%% You should probably cite draft-sato-soos-mjwt-04 instead of this revision. @techreport{sato-soos-mjwt-01, number = {draft-sato-soos-mjwt-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sato-soos-mjwt/01/}, author = {Tom Sato}, title = {{The Mandate JWT (MJWT) for Agentic AI Systems}}, pagetotal = 27, year = 2026, month = jun, day = 10, abstract = {An AI agent that can act without a verifiable, human-traceable authorization record is an agent without an owner. Existing authorization credentials tell you what an agent is permitted to do; none of them tell you who authorized it, on which specific object, under which mission, or how far that authority can be delegated before it reaches this agent. This document defines the Mandate JWT (MJWT): a WIMSE workload credential profile that binds an AI agent's authority to a specific Sovereign Object instance under a named human principal, with a cryptographically enforced delegation ceiling and a six-dimensional Narrowing Property that prevents any sub-agent from exceeding the authority of the human principal at the root of the chain. The MJWT is the authorization primitive referenced by {[}I-D.sato-soos-idp{]}, {[}I-D.sato-soos-hem{]}, {[}I-D.sato-soos-gar{]}, {[}I-D.sato-soos-cap{]}, and {[}I-D.sato-soos-sov{]}.}, }