Technical report / Version 1

Requirement-Preserving Human Approvals for Signed Agent Manifests

Imran Siddique

OPAQUE Systems

October 1, 2026Not peer reviewed

Abstract

Human approval often arrives after an agent manifest has been issued. If the issuer signs the approval collection as immutable content, nobody can attach an approval later without a new signature. If the issuer leaves the whole oversight record unsigned, anyone can weaken the requirement. We analyze a two-domain construction: the issuer signs the oversight requirement while normalizing only its approvals array to empty, and each human separately signs an approval bound to a manifest and scope. A verifier reconstructs the issuer pre-image and evaluates human evidence on its own terms. Agent Manifest uses this pre-image for version 0.1 manifests; its version 0.2 COSE envelope reaches the same split by carrying approvals in the unprotected header. At a pinned Agent Manifest revision, 74 signing and delegation/HITL tests passed on September 4, September 27 and October 1, 2026. Separate probes confirm requirement binding and appendability. At the pinned revision they also show that the human signature did not cover the outer authenticator-method label. A later upstream change binds that label, and the same probe fails against two later revisions, including the October 1 main branch. The result is a precise signing boundary and a list of the identity, action and authenticator evidence a runtime still needs before it acts on an approval.

What this report contributes

A two-domain signing boundary: the issuer signs the oversight requirement with approvals normalized to empty, and each human signs an approval bound to a manifest and scope.

Evidence and limits

The source package preserves the recorded inputs and results. Tests and probes were rerun at the pinned revision on October 1, 2026 in a fresh environment. No independent replication is claimed.

Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.

Cite this report

Imran Siddique. Requirement-Preserving Human Approvals for Signed Agent Manifests. AgenTrust technical report, version 1, 2026.

Download BibTeX / Download CITATION.cff

@techreport{agentrust2026requirementpreservinghumanapproval,
  title = {Requirement-Preserving Human Approvals for Signed Agent Manifests},
  author = {Imran Siddique},
  institution = {AgenTrust},
  year = {2026},
  type = {Technical report},
  note = {Version 1; not peer reviewed},
  doi = {10.5281/zenodo.23091292},
  url = {https://agentrust-io.com/research/requirement-preserving-human-approval/v1/}
}

Version history

Version 1, October 1, 2026: First public edition. Revises a manuscript dated September 4, 2026; tests and probes were rerun on September 27 and October 1, 2026, and the probes were run against two later revisions.

Revises a manuscript dated September 4, 2026.

File checksums. Published version files are retained; substantive revisions receive a new version.

Questions and corrections

Open an issue in the project repository and identify the report version and section.