Canonical summary
Defines deterministic, machine-verifiable requirements for the authority under which an AI agent acts on behalf of a principal, covering the signed authorization credential and its binding to a specific agent instance and configuration, the expression of scope in machine-testable form, human checkpoints, revocation, sub-delegation, and a tamper-evident action log reconciled against counterparty records. It determines whether the recorded actions stayed within the granted authority during a specified assessment window, and does not state anything about future agent behaviour. It does not evaluate the agent's capability, output quality, or decision correctness, does not certify the safety or alignment of the underlying model, and does not allocate liability.