Technical report / Version 1
Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation
OPAQUE Systems
Abstract
This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.
What this report contributes
A conditional composition argument and proposed handoff contract for when tool calls and delegations preserve an authorized plaintext-holder boundary.
Evidence and limits
- All results are software results: attestation in the composed experiment is synthetic and one operator runs every party.
- The composed experiment was rerun on September 27, 2026 at WCM main 94d5519: 36 of 36 hosted and 32 portable cases locally, matching every recorded observation.
- Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published.
The source package preserves the recorded inputs and results. The composed software experiment was rerun for this edition; no hardware run was repeated. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Imran Siddique. Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026confidentialhandoffs,
title = {Confidentiality Across Agent Handoffs: Conditions for preserving an inference guarantee through tools and delegation},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23022884},
url = {https://agentrust-io.com/research/confidential-handoffs/v1/}
}
Version history
Version 1, September 27, 2026: Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.
Revises a discussion draft dated September 19, 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.