@techreport{sato-soos-sov-02, number = {draft-sato-soos-sov-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sato-soos-sov/02/}, author = {Tom Sato}, title = {{The Sovereign Object (SOV) for Agentic AI Systems}}, pagetotal = 42, year = 2026, month = jun, day = 30, abstract = {When an AI agent acts on your behalf, it acts on something: a document, a booking, a contract, a financial instruction. No existing IETF specification defines what that something is, what states it can be in, who governs it, or how it is irreversibly erased when the relationship ends. Agentic AI governance protocols -- including intent declaration, human escalation, audit recording, and constitutional prohibition -- all require a normative definition of the governed resource that agents operate on: the structured, stateful, policy-carrying entity to which agent authority is bound and upon which governed transitions execute. No existing IETF specification defines this primitive. This document defines the Sovereign Object (SO): a causally ordered, policy-governed, typed, living document that evolves through a predefined finite state space under Governing Enforcement Component (GEC) authority. The SO is the unit of governance in the SOOS protocol family: the thing agents operate on, the GEC governs, and human principals reason about. This document specifies the SO's five-layer structure (Identity, State, Event Stream, Typed Graph, Attachment Index), its Zone A / Zone B boundary model, its five-phase lifecycle, its SO Type system, its Cedar policy context model, and the binding model by which a Mandate JWT binds an agent to a specific SO instance. Version -02 extends SOV-01 with: (a) SO Type registry governance including a SOV-02 subtype model for structured SO Type composition; (b) the Standing Plan Object (SPO) as a normative SOV-02 subtype, specifying declarative scope constraints, Cedar bundle reference, CAP-RRS catalog reference, and IDP structural validation integration; (c) the Mission Plan SO and Mission Status SO as normative SOV-02 subtypes for multi-agent orchestration over directed-acyclic-graph task structures; (d) event stream integrity normative requirements including GEC-signed append-only guarantees, kernel\_id binding, and OpenTelemetry integration for observability bridging; (e) expanded Security Considerations addressing SO state manipulation, event stream tampering, SO Type spoofing, and stale state\_constraint exploitation; and (f) IANA registrations for the SO Type code namespace and SPO media type. The Sovereign Object is the architectural foundation referenced normatively by {[}I-D.sato-soos-idp{]}, {[}I-D.sato-soos-hem{]}, {[}I-D.sato-soos-gar{]}, {[}I-D.sato-soos-cap{]}, and {[}I-D.sato-soos-mjwt{]}.}, }