%% You should probably cite draft-schrock-ep-authorization-receipts-08 instead of this revision. @techreport{schrock-ep-authorization-receipts-04, number = {draft-schrock-ep-authorization-receipts-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-schrock-ep-authorization-receipts/04/}, author = {Iman Schrock}, title = {{Authorization Receipts for High-Risk Agent Actions}}, pagetotal = 27, year = , month = , day = , abstract = {This document defines the EMILIA Protocol (EP) authorization receipt, a cryptographic primitive that binds a named, accountable human approver to one exact high-risk action before that action executes. An approver holding their own signing key produces a signature over a canonical Authorization Context containing the action hash, policy reference, one-time nonce, and validity window. The resulting Trust Receipt is Merkle-anchored and verifiable fully offline: a relying party can confirm that a specific action was approved by an authorized human, exactly once, without network access to any EP operator, log, or API. The protocol additionally enforces separation of duties (an initiator must not approve its own action) and one-time consumption (an authorization, once consumed or refused, is terminally unusable). These invariants are machine-checked in published TLA+ and Alloy models. EP addresses organizational authorization of agent actions (approver- to-action trust). It is complementary to, not a replacement for, user-to-operator delegation work (draft-nelson-agent-delegation- receipts), service-to-service identity (WIMSE), and authentication- layer approval (CIBA). EP is the human-authorization apex of the agent stack: it composes with, and does not replace, the agent identity, delegation, machine-policy, and transparency-log layers, supplying the named-human authorization evidence those layers reference but do not themselves produce.}, }