<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.schrock-ep-authorization-receipts" target="https://datatracker.ietf.org/doc/html/draft-schrock-ep-authorization-receipts-07">
   <front>
      <title>Authorization Receipts for High-Risk Agent Actions</title>
      <author initials="I." surname="Schrock" fullname="Iman Schrock">
         <organization>EMILIA Protocol, Inc.</organization>
      </author>
      <date month="July" day="19" year="2026" />
      <abstract>
	 <t>   This document defines the EMILIA Protocol (EP) authorization receipt,
   an evidence artifact binding an enrolled approver key to one
   canonical action before execution.  An approver-held key signs an
   Authorization Context containing the action hash, policy reference,
   nonce, audience, and validity window.  A Trust Receipt carries the
   signed contexts, terminal consumption record, and Merkle inclusion
   material so a relying party can verify the recorded event offline
   under independently selected log, directory, policy, and approver
   trust inputs.

   The receipt establishes only the guarantees of the selected
   verification profile.  The mapping from an enrolled approver
   identifier to a natural person is asserted by the directory
   authority.  Offline verification does not establish current
   revocation status, global non-replay, comprehension, legality,
   safety, or execution.  Replay prevention requires an online atomic
   consumption store at the executor.  The state-machine invariants are
   machine-checked under the assumptions stated in this document.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-schrock-ep-authorization-receipts-07" />
   
</reference>
