<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.sokolov-rats-aep-composition" target="https://datatracker.ietf.org/doc/html/draft-sokolov-rats-aep-composition-02">
   <front>
      <title>Composing Application-Layer Action Evidence with Remote Attestation Procedures</title>
      <author initials="A." surname="Sokolov" fullname="Anton Sokolov">
         <organization>Tyche Institute</organization>
      </author>
      <date month="June" day="28" year="2026" />
      <abstract>
	 <t>   This document sketches a composition pattern in which an application-
   layer &quot;action evidence package&quot; (AEP) -- a signed, append-only record
   of an action taken by an automated (for example, AI-agent) system,
   the authority under which it was taken, and its outcome -- is treated
   as Evidence in the sense of the RATS Architecture (RFC 9334) and
   bound to platform Evidence produced by a hardware root of trust.  The
   intent is that a single Verifier, or a composition of Verifiers, can
   appraise both the platform state and the application-layer action
   together, and emit an Attestation Result that a Relying Party can use
   to reason about _what an automated system did_ and _on what platform
   it did so_ without trusting the operator&#x27;s self-report for either.
   This is an individual sketch intended to ask the working group
   whether the pattern is already covered by existing mechanisms or
   warrants a short document.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-sokolov-rats-aep-composition-02" />
   
</reference>
