@techreport{helixar-hdp-agentic-delegation-03, number = {draft-helixar-hdp-agentic-delegation-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-helixar-hdp-agentic-delegation/03/}, author = {Asiri Dalugoda}, title = {{Human Delegation Provenance Protocol (HDP): Cryptographic Chain-of-Custody for Agentic AI Systems}}, pagetotal = 47, year = 2026, month = oct, day = 6, abstract = {Agentic AI systems operate on behalf of human principals, often delegating tasks through multi-step chains of AI agents. There is currently no standard mechanism to record who authorized an agent to act, under what scope, and through what chain of delegation, in a way that can be verified offline, without a central registry, and without third-party trust anchors. This document specifies the Human Delegation Provenance Protocol (HDP) version 0.1, a lightweight token-based protocol that captures, structures, cryptographically signs, and verifies human delegation context in agentic AI systems. An HDP token binds a human authorization event to a session, records each agent's delegation action as a signed hop in an append-only chain, and lets an auditor verify the integrity of the full record using only the issuer's Ed25519 public key. Verification is fully offline. No registry lookup, no network call, and no third-party trust anchor is required. HDP's distinguishing contribution is a signed, tamper-evident record of what the human asked for and of how each agent read and acted on that request. On deployments that use capability-based delegation formats such as UCAN and ZCAP-LD, the same content can travel in the capability certificates' own metadata instead of a separate token. The underlying append-only, offline-verifiable chain-of-custody mechanism is payload-agnostic; human-authorized agentic delegation is the reference profile specified in this document. HDP is not an authorization protocol. An HDP token confers no authority and is not an input to any access decision. It is a record of who authorized a task and of what each agent declared it did with that authorization, carried with the task and read at audit.}, }