The problem
The conformance chapter says what ACS-Core guarantees technically. It does not say that a conformance claim is silent on whether a human authorized anything. A deployment whose policy was written by automation and whose every ASK is answered by a service is fully conformant and produces a complete audit chain, so a reader can take the claim as evidence of human oversight that ACS never checked.
Why the wire has to carry it
Nothing new goes on the wire. This is scope language in docs/spec/conformance.md, together with a rule that a deployment must not represent its conformance as evidence that a human authorized a specific action.
Which constituencies this affects
Alternatives considered
Leave it to docs/concepts/trust.md, which draws the asserted versus attested line but says nothing about the conformance claim itself. Or wait for the Policy Attestation profile in v0.2, which leaves v0.1.0 silent while deployments are making the claim now.
Discussion link
No Discussion exists. PR #24 carries the argument, and @jrcrittenden wrote it. GitHub will not let us assign an issue to someone without repository access, so this names him here instead.
Current Priority Scope
Feeds conformance evidence
The problem
The conformance chapter says what ACS-Core guarantees technically. It does not say that a conformance claim is silent on whether a human authorized anything. A deployment whose policy was written by automation and whose every ASK is answered by a service is fully conformant and produces a complete audit chain, so a reader can take the claim as evidence of human oversight that ACS never checked.
Why the wire has to carry it
Nothing new goes on the wire. This is scope language in
docs/spec/conformance.md, together with a rule that a deployment must not represent its conformance as evidence that a human authorized a specific action.Which constituencies this affects
Alternatives considered
Leave it to
docs/concepts/trust.md, which draws the asserted versus attested line but says nothing about the conformance claim itself. Or wait for the Policy Attestation profile in v0.2, which leaves v0.1.0 silent while deployments are making the claim now.Discussion link
No Discussion exists. PR #24 carries the argument, and @jrcrittenden wrote it. GitHub will not let us assign an issue to someone without repository access, so this names him here instead.
Current Priority Scope
Feeds conformance evidence