<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sabey-refusal-transparency" target="https://datatracker.ietf.org/doc/html/draft-sabey-refusal-transparency-02">
   <front>
      <title>Refusal Transparency: Signed, Replay-Resistant Evidence of Refused Agent-System Transitions</title>
      <author initials="J. M." surname="Sabey" fullname="Jaryn Mervin Sabey">
         <organization>Continuity Laboratories</organization>
      </author>
      <date month="July" day="21" year="2026" />
      <abstract>
	 <t>   A governance system for autonomous agents is defined as much by what
   it refuses as by what it permits, yet refusals are the one behavior
   vendors only ever assert.  A Refusal Digest is a portable, signed
   JSON document recording one adversarial probe run against a live
   agent-governance system: for every attack attempted, the system&#x27;s
   verbatim refusal ground, the event types the attack would have
   recorded had it succeeded, and the complete signed event ledger of
   the attempt — in which the refused transition is provably absent.
   Digests verify offline, by parties who do not operate the probed
   system, using only the issuer&#x27;s public key.  From version 0.2, every
   quantity that varies between runs derives deterministically from a
   per-run seed carried in the digest, so a relying party can recompute
   the derivations and a replayed or pre-recorded ledger cannot match a
   fresh digest.  This document specifies the digest wire format, its
   canonicalization and signature scheme, the seeded-variation
   derivations, and the verification algorithm.  Where succession
   receipts prove that an agent legitimately became the holder of an
   authority, refusal digests prove what the governing system declined
   to let happen.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sabey-refusal-transparency-02" />
   
</reference>
