%% You should probably cite draft-correctover-ccs-08 instead of this revision. @techreport{correctover-ccs-02, number = {draft-correctover-ccs-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-correctover-ccs/02/}, author = {Correctover}, title = {{Correctover Conformance Shape (CCS): A Receipt and Binding Specification for Agent Runtime Verification}}, pagetotal = 32, year = , month = , day = , abstract = {The Correctover Conformance Shape (CCS) defines a tamper-evident receipt schema and a set of cryptographic bindings that together constitute a verifiable conformance record for an agent runtime's decision to permit, deny, or escalate a tool invocation. CCS is designed as a one-receipt-per-invocation object that can be consumed by an executor-side Action Evidence Boundary (AEB), providing the request\_hash, response\_hash, runtime\_context\_hash, action binding, params\_hash binding, issuer, audience, nonce/sequence, freshness, and config\_hash fields that the AEB processing model requires as native inputs. This document specifies the CCS Receipt Schema, the Canonical Configuration model, the nine binding mechanisms, key management, transport requirements, verifier source classification, conformance levels, and negative test cases. It is intended to enable a reader such as the author of the Action Evidence Boundary specification to evaluate whether and how a CCS receipt can be mapped into an Authorization Evidence Chain (AEC) component.}, }