<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sato-soos-sov" target="https://datatracker.ietf.org/doc/html/draft-sato-soos-sov-02">
   <front>
      <title>The Sovereign Object (SOV) for Agentic AI Systems</title>
      <author initials="" surname="Sato" fullname="Tom Sato">
         <organization>MyAuberge K.K.</organization>
      </author>
      <date month="June" day="30" year="2026" />
      <abstract>
	 <t>   When an AI agent acts on your behalf, it acts on something: a
   document, a booking, a contract, a financial instruction.  No
   existing IETF specification defines what that something is, what
   states it can be in, who governs it, or how it is irreversibly
   erased when the relationship ends.

   Agentic AI governance protocols -- including intent declaration,
   human escalation, audit recording, and constitutional prohibition --
   all require a normative definition of the governed resource that
   agents operate on: the structured, stateful, policy-carrying entity
   to which agent authority is bound and upon which governed transitions
   execute.  No existing IETF specification defines this primitive.

   This document defines the Sovereign Object (SO): a causally ordered,
   policy-governed, typed, living document that evolves through a
   predefined finite state space under Governing Enforcement Component
   (GEC) authority.  The SO is the unit of governance in the SOOS
   protocol family: the thing agents operate on, the GEC governs, and
   human principals reason about.

   This document specifies the SO&#x27;s five-layer structure (Identity,
   State, Event Stream, Typed Graph, Attachment Index), its Zone A /
   Zone B boundary model, its five-phase lifecycle, its SO Type system,
   its Cedar policy context model, and the binding model by which a
   Mandate JWT binds an agent to a specific SO instance.

   Version -02 extends SOV-01 with: (a) SO Type registry governance
   including a SOV-02 subtype model for structured SO Type composition;
   (b) the Standing Plan Object (SPO) as a normative SOV-02 subtype,
   specifying declarative scope constraints, Cedar bundle reference,
   CAP-RRS catalog reference, and IDP structural validation integration;
   (c) the Mission Plan SO and Mission Status SO as normative SOV-02
   subtypes for multi-agent orchestration over directed-acyclic-graph
   task structures; (d) event stream integrity normative requirements
   including GEC-signed append-only guarantees, kernel_id binding, and
   OpenTelemetry integration for observability bridging; (e) expanded
   Security Considerations addressing SO state manipulation, event
   stream tampering, SO Type spoofing, and stale state_constraint
   exploitation; and (f) IANA registrations for the SO Type code
   namespace and SPO media type.

   The Sovereign Object is the architectural foundation referenced
   normatively by [I-D.sato-soos-idp], [I-D.sato-soos-hem],
   [I-D.sato-soos-gar], [I-D.sato-soos-cap], and [I-D.sato-soos-mjwt].

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sato-soos-sov-02" />
   
</reference>
