Agent Action Capsule.  A Capsule is a digest-
   committed record of one agent action carrying its verdict-level
   disposition (executed, blocked, denied, errored, timed out), the
   deterministic constraints that were evaluated, the effect that was
   committed together with a confirmed-effect binding that distinguishes
   a dispatched attempt from an observed result, and an honest human-in-
   the-loop flag.  Capsules are identified independently of signing and
   MAY be authenticated by one or more COSE_Sign1 Producer Envelopes.
   Its Capsule ID can separately be made transparent by registration in
   a SCITT Transparency Service.  A Capsule is recorded on every
   verdict, including refusals: a blocked or denied Capsule is the
   auditor-grade evidence that a gate worked.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-mih-scitt-agent-action-capsule-05"/>
        </reference>
        <reference anchor="I-D.mih-sokolov-scitt-payload-binding">
          <front>
            <title>Canonicalization Declaration for SCITT Signed Statements</title>
            <author fullname="Steven Mih" initials="S." surname="Mih">
              <organization>Action State Group, Inc.</organization>
            </author>
            <author fullname="Anton Sokolov" initials="A." surname="Sokolov">
              <organization>Tyche Institute</organization>
            </author>
            <date day="12" month="September" year="2026"/>
            <abstract>
              <t>   Independently written systems that anchor records to a SCITT
   Transparency Service repeatedly need the same construction: a
   canonical form of structured content, a content-addressed identifier
   derived from that form, binding to a SCITT Signed Statement and
   Receipt, and references that cite external artifacts by digest.  This
   document, referred to as CPB, specifies that construction as
   declarations rather than as a payload format.  A payload profile
   declares its canonicalization algorithm and exclusion set and thereby
   obtains a reproducible derived identifier.  A CPB Signed Statement
   carries either the complete statement content as specified by RFC
   9943 or a digest of content held elsewhere using the COSE Hash
   Envelope of RFC 9995.  CPB also defines an abstract typed digest
   reference information model and one optional protected-header
   encoding, cpb-refs; a payload profile may instead define its own
   reference serialization.  An IANA registry assigns the
   canonicalization algorithm identifiers that these declarations name.
   CPB does not define payload content formats, establish or require a
   universal artifact-type registry, or require either typed-reference
   carrier.

              </t>
            </abstract>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-mih-sokolov-scitt-payload-binding-05"/>
        </reference>
        <reference anchor="W3C.TraceContext" target="https://www.w3.org/TR/trace-context/">
          <front>
            <title>Trace Context</title>
            <author>
              <organization>W3C</organization>
            </author>
            <date year="2021"/>
          </front>
        </reference>
        <reference anchor="RFC2119">
          <front>
            <title>Key words for use in RFCs to Indicate Requirement Levels</title>
            <author fullname="S. Bradner" initials="S." surname="Bradner"/>
            <date month="March" year="1997"/>
            <abstract>
              <t>In many standards track documents several words are used to signify the requirements in the specification. These words are often capitalized. This document defines these words as they should be interpreted in IETF documents. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="2119"/>
          <seriesInfo name="DOI" value="10.17487/RFC2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front>
            <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
            <author fullname="B. Leiba" initials="B." surname="Leiba"/>
            <date month="May" year="2017"/>
            <abstract>
              <t>RFC 2119 specifies common key words that may be used in protocol specifications. This document aims to reduce the ambiguity by clarifying that only UPPERCASE usage of the key words have the defined special meanings.</t>
            </abstract>
          </front>
          <seriesInfo name="BCP" value="14"/>
          <seriesInfo name="RFC" value="8174"/>
          <seriesInfo name="DOI" value="10.17487/RFC8174"/>
        </reference>
      </references>
      <references anchor="sec-informative-references">
        <name>Informative References</name>
        <reference anchor="RFC7942">
          <front>
            <title>Improving Awareness of Running Code: The Implementation Status Section</title>
            <author fullname="Y. Sheffer" initials="Y." surname="Sheffer"/>
            <author fullname="A. Farrel" initials="A." surname="Farrel"/>
            <date month="July" year="2016"/>
          </front>
          <seriesInfo name="BCP" value="205"/>
          <seriesInfo name="RFC" value="7942"/>
          <seriesInfo name="DOI" value="10.17487/RFC7942"/>
        </reference>
        <reference anchor="I-D.mih-agent-accountability-conformance" target="https://datatracker.ietf.org/doc/draft-mih-agent-accountability-conformance/">
          <front>
            <title>Agent Accountability: A Conformance and Verification Method</title>
            <author initials="S." surname="Mih" fullname="Steven Mih">
              <organization>Action State Group, Inc.</organization>
            </author>
            <date year="2026" month="July" day="31"/>
          </front>
          <seriesInfo name="Internet-Draft" value="draft-mih-agent-accountability-conformance-00"/>
        </reference>
        <reference anchor="OTEL-GENAI" target="https://github.com/open-telemetry/semantic-conventions-genai">
          <front>
            <title>OpenTelemetry GenAI Semantic Conventions (repository open-telemetry/semantic-conventions-genai, commit 8c1b98a)</title>
            <author>
              <organization>OpenTelemetry</organization>
            </author>
            <date year="2026" month="September"/>
          </front>
        </reference>
        <reference anchor="OTEL-BAGGAGE" target="https://opentelemetry.io/docs/specs/otel/baggage/api/">
          <front>
            <title>OpenTelemetry Baggage</title>
            <author>
              <organization>OpenTelemetry</organization>
            </author>
            <date>n.d.</date>
          </front>
        </reference>
      </references>
    </references>
    <?line 435?>

<section anchor="example">
      <name>Example</name>
      <sourcecode type="json"><![CDATA[
{
  "spec_version": "draft-mih-scitt-agent-action-capsule-05",
  "format_version": "4",
  "canonicalization_id": "jcs",
  "capsule_id": "…",
  "action_id": "act-7f3e…",
  "action_type": "decide",
  "operator": "example-tenant",
  "developer": "support-agent@2.3.1",
  "timestamp": "2026-09-04T18:02:11Z",
  "org.agentactioncapsule.otel": {
    "trace_id": "4bf92f3577b34da6a3ce929d0e0e4736",
    "span_id": "00f067aa0ba902b7",
    "trace_flags": "01",
    "resource": { "service.name": "support-agent",
                  "service.version": "2.3.1" },
    "semconv": {
      "source": "open-telemetry/semantic-conventions-genai@8c1b98a",
      "gen_ai.provider.name": "local",
      "gen_ai.operation.name": "execute_tool",
      "gen_ai.usage.input_tokens": 412,
      "gen_ai.usage.output_tokens": 88
    }
  }
}
]]></sourcecode>
    </section>
    <section anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>The authors thank the maintainers of the OpenTelemetry GenAI semantic
conventions, whose attribute vocabulary this document admits by reference,
and the contributors to the capsule-emit OpenTelemetry exporter, whose
implementation shaped the digest-only defaults in <xref target="privacy"/>.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA9Vc63LbRpb+30/Rq/yI5CKoix1fpJnZyJc4mo0vayuTmk2l
xCbQJBGBAAcNSuY4mpqH2AfYX/Mg+yjzJHtu3WiAsKzJbtXUuso2CQLdp0+f
851rI0kS1eRNYY/1zpuVLc9tYZe2qTf6WVXXtjBNXpX6xYfGlg4/zapan85t
2ejTlH56ZlZuXVi3o8x0WtsrGOf09Jl+AwO1j+2orEpLs4RZstrMmmRlClPm
ziw3iUvzpkmMSZOqsUVycKBS09h5VW+OdV7OKpWv6mPd1GvXHB0cPDk4Uqa2
5li/t+m6zpuNurSb66rOjvWP75+dnZ+PdGcdI22Q3JFOmVD40C5spFd1fmXS
zU/KNabMLkxRlUDkxjq1ymHEpkpH2lV1U9uZg0+bJX74SSmzbhZVfax0AkS6
Y/1yrN+GNSmtNa/2ZXWVl5mpzc+9n6t6Dt/+TFQAy87KzALVGVC6gz/bpckL
uF6u5jhCgyOY8us5Xh6n1XInTPx+rF/li3bG9429sqW/1p1Gtux9AwzWL+tq
vRrpszIdRzM6evxrQ3c6vHFscqXKql7CIFcWVqzfffPs8aPHX+HHs+T5eJkv
/CYipxN+NhF+d+6qLquiupK7V2ZTVCZLpsChvJzjjT/cfzY+r01qn1VlYz80
eE1rL5/0i5afdvgnU89tc6wXTbNyx/v719fX4+v7Y1j2/vm7/QYfSFJ+YJ8e
CPtGfxJk0DFOSxcyWO6xPjo4OlQKRa+75kdPHhzFq/GrTas1bNA0L0AYcTJ6
rkxtl3ivNPHdsCO4HP+ABgnUf7B1PstT1rtXFqjNhpcKxBpc4KWtx7ltZrRo
ULN91rC7UDjMkp5Y0Z8h2aI/xL/b5Kpl6sPk4FFy/5AuOlildchjP+8ZbFJd
2iZ5juR7nLjLKhAyNADOi++Sly9en551+d4FtZe2PD0D6IAHmzxF5sOCSNT1
bm1XlcsbAB5dwUNJ45/ad3I/zurvT4AqkyOaLJd5ox+nh9Mnj83e8F7N82ax
nqLi7t956E+La2dJWzx+4pnx9PTly9OXL25jx1MznwN7h4lGSgOh47xC4XL7
bmXhX4Tq/Sk/vW9W+S3K1aVWJUmizdSh5DZKnS9yp2Hc9RK1I7OzvLROT+DB
MW07Y4lAyRhnnQCgkzi6FSh3pgVFlO2YqGZhB80U4H01y2EofQ53tM+kpkaB
VF32EH6QVsJkcBMDiUYjMXd5Bj+BIJsCqIiRT9cWTAw8U6lmYRqixU+PY+H3
agoacCXCTKMDG6xL6xzQcE63gKWA+3nEFGafWvVzBeyByWagKnTPDH4f67NG
L2F8urIl7rYmDNMg9l7WVCRrGtZUBfJmuS0yp68XtsbFwagrJAf26NoWhexP
xhxBZXfqepGni96sV6ZYwy6++v79uX795lyjGNUwXGACsrDob0FWwXBlhb/h
7f7mqwgPj2EQ/k7rh3HwIY0P5csVTg8bDsoI1to0TiE/pkWVXmrjdMDzqjTF
mOVwmWdZYZX6AtGnrrI1cVsplpwa4CYHOQPTCGN2l8g7RpJWVQXsT1GAe7Cs
MvB68vKqYnrdSCGrFvBPNZs5XvFtYqk+fvy8Rb25Ianj/SZnxq0qMqFe8ljo
lJ3NbNroKeAmuCDoCQExsA2FcU4ftpyE/coRQRzybmphVRY/wa4D6NpVgzvu
lL0CiQe4xVXAT+3GLc2lZWJQPuGHVZED8ccdwRcFI7p6aoXDNkQJTOhcleYG
p7wGzKQhePWjoDusi4aVdqOiWb5EJQKHDp5uB8XNh5tN04ByrZtt+r2cqhQ2
am5pjqlxNjAKdpk/HnWkkbd7DDZ8WyZVVyabjqTThCSj+tMiSsvFO1U+L2VH
UN46FKzWNdgs60Cez68rBCgEVvAXHexKA2o01t/ktQPvtxlesygbkvGWFMDW
6gWAQwHgrwVHiRcioMDhDgEeUkS24a4GRA74v7AGtkJXM22Ul4EafUxQm7QA
mjM93WwNr3bvpgAj9P6JgB2JMRhJd/ZEyItCCZZ5zCJIKxAJQUZjyRQDokFJ
CKUi2wKRxVjBTKBdwxzkTexCQ1ec42hDIRAUqGaIuW4DvvbSscwszUYvqiID
rMySNdgGNOmGmdrjv8mWuUMSIG6jOVarAjhZaWsAiWnVYBJANkwNG7MuTD3S
E1K5izybEHsmqEL8rbYqLaypE2dmsOMlDAXoTxza4K8ArmUiS9ogxKBaCgdX
IjFAlEtBYEAVRLfPnhN66KKqLtcr5COvuajmAJOnb1/BosBxLTPH+zUHjb8G
FjB+tTxRxJMOP2Bc4QXSUDNaeccB7DFoeUr2pbpOitw1LA+l8rCks3xuXZPQ
Ukn6SzaQYCcXrMIl7yuuFj5XK/Onte0CCuxkvYSddCjEMLlZF80Y7UjsUOLE
z5GwnL6js2OJFde0xh2UoJ0R/4+6iJ/fvfj378/evXiOn99/e/rdd+GDkjve
f/vm+++et5/aJ5+9efXqxevn/DDqdueS2nl1+scdZvfOm7fnZ29en363w8oQ
+2C457BTU9QTYM6qtoL/4p4gtpb66bO3//1fhw/0x4//ApHR0eHhE7BK/OXx
4aMH8AWliGcLQjUiqVIgsCBwOArsEobleWPQeoKyuEV1XZKqAjfv/Yic+elY
/2aarg4f/E4u4II7Fz3POheJZ9tXth5mJg5cGpgmcLNzvcfpLr2nf+x893yP
Lv7mXwsQXZ0cPv7X3ynlsXIU4Fh7OB4N2DbQbMFE1OZgIhUqSxKAQjNQ7LaK
Poq1YKRLCOvqhNw0t0cSsHZ+0xk9YbPuhsygooIAIzbU+IFAQc0KMxd9pwvk
Qcaz6c5s/VwAjN2PF9AvrYEWwCszR9MCThu4KbTm5OArtD59C4PesjJZBk6T
E6+l64vPzQqEv7m2OKh37/vuO676yt4eLSBQVutGk1fhnfptl0JtuxRI9125
3QP621yr2sbGSIsxGqH73OKZoB278CdsBlqcre2f1nltg48X4SyjZaZieKUp
yGgEk7IklL8CtiIPcrC5HwjfkynIJt7a4rwacFdy8dMxOintNQwHri2F7LxU
2MC0MPnyuP0OA0FkD/uN8p15608ywdw2uGoMk6p6P7OsbHUI9mKzAGZkQhtB
tlNMbTeK8T6OT26xmRFXjpewRJcN3KKWdti1Enz4ukGevDmFKFr7dGC6Aata
yi2y/U0FplPP1+C0Y9YIFhglq2gyhrCkApebFu0qHULRWBsCuYGCRJV2Dd8K
Mme4tluDcf2UnNePX5ATewOhU9AVwD720GGrmmqVFMja4G0t7XIKbEVnK1O3
TsEcju5HtUcRqp1Nnr9+Hzls4zvGT+CwBP/xtTyNstfGxTsqXYOqlA3sHke6
bCZrXBntKWcZatu6QQmwAMQag78paiPmE3Zblxwkcj9d2PTyotkgmk/SCuKD
HLdwPKuBCnAL4DfASAZyEDXn1jX97qp1DYD540/jS1CZyd4JRgMh9t3YRs8p
0i/yP/v4pbYJMmZfteyhCwAMBYbI1Sc3BdS+g6KFnTUkPsoJ09Ylh0qZOGSt
85BVq8a16YuWocSvHH4DA69kM//+1/8kQnkHNapojfaNwhzOIWwJrLMWnUbS
faY2WiCNGDCaklGOMAsQiRUgOXjYZxVtqQe0Ahx+9QPFCm1ohlEDBDjfw0KK
bYrQzMK6IioCY2WhLhp+xCanbOMOBBqQD7sdbAG6gh+aQYhL+QwEKgGaaUFa
MCEAu8BID4UU2IwpxhUEufG1id4FrqlbCi+S6dhjVQOsh/UjsmDiQ8JDNgBq
VaDhZl2QuLVRdyPjx51btHznp4lqqgyMA9IK1g9j55sbCOcoDUBQyywesTfD
foRbmBVuHgyIMBs8CEUuJETmXjcJjYj4OORutM0J3VcA8luBvArxuxsM/jBY
mZdB4waGbGP4NtpvIE4nQnhgNlOYP9qcMLDgTb9//+Y1j5DlM9gNCvDDJGzw
8xWnbNieDeQ9ivwSeANL2uhKSOJUKUvlseR4UgMhHlIAK/FR8O+fvYc9kDoP
OPO4jrSCoThsj53OsRrKf+h+/mObfZLWaHkHAqYGsxtd+zkzoIVtMnFqUwMO
hCxG7Dyw6xf9DQnNL/oc4Bb+e2f/hF+QzF/0KwtaAIj/i/olSZKtv/C0j5jh
Zowp4d7d+0cQwF7bOkUdXdgPeziqBB/wMXavMWWQSyJHJFoqjSDUSAasGhxc
HcJlcVXJayMusldqW38TtArJ1RK7R3QdPvxVdLVUiKPORMDc+J0nA1FDd+du
c/ro5tY539KIOFXIQozYP7wsMfhDwxTlFpgM3gwKICIaBrZjkAT40vKaB8FY
06B4hjTUwIRk+C/YoY2mffjg1nljB/gX8MROk6OvHmpUHppn0g498VkyMnZI
E0CKRTUed28Lsj/1iVTyY2mFehcsbAYWE7hKGVb0sNnvirz/vUh2yAsIy7nj
tp2LcH7Jlm4UpYokVQwg/QHoYlca1ZfmQdWl8JK9fIEppgZ0lfwaGL6a/oyp
6g4xrDb+JkChXwChJXfo1qAeJEXdGCwMGdK9TlZul+iM3DqV3EMzcaFwoDoX
jcymv/EyFDlCI4D4NdhnGVH8t4n+reTs2yRRVHRkkKVqImwnxGkWBQwfYP8I
PSUw4qAjs7pa4rLUaRa2yLsaDOC3O+0kT1Mb+yy7378742mDY60ATGFP9zqG
MYZuP2XsiwajiPHDFwC6W/sBwULYU6XeeJM3qzCU5CLG9jNoviVvJAv0d4mz
3Mlc5sF/JJ7ZVVFtyA6RN27Q7sZhHUgs51zBAOFnMDlkpniMY7Qlp56U1oS8
rvCb6tsNRO0cXHbRsg4KPQ+UJODbAxe9JviHkPc4c++5/ri0Z0M3tUsd2/Iq
r6uSPg/RQigXqrsuu+S79nsXP0mRmniKcuIpfkAonywqxzOGL3w9+LnjkKoy
5UaFTWbTEzDLUf0xXWByDOQS4DnF/ISfjHc2TuU2allJulcyeCDhFSvocZvP
hsfJe44yI+RiuiVmI7lkhrkdhNNqhXlrTePOCmsb11aheln5a1OXnOSBRSyM
W0jdFJMr6GBtltKFQ/n6nEo2oB9dmOkgw8cvPB6x7zfUyNC5/2PbAgEQBsY0
LneASmDkFcHN7uTOrQiTEzaRACje4VSYNxjCxw6kgb+Y14i2DVeUHSL21eH4
wYPxAUcbG8VFBo5ieXOw42obOwl5SEYpauviJlI0jJ2tfDGKXlNsZzCDgjB6
InG9D3ivjVP9nKIMPJEej0kIEaOSNkdqcZmTI2Cs0G/VjjxaqmyNcSGmQfPm
RMruXQsRRjQ0VKdyBVHEpaOAMtIiRMqpbU2TwKVwc6J9GIIgRun2cQtuTBRm
8zAfK/sSjdSQ5x14lWIGk3UVhlzq3ajqwlq6R444y6qJIPR57mj7YJQTnARx
J1SKsc3H1hjkxPAK44AsXph8DEqHpeh6G9ZOqInHh6goJE2OIctEnuSS22Rv
KHD2o07YikggcQJ7RVwQj6rUU4ildESNpBfGnEvcby9jUd5Zud6lcmB6voJp
xd2omMB6s/d5KoLXNcSUSQqghBBsP9gUo3LsWcDv2KlwCUE6+gnRd0xEzWAn
4dLf//o3SqpwghE8GnYnKIU1Cf0h7Ou21NCAAPMtO/iKWJjOtSEDcxK1NTgf
EbQ1/knI0gIwMUuIgnyGrojJMsd9Ilz76CtMTKhf6TbXOv7vifi2/naBEpz0
ZMC7jWdAVvfWTZcaDkrjNVMniU9bj1j36vma8wT9ITFjMKaI7JM0YzcG2bpe
hOMZKu0hXHPtM7Jf9o3mXzvYObD6q3VzQaloB2ur1k3nO8Chq9Aijvu/pGDU
7cW97gD93V/jmj0CUSq+bIa0DtSZJH9dw+qbanWx4v8uRyCcH2T0EWUN4V/8
xeGTAE1wtaWRsnXAvkWFDg1N3yMpAy5Riw3gEuxmQ2nSAT3293VhpEu6IANW
ht3igqlwA9CBY66jH5iT26IzOHqsfZ5bK4Tuau0u4rs6EeuJ9jgYPFQQyU8W
j7iq7x+h8n5MDNZyLth+d+iBwKFC/xLMt/2MELd+vRly5FETqfKkaTApZcLX
4NPTdd01H8tVH4vk4hAY9QhiP5EjdvLDQQ5AXzrUSb6WB20rUZh0QA8A/Utf
gWXn04DXXcJyEkoSNeg7FI1ks8Hu4jfYCHkCe2o8Gb7WgGUu+J3AGb4lqNSw
GFL/aO2kc8B+58iV60vW9g9sMS/QDaq5Ow519d69uGJ8796JV9GTbs8X+U0u
6C/2SvASmkVdrecLKgh0YGjLlLRg12Lh/vaPINBr4Fj3l6xtvriN6Hg6kUzf
h9KXWFAj+JfqgpFyYd4FBOIzv/rcwJ1p8TJp6hz3cXxP7+ZlWoyDO9O/AeWd
sjuTvcE5ECwLlC7/hBPQDw02uEVcseLNjskhn7R2DHM5wOkyXY0lVKbvE/nC
KT1bZjjs+N5I8/+DJIV2J/Dafdjt9QV+/ZAW6wyhG80Ay07XvCJn10wSsIcz
UywLI+xJAniB+bH6Ykq6CxmDRXnQIWpZAiu5zua8LWaKvxjs+wQPGnt8vaUM
hmIf70a8Cb48kwb3mQ4+Ukb7pA0QvqTCFzolqKSorHEdug0js9Yx7vC+wEIu
LLFVTEwOI1cxdstTx9txL2xItpYsXH+9cn8wrgiU0mWMAQbiNydueCUQyK6o
uUy6PxlPOSUfrsE+cevkxy/8tYTuu5GOjTb0oUxhzClf68KiX2CXeD++VKe6
LRqwASAIUlRcGo756YEy0JQEmrAnsUorbNRUXKHtroUiJm5E4L2OFt42gkQd
IKqfcmSs8P0eGH+QSQJ87t4J/xrSMgmhZcyx/i6/tNe5s6N4BXq6Rhsb1dFJ
RwrOTxSIpY6yoRL8MktBPYbIkzBQCrBSGw0ZiTLzg4EfpbAg6gtO7L8AMVQa
CEW/tiPEmY3zdater7v3NxU1IPe2nR2Inm9PrewhlWgpGwAuEg9NlSyFof0V
Gn7uscEGS7NC9486NIUC7n1xtKtyqsoXWGQm5YkbcZdr9CB2M/p8TGiBY6Jz
aedMG87e+LNvfqkZpRQQb6oadyLkVijnCYKx2eqQmNr24W5fP4/FjeY+vdCO
XGEzSlctpKVyRKpkP1B5Q1ynMnS4wF5NK4PyiqL2gRt3VOS7TFFkkFRKYGHp
M+QD9ft1uoh0gTIyLJoeylQLZRN0C9GrSe0F+skTkR1yeMhzPtY7SDPcX9hs
Z/Irmn/fhimol4ckuR3Sq6Z0BVOn+ITdUfCAZ5NQ72LCJGvoox5p2haGk0iJ
LkW6SxLowz5Oy6PaSO8xFrluTcRj+21DSeuQkBqaNspV0y2GM3vSotS2/VHG
SbqCuQs6NMFik7AvIsctBqk/OIINAGj65uxfRlyMjm1cU4q2cWp7c916hTQ7
rBYMPEx8hk3lJl2ucvqmgk7Xb9BfEk4MuiWpL2IJ3ChPtkoOtCumiQ8D0NZI
/14YI6AGtzZkYzlv51nGXvPcUqIUVsMy7qM4pkAOwBD3l3CXKS3EVC0YOIsx
IuzvJvRQSVWFQvLjQGBUq68i8hAr6HYCizZqJxAkh5qyP8JGOdPhD/CQhodz
QyLSzjJn+IGQh5sYk46jUv52pmWgqwBEGASN2DoKfWVdIELnm9qpYDa0uA0n
NWUvZLu8rHPHOKtNN1fL9fxqRQW/GaV15zk2UzEWM8e6p8s+kY+mx7z495iA
Dkl2lTt077cKXUgrNbJ0Wh6I9ljUTsJmdIsZYFTNvLbWtYdZwoiZxJA4P7bZ
YgyUt1LAHlD3qAKJU3w+dMu78n3wZdU9pjG1CwORfw0fNtVgAUP5zlSUp+5p
F2yGxL41p3cFeJ1+SPc9Hh8BWtyx6W4P7MfKpkRUUWyOlUp07GKM8Fggf6jq
EA99FkIDDLSnd5QOjjY8/rlTPAgG3tNo2wFYWGGkfuuv58mX/nQUWR9m0BiW
FIsQ2HdsTfnk6Qs6EUH6gW5FNa1qPnVARh/mBklqa/9tCxEjo3hlXvJc6zgG
HGVVo2UIIFQp9TVmJ96xQBfOFrOE8S5aPypg2xNx2iIjnvnVoTVR84MtmZw8
MzRAEsDL0xh5ZDBQtGqkreOhIcQHp5YVCNn7LbjpYl19FdsfX2OQKGw5l84r
atDoZvOxplhg1EBMYQ2skZ7aRZ1InYNYbQtvW1b03CKNfMuNPXj2Aw+F8mqw
fuc7frbNLkLrUIv+HJlcStMWN735AxpEmTRG+z5M6Uy9XkRFHQdhhuF2y8FT
mb5fCvUE3Ns1x5okMoOHXWDq0BwedI2O5fhjGvfO/+Gm8/G9eyBS0Vmh4UNI
3FnST0Uj+HMcQy1s0hyBDgNWNzAm52OkGNo67Jp6SmF952RS4aqB40nMd855
SQsgxoXShMXeFY2CmTnfVzp0psmfZ0KEAL5RXlR6U5WrlhJOYezmT4ENHf56
Rvkz7qyPyPeNP0SyUZH7Q70/qC8I9CE+5GgBpajOqHcw7uifY28rP0w/KdOy
oz2hZqP4UFKs0g44DgdVRCGlKCjHIVSQirPnfBzuE4fN+iei26k3EpxnFW0r
VhoBsZDqLs/aygmIPg0b0dzHFodnoPmwCSawsaHSs8HHWjS6bCA5RtF2jfUb
ZCHG7KRIuDgPR75BCwMDylg5ogjE0eT8RKwQkabJAIpOw2DGFcgg/fohtO4j
BgB2CAAu1yB+vBtTiyr1zs4htONzHDNCA3QjBEjAUH+mK8gnGo595prsMIaR
XIn2OV5JE4MbmuV0SAT8PdWmZ8lTwxScO+nvDoPCVq5vxh29QbKrWuGhXeHf
SQ/I5LUDoeFNGh/kdQc3Nyfd5rm8ZHA5EcK2eovivpMNHQBtwLYVAh+8dw6U
sLDgp1HHi/620+Chuw0eZIUg8PIdJAK8u7EBGKmd52gAToMBwK4iiFRPRNva
xpZGUHgWeUWs7Lj9Uwq5ryjRT5rPjiN120csjx/QizyDn0i0TvsVe0LmzKwa
auzyDbzc2dJxNcUYUneACo3LEVttCfJQm3DmpnNOADNOfGwyAVI2lCyjJmU3
whasodSoYariqHZFZ5wB4V/b636XAT6Ars/UI2LUUyFlHneHHgfJe6lAeq/p
gTwA/yqingsQ92xT6ig0UMdYhFU2X8AcbORu4/vgWUaeJ3WJrwXl0WvliJBu
2MqtRY2kis6+yjl7zFtmtrHSZnwmVXTADskU4rtqTMirxdVkzmyrJnrfknjK
9DYAMNC25FoDOjGST8UmeB/1UyDIByLA/ozVs45TKPkOR4ewxXpxXIje7uAh
cghmoqMzaV05d0EPXmB6YwLwhaFC7pYhntFfjR+MD/+BUIaVzHd9BqUgYTjz
SmPCS3HW6A3SiQaJ2LwD12Y+qDENbwSB40bovDOOC5LYqmDw+tihgEAZFXWE
wMXd+/jGIjokSH4Un+qt7RLkEPSC7f9qPS2iSAj2F56DdchaE3r3xe7pCov2
ydH4YKTfbkAiyr1jjRlyeqILz++f/5uavAdJecFJrHrC6MPvrJBqn0QfUdYE
pQYbrzqnS8bqrPENc4wvrfLTIdG2ZZcPf0SIQgEAv9WlDcBGcdf5pNvdLk2J
k9AkPcFBfQO32HK1Lsm+duq9dOiJXCa2X4z4I8zq+YOfWFVD/4aO6E1RNBeK
jnmGYwHxUXLcsaiPiSGEUvh3PGwzYX5EJ7bbcUT4xoROkmms5W0fMBKoBusV
+MfWXOomHJ4C9fF9VQAzPNh0nRdIlu+VQ74UMCcnwEAmc7ChtpOLRJxaVNc0
Es5AuBe67VSYgBs1/d1gYq0/Yh9emPUHWAqe8cKUWZsb8lpGtSY0n8mR3sU6
lwDEXlyPkpQLfLVdAPjca6dubij88CkXX1oJb8Qg1xdNbkInVjAYdZTnq1be
HSXaDrW8AE1Hg3P0EaHRbW9OA9nZffb26V6ghQoAFMucnj5T3dN9/SN74sIA
+bagxC+PmWCiEwwNOMZUjKCjvW3GFZlNfRYT7gTziaq3T/Wpf4TO3byT5NuJ
iJB8VRzpsjjJGN5N1fg1dDuE02jgQUWFjREfxm0lHjP6bkJO4caTI+fa2u3G
QoAcqRI3RJWAEXiaA1GH+3dLeQlIeLdUJC50porwicXxNOAygRfBLwswr1Nz
KR1DEDowOiCMKt52z28S3vbUYNsgyxk0Pur4DwmrTxYArORRuY7URO2cP6XA
0ujZmoj1/s94pycubeSYmpLSbnnD78FqGkyYdXK01LSd+cWziDHIBlECQ23x
3DNwU//A1QV+gY5YeOxjbvPM3QwwNcXiAilkrEo53CdMDqJG6bJuxz86eGRs
Rt6dAY8kceRRxG+WuyJ8wcWxQno2cKU+zVf07obWjdjzJ+RJLEwZyq+y2cea
q/tX6MsxdFFmeJWXpc8IS495ixz+To5OW/qiA4rytkBOWc8wvROvFtxwxGKI
NJamSRcgtm+FChlb7/rg1b/wadSeucPD83zkPiRB4mS4Gj4xGJ0qjJyL3klE
gaS9Y6X+8pe//AyWQn1UWt96UPRYf6T3y+14mw5Xdh5MZ0+OZve/evRoev9B
Zh6a+6l9cvQkO7AH9sGj+w93RvyMWHp85OBgdvDwkTEHU/Pk4Gj6yN8SHTWj
2w79Dz50RApgpOg4Bt4n5S9WxB194ydk/yRQjZf8KDt37r//WjrPhRQYZKgV
GoekBoet27rdwXhf3AnMb/+7Ufj3BjdCKdz45JvTs++C8O3GgqeHBe9n6fRn
JMesh7rTq644zmWvld8jwCdO4zOTLCJqfx8o2WuTuOGY5rG+f4iH8bAMgK8W
DEeEl9S5i9Z3rD7+GtF6+s2To28+KVp3kSx9A5wl0qd78atP+kf5TkIOyYRe
v5qrIs2vJP7/WC+IbrwLZGFe/bZ5eFinP1zOX/35RbTIdC+ctpOD/hBe0usS
b/Xg/+krjHQ1aE63YXLHv9oy+vPjx526KogpmOjCdy9JlgYv/f2vf9u5+Ql5
o0W1IEA8fX06kCmIrezCUPBNd8qreMd3eBkHs1v54unQezL9lmxrmziCOGfC
3hnWN97FFte7Om0ex7UGibwnNr3h/QXXJufXQajgEGEPPR35kNf8dBz3m5Pe
BJJkD9xQvlWN/Imx3iZvoKy9VfFVMqzN/DO9tzveVkYeBTbJWyQx7Y/7+oI9
054tQ4/tQhJOKBHte20/nWFIDr4iodxhkIwff8A/9M2riPbPqfO/++V7KaTL
cnqDr8KX5NHsvu3/iu43UQquZmb5J98+xLaD1plwyzL/Hk5kbNnCr4/G98ds
RHfodZoNPI13ydtqk4MH54ePjw+Ojg8P/0Mm+2fD3P/W/I+2YaJ9JNpMZs3/
L2ehf/v2aRB45MHh0fB9ncMgcOPjx9vOB6jSaYo5MIgnuDWXE6n+hS7o01IL
osYziHym1A0rcvd4ZfzeW3znAL2GKcBC1EvfAzl+wQs1xkksyu91lbwOD0CU
cf9MJ3fWJcinW2T6vgdP7zPJtkoAkhZyjJjBKRqr/wGo8GNwvl8AAA==

-->

</rfc>
