@techreport{zagarella-autonomy-governor-01, number = {draft-zagarella-autonomy-governor-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-zagarella-autonomy-governor/01/}, author = {Roberto Antonio Zagarella}, title = {{Pre-Action Risk-Graded Assurance for Agent Interactions}}, pagetotal = 12, year = 2026, month = aug, day = 23, abstract = {Governance of autonomous agents today is largely expressed as boundary enforcement: an action is permitted or blocked at the point it is attempted, per a policy evaluated at that boundary. As agents span heterogeneous action types — authenticating a human, executing a delegated task, selecting a computational resource — a single, uniform way to express "how much assurance this action requires, before it proceeds" is missing. This document describes an interface for pre-action, risk-graded assurance: a policy stage that, before an agent action proceeds, derives an assurance requirement from a risk signal and expresses that requirement in a domain-appropriate form, recording the decision in an audit record and optionally binding it to a verified human root. It defines the interface and the audit-record fields, not any particular risk-scoring method or control law. This document also describes the autonomy-asymmetry control law: a feedback loop coupling assurance requirements to VERIFY-phase pass rates, with fast-down (immediate elevation on failure) and slow-up (hysteresis- governed relaxation on sustained success) asymmetry. The iteration governor is described as the per-packet instance of this control law, and the phase-seal chain as its sensor. This document is offered as input to the proposed AUDIT working group's work on authorization state over time and action provenance.}, }