Technical report / Version 1
Exact-Output Disclosure for Agent Workflows: Owner approval of exact bytes, consumed once before delivery
OPAQUE Systems
Abstract
An answer an agent writes from a confidential record keeps the record's restrictions, even when it reads like a harmless summary. This report describes a release path for that case. An owner signs the exact output bytes together with the recipient, purpose, source scope, inherited labels, policy version and a validity interval. A gate checks the signer's authority for that scope, verifies the signature, and commits a request identifier to a persistent ledger before it calls the one registered delivery adapter. If the acknowledgment is lost, the attempt stays consumed and the outcome is reported as unknown. Nothing is sent twice. We evaluate the implementation in cMCP, which ships in cmcp-runtime 0.6.0 and later. All 46 existing tests pass, and removing either of two controls makes specific tests fail. In 20 rounds of 16 concurrent attempts, every round delivered once. In 10 rounds of 8 competing sender processes, every round produced exactly one recorded receipt. Process kills on both sides of the ledger commit, lock timeouts, a corrupted ledger and a dropped acknowledgment never produced a second receipt; with replay consumption removed, all 9 of those cases fail. Every number was reproduced on October 1, 2026 at the evaluated revision and at current main.
What this report contributes
A release gate that ties owner-signed exact output bytes to a scoped, persistent, single-attempt decision and reports an uncertain delivery as unknown instead of repeating it.
Evidence and limits
- Software-only, on one Windows host with a local SQLite ledger, synthetic payloads and a loopback recipient. A networked ledger and an independently operated recipient are untested.
- Restoring an earlier ledger re-enables an approval. Rollback protection, egress confinement and trusted classification are outside the gate.
- A low-entropy output can be guessed from its digest, so approval records need private storage. The gate has no delivery watchdog.
The source package preserves the recorded inputs and results. Every experiment was rerun on October 1, 2026 in a fresh environment at the evaluated revision and at current main. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Imran Siddique. Exact-Output Disclosure for Agent Workflows: Owner approval of exact bytes, consumed once before delivery. AgenTrust technical report, version 1, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026exactoutputdisclosure,
title = {Exact-Output Disclosure for Agent Workflows: Owner approval of exact bytes, consumed once before delivery},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 1; not peer reviewed},
doi = {10.5281/zenodo.23091294},
url = {https://agentrust-io.com/research/exact-output-disclosure/v1/}
}
Version history
Version 1, October 1, 2026: First public edition. Evaluates cMCP 2cdb168; every count was reproduced on October 1, 2026 at that revision and at main a3f61e1.
Based on an internal study drafted September 23, 2026 and rerun September 27, 2026.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.