Skip to content

Research Sources

Agent Policy v0.1.0 uses established policy, authorization, eventing, telemetry, AI governance, and agent protocol references. These references inform the shape of the standard; they do not transfer ownership of Agent Policy semantics.

SourceWhat Agent Policy takes from it
Open Policy Agent docsPolicy-as-code, structured input, structured decision output, and decoupling decision from enforcement.
OPA policy languageRego-style policy evaluation concepts and data-driven policy authoring.
OPA management bundlesVersioned policy bundles as a reference for policy set identity and distribution.
Cedar documentationPrincipal, action, resource, context, entities, schema validation, and authorization decisions.
Cedar authorizationPARC request shape and permit/forbid evaluation model.
OASIS XACML 3.0PDP/PEP split and decision vocabulary such as Permit, Deny, NotApplicable, and Indeterminate.
OAuth 2.0 RFC 6749Token, grant, and scope concepts as adjacent identity inputs.
OAuth 2.0 Resource Indicators RFC 8707Resource-bound authorization requests as a reference for constrained grants.
Model Context Protocol specificationTool, resource, prompt, and authorization boundaries for agent integrations.
Agent2Agent ProtocolPeer agent tasks, messages, artifacts, and handoff references.
CloudEvents specificationPortable event envelope design.
OpenTelemetry GenAI semantic conventionsTrace and span correlation for model and agent operations.
NIST AI Risk Management FrameworkGovernance-oriented vocabulary for mapping, measuring, managing, and documenting AI risk.

Draft standard for portable agent policy decisions, approvals, permissions, risk, and audit traces.