<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.helixar-hdp-agentic-delegation" target="https://datatracker.ietf.org/doc/html/draft-helixar-hdp-agentic-delegation-03">
   <front>
      <title>Human Delegation Provenance Protocol (HDP): Cryptographic Chain-of-Custody for Agentic AI Systems</title>
      <author initials="A." surname="Dalugoda" fullname="Asiri Dalugoda">
         <organization>Helixar Limited</organization>
      </author>
      <date month="October" day="6" year="2026" />
      <abstract>
	 <t>   Agentic AI systems operate on behalf of human principals, often
   delegating tasks through multi-step chains of AI agents.  There is
   currently no standard mechanism to record who authorized an agent to
   act, under what scope, and through what chain of delegation, in a way
   that can be verified offline, without a central registry, and without
   third-party trust anchors.

   This document specifies the Human Delegation Provenance Protocol
   (HDP) version 0.1, a lightweight token-based protocol that captures,
   structures, cryptographically signs, and verifies human delegation
   context in agentic AI systems.  An HDP token binds a human
   authorization event to a session, records each agent&#x27;s delegation
   action as a signed hop in an append-only chain, and lets an auditor
   verify the integrity of the full record using only the issuer&#x27;s
   Ed25519 public key.  Verification is fully offline.  No registry
   lookup, no network call, and no third-party trust anchor is required.

   HDP&#x27;s distinguishing contribution is a signed, tamper-evident record
   of what the human asked for and of how each agent read and acted on
   that request.  On deployments that use capability-based delegation
   formats such as UCAN and ZCAP-LD, the same content can travel in the
   capability certificates&#x27; own metadata instead of a separate token.
   The underlying append-only, offline-verifiable chain-of-custody
   mechanism is payload-agnostic; human-authorized agentic delegation is
   the reference profile specified in this document.

   HDP is not an authorization protocol.  An HDP token confers no
   authority and is not an input to any access decision.  It is a record
   of who authorized a task and of what each agent declared it did with
   that authorization, carried with the task and read at audit.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-helixar-hdp-agentic-delegation-03" />
   
</reference>
