[{"author": "Noah Stride", "text": "<p>Sounds good</p>", "time": "2026-06-03T15:00:07.000Z"}, {"author": "Jeff Lombardo", "text": "<p>Hi Everyone</p>", "time": "2026-06-03T15:00:15.000Z"}, {"author": "Yaroslav Rosomakho", "text": "<p>... or think something!</p>", "time": "2026-06-03T15:02:38.000Z"}, {"author": "Justin Richer", "text": "<p>@Yaroslav we don't have thought police bots ... yet ....</p>", "time": "2026-06-03T15:03:39.000Z"}, {"author": "Pieter Kasselman", "text": "<p>On the API Keys use with LLM topic, there has been some very good announcements from Anthroopic and OpenAI that uses Workload Identity Federation (RFC7523 +OIDCC Discoovery). It's great to see that anti-pattern not propagating ;)</p>", "time": "2026-06-03T15:22:42.000Z"}, {"author": "Jeff Lombardo", "text": "<ul>\n<li><a href=\"https://developers.openai.com/api/docs/guides/workload-identity-federation\">https://developers.openai.com/api/docs/guides/workload-identity-federation</a></li>\n<li><a href=\"https://platform.claude.com/docs/en/build-with-claude/workload-identity-federation\">https://platform.claude.com/docs/en/build-with-claude/workload-identity-federation</a></li>\n<li><a href=\"https://docs.snowflake.com/en/user-guide/workload-identity-federation\">https://docs.snowflake.com/en/user-guide/workload-identity-federation</a></li>\n</ul>", "time": "2026-06-03T15:23:51.000Z"}, {"author": "Pieter Kasselman", "text": "<p>It was a timing thing.... WIMSE did not exist yet ;)</p>", "time": "2026-06-03T15:29:51.000Z"}, {"author": "Brian Campbell", "text": "<p>blueprint is a better term than roadmap for this</p>", "time": "2026-06-03T15:34:10.000Z"}, {"author": "Brian Campbell", "text": "<p>thanks jeff</p>", "time": "2026-06-03T15:34:16.000Z"}, {"author": "Brian Campbell", "text": "<p>happy to let you finish it out pieter</p>", "time": "2026-06-03T15:36:22.000Z"}, {"author": "Brian Campbell", "text": "<p>1) yes</p>", "time": "2026-06-03T15:37:41.000Z"}, {"author": "Brian Campbell", "text": "<p>2) yes</p>", "time": "2026-06-03T15:37:44.000Z"}, {"author": "Brian Campbell", "text": "<p>(i know we have other stuff to finish)</p>", "time": "2026-06-03T15:37:55.000Z"}, {"author": "Jeff Lombardo", "text": "<p>1) yes</p>\n<p>2) yes</p>", "time": "2026-06-03T15:38:08.000Z"}, {"author": "Paul Carleton", "text": "<p>1) yes plz</p>", "time": "2026-06-03T15:38:42.000Z"}, {"author": "Paul Carleton", "text": "<p>+1, section 9 being super specific would be very helpful</p>", "time": "2026-06-03T15:40:22.000Z"}, {"author": "Pieter Kasselman", "text": "<p>I think Yaron said its not ready for WGLC... but we should do it!</p>", "time": "2026-06-03T15:40:38.000Z"}, {"author": "Yaron Sheffer", "text": "<p>Exactly.</p>", "time": "2026-06-03T15:40:49.000Z"}, {"author": "Pieter Kasselman", "text": "<p>and the existing WIMSE deliverables on on their wayy ;)</p>", "time": "2026-06-03T15:40:54.000Z"}, {"author": "Justin Richer", "text": "<p>if it were ready for WGLC we'd have done things backwards</p>", "time": "2026-06-03T15:41:01.000Z"}, {"author": "Pieter Kasselman", "text": "<p>+1</p>", "time": "2026-06-03T15:41:10.000Z"}, {"author": "Brian Campbell", "text": "<p>it tries to be specific :) but sounds like it needs to be more specific</p>", "time": "2026-06-03T15:41:18.000Z"}, {"author": "Jeff Lombardo", "text": "<p>there are some interoperability element at work already - For example OAuth SPIFFE Client Authentication - <a href=\"https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/\">https://datatracker.ietf.org/doc/draft-ietf-oauth-spiffe-client-auth/</a></p>", "time": "2026-06-03T15:41:27.000Z"}, {"author": "Pieter Kasselman", "text": "<p>ACT claim is one of the things that may help fill a gap</p>", "time": "2026-06-03T15:41:49.000Z"}, {"author": "Yaron Sheffer", "text": "<p>@Jeff what I'm looking for is a a higher level, e.g. in an enterprise-internal service mesh, can I do everything with just WIMSE tools, or do I need OAuth to call Tools, even within the trust domain?</p>", "time": "2026-06-03T15:42:55.000Z"}, {"author": "Jeff Lombardo", "text": "<p>Ack</p>", "time": "2026-06-03T15:43:16.000Z"}, {"author": "Suresh Krishnan", "text": "<p>+1 to take on this work in wimse</p>", "time": "2026-06-03T15:43:27.000Z"}, {"author": "Justin Richer", "text": "<p>@yaron do you want to raise that on mic?</p>", "time": "2026-06-03T15:44:46.000Z"}, {"author": "Yaron Sheffer", "text": "<p>Sure.</p>", "time": "2026-06-03T15:44:58.000Z"}, {"author": "Brian Campbell", "text": "<p>yeah, @Yaron, those are questions that could be more clearly addressed in the doc and should be</p>", "time": "2026-06-03T15:45:30.000Z"}, {"author": "Brian Campbell", "text": "<p>Justin says smart things</p>", "time": "2026-06-03T15:49:58.000Z"}, {"author": "Michael Richardson", "text": "<p>It seems to overlap some parts of proposed AUDIT/AGENTIC charter (\"agent2agent\" ML)</p>", "time": "2026-06-03T15:51:29.000Z"}, {"author": "Pieter Kasselman", "text": "<p>Especially in multiple systems ;)</p>", "time": "2026-06-03T15:52:35.000Z"}, {"author": "Tom Sato", "text": "<p>On the human-in-the-loop gap identified in the authorization slide \u2014 I've authored a draft, draft-sato-soos-hem, that specifically addresses mid-execution agent-initiated escalation, which is architecturally different from CIBA. It may be worth a pointer in the gaps section. Happy to share details on-list.</p>\n<p><a href=\"https://datatracker.ietf.org/doc/draft-sato-soos-hem/\">https://datatracker.ietf.org/doc/draft-sato-soos-hem/</a></p>", "time": "2026-06-03T15:54:33.000Z"}, {"author": "Yaron Sheffer", "text": "<p>I think it would be a good thing to explicitly recharter, so that the IESG can look at the whole domain (inc. AUDIT/AGENTIC) and partition it to minimize future conflicts.</p>", "time": "2026-06-03T15:56:41.000Z"}, {"author": "Andreas Falk", "text": "<p>+1 to take on this work in wimse</p>", "time": "2026-06-03T15:56:47.000Z"}, {"author": "Brian Campbell", "text": "<p>my perspective is that this work shouldn't define new things directly but might serve as the vehicle to identify what/where new work might take place</p>", "time": "2026-06-03T15:58:25.000Z"}, {"author": "Yaron Sheffer", "text": "<p>@Brian, I see pros and cons, we would need to have a deep discussion.</p>", "time": "2026-06-03T15:59:31.000Z"}]