<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sato-soos-gar" target="https://datatracker.ietf.org/doc/html/draft-sato-soos-gar-02">
   <front>
      <title>The Governance Audit Record (GAR) for Agentic AI Systems</title>
      <author initials="" surname="Sato" fullname="Tom Sato">
         <organization>MyAuberge K.K.</organization>
      </author>
      <date month="June" day="10" year="2026" />
      <abstract>
	 <t>   This document specifies the Governance Audit Record (GAR), the audit
   architecture for agentic AI systems.  GAR defines five audit types,
   the Session Audit Record (SAR), the Audit Alert system, auditor
   principal categories, and the Audit Package for external regulatory
   inspection.  GAR provides verifiable evidence that AI agent sessions
   were governed in accordance with the Intent Declaration Primitive
   [I-D.sato-soos-idp] and the Human Escalation Mechanism
   [I-D.sato-soos-hem].  GAR answers the governance question: can any
   of this be proven to a regulator?  GAR is a domain-specific
   application of the SCITT (Supply Chain Integrity, Transparency and
   Trust) architecture [I-D.ietf-scitt-architecture] extended with
   causal ordering semantics for agentic governance events.  GAR defines
   the Authority Lifecycle Event (ALE) category: a normative set of
   causally-ordered event types covering the complete agent session
   revocation and recovery lifecycle, including single-agent revocation,
   authority suspension, partial state recording, recovery initiation,
   credential restoration, and multi-agent delegation tree events.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sato-soos-gar-02" />
   
</reference>
