The Governed Agent Authority (GAA) Standard
A provider-agnostic, vertical-agnostic specification for governing the authority of an AI agent that acts on a Principal's behalf. The agent acts; the governor governs its authority; the institution executes. The model, engine, venue, and site are swappable adapters; the governance is the specified contract.
The Standard publishes a category language and public interop shapes — a vocabulary, an open registry of agent classes, an authority-composition model, a set of named controls, a receipts artifact, and a site-integration seam. It deliberately does not publish any implementer's enforcement. A reader learns what the roles, controls, and contracts are; the specification never contains a particular vendor's runtime, corpus, or seal internals — those remain each implementer's own.
What GAA specifies
- Authority as governed records. An agent's authority is a granted, scoped, revocable Mandate — itself a typed, sealed record, never an ambient permission.
- Deny-by-default. An ungranted capability, destination, or counterparty is refused before it fires; composing several grants never widens any single grant.
- Consequential vs informational verb classes. Reading and rendering are informational; anything that moves money, sends, publishes, deletes, or binds the Principal is consequential and gated.
- Escalate-and-hold with out-of-band human ratification. A consequential act holds until a human ratifies it through a channel the agent cannot self-produce. The agent proposes; the human disposes.
- Sovereign revocation. The Principal may revoke any grant at any time; a revoked parent fails its whole delegation subtree closed on the next action.
- Sealed, third-party-re-derivable records. Every governed decision is sealed into a tamper-evident chain; an independent examiner re-derives what happened, under which rules, from the record alone.
The sections
| Section | Names |
|---|---|
| §2 Vocabulary | Principal · Governed Agent · Mandate · Governed Mediation |
| §3 Agent classes | an open registry, placed by three axes (whose-interest · real-vs-simulated · latitude) |
| §4 Authority composition | the RAR grant schema · deny-unless-permit composition · the 2-axis limit model · narrow-only delegation · the AuthZEN decision contract |
| §5 Controls C1–C7 | capability · egress · human ratification · limit/policy · seal · examiner · swappable adapter |
| §6 Disclosure → control map | each shipping agentic-disclosure line ↔ the control that fills it |
| §7 Position | plane-not-box · individual-first · the triad Governed · Secure · Private, in the Principal's favor |
| §8 Receipts | the typed, content-hashed, sealed artifact a governed interaction emits |
| §9 Site-Integration | the seam by which an existing site GAA-enables a governed-agent door |
| §10 Cryptographic agility | hash-namespace and signature agility; the steward's standing watch |
| §12 Conformance | one path, no first-party privilege; honest self-attestation |
| §13 Security considerations | what the authority plane addresses — and the substrate boundary it never claims |
| §14 Registry | the open agent-class registry and its in-spec registration procedure |
Every normative requirement carries a stable ID (GAA-*) and a deep link — a crosswalk or a
conformance test cites /standard/text#GAA-COMP-2, an exact requirement, not a paragraph.
Requirement IDs are stable across versions and renumbering.
The specification cites neighboring open work by name — OAuth 2.0 Rich Authorization Requests (RFC 9396), the OpenID AuthZEN Authorization API, FAPI 2.0, XACML 3.0, NIST SP 800-162 ABAC, Ed25519, Open Banking Variable Recurring Payments, the Model Context Protocol — and specifies how GAA composes with each.
Read the canonical text
The entire canonical text is hosted here, by the Institute: the canonical text · the version history · the lifecycle policy. Each sealed revision is frozen at a per-revision URL (currently /standard/r1/); each version is preserved as a version of record, and each staged or published revision carries a governed seal an independent party can re-derive — in the browser, keyless, from the version-history page itself.
Honest label
The specification is charter-grade — a candidate for formal ratification under the Institute's change-governance process. A reference implementation is live as a mechanism; products built on it are demonstrations. The specification is stated as a specification, not as a product claim.