DRAFT

Skeleton proposed for discussion at weekly AIKR CG calls starting Monday 21 September 2026. Nothing here has been agreed by the group.

What the skeleton does

KRT records a trust decision: a relying party's judgement about one proposition, for one action, at one time.

The record names who presented a claim and through which channel, on whose authority, with what evidence, for an action of what reversibility, enforced where, with an outcome of yes, no or unknown and a stated policy for unknown. A relying party, an auditor or a regulator can then see which part of a decision rested on something nobody checked.

The vocabulary follows the property groups A to H developed in the trust thread and uses the terms of the companion glossary.

Provenance. The skeleton was derived from case work: structured analysis by the Epistemic Systems Lab of documented incidents involving AI agents, read against the contributions to the AIKR CG trust thread. Each design rule below corresponds to a failure pattern found in that analysis. The case material itself is not reproduced here.

Core pattern

TrustDecision RelyingPartyParty (subject)Channel PropositionActionArtefact (evidence) TrustPolicyOutcome: yes | no | unknown relyingPartysubjectpresentedVia propositionforActionusesEvidence appliesPolicyoutcome

Classes

Decision

  • TrustDecision
  • Proposition
  • Outcome
  • TrustPolicy

Parties

  • Party
  • Principal
  • Agent
  • AgentInstance
  • Operator
  • RelyingParty
  • Issuer

Artefacts

  • Artefact
  • IdentityDocument
  • Credential
  • Mandate, Delegation
  • Declaration
  • Verdict
  • Receipt
  • AccountabilityRecord
  • Revocation
  • EnvironmentAttestation
  • AgentConfiguration

Activity and control

  • Action
  • Instruction
  • DeclaredPolicy
  • EnforcementPoint
  • Channel
  • VerificationPath

Properties by group

GroupPropertiesControlled values
DecisionrelyingParty subject proposition forAction presentedVia usesEvidence outcome appliesPolicy onUnknown actionTaken decidedAtOutcome: yes, no, unknown. Propositions: key control, authority to act, action occurred, responsibility, controlling principal known, containment holds, artefact integrity.
A. Resolution and integrityviaPath topology coupling integrityMode stalenessBound governedBy observableBy contentHash anchoredInTopology: ledger, operator domain, third-party registry, self-certifying. Coupling: coupled, decoupled. Integrity: content-addressed, location-bound.
B. Proposition and attestationissuedBy about canProve attestationMode validFrom validUntilSelf-asserted, third-party attested.
C. ComparisoncanonicalForm unicodeNormalization largeIntegersAsStrings declaredSemantics
D. Authority continuitygrantedBy grantedTo derivedFrom scope valueLimit currency attenuationChecked revocationPropagates underMandate
E. Binding pointbindingPoint producedByDeclared call, request as sent, observed effect.
F. Coverage and disclosurevouchesFor claimSource completeness presentingSubject controllingPrincipal controlDisclosure declaresNoActivityInCompleteness attested or not. Disclosure: disclosed, unknown, cannot disclose.
G. Enforcement and oversightdeclaresPolicy rule enforcedAt location enforcer enforcementEvidence monitoringCoverage stopChannel stopChannelTested environment networkReach configurationLocation: inside the agent, platform, system acted on, independent component. Monitoring: none, partial, full.
H. Instance and attributioninstanceOf onBehalfOf operatorOfRecord performedBy coordinationChannel authorshipAuthorship: agent instance, person using agent credentials, unknown.
Actions and instructionsreversibility affects requestedBy instructionProvenance issuingPrincipal revokes coversDerivedDataReversible, compensable, irreversible. Provenance: signed by a mandate holder, authenticated principal session, content with no principal.

Design rules

Each rule is expressed as a SHACL shape in krt-shapes.ttl, so a set of decision records can be checked mechanically.

RuleStatementShape
R0A decision record names relying party, proposition, action, one outcome and the policy applied.DecisionShape
R1A channel establishes no identity. A yes outcome cites at least one artefact.EvidenceShape
R2Instructions carry their principal's authority. Content with no principal carries none.InstructionAuthorityShape
R3Authority over affected third parties is decided separately from the requester's.ThirdPartyShape
R4A yes outcome for an irreversible action needs evidence attested by someone other than the subject.IrreversibleShape
R5An agent's report of its own action is a claim. Receipts come from another component.ReceiptShape
R6Every declared policy names its enforcement point and where it sits.PolicyShape
R7A revocation states which copies it reaches and its staleness bound.RevocationShape
R8An acting instance is linked to its agent and an operator of record.InstanceShape
R9Environment claims are dated and preferably attested by infrastructure.EnvironmentShape
R10Credentials state their completeness and whether the controlling principal is disclosed.ControlShape
R11Artefacts compared by canonical form carry large identifiers as strings, state their Unicode normalization, and declare their semantics. Added after the correction posted on the list.ComparisonShape

Example

krt-example.ttl uses the reference scenario from the glossary: X, agents A and B, operator Y. Decision d1 passes. Decision d2 affirms authority for an irreversible transfer requested by unattributed content, citing only a self-asserted declaration.

ex:i2 a krt:Instruction ; krt:instructionProvenance krt:UnattributedContent .
ex:transfer2 a krt:Action ; krt:requestedBy ex:i2 ; krt:performedBy ex:A-7 ;
    krt:reversibility krt:Irreversible .
ex:d2 a krt:TrustDecision ;
    krt:relyingParty ex:B ; krt:subject ex:A-7 ;
    krt:proposition krt:AuthorityToAct ; krt:forAction ex:transfer2 ;
    krt:usesEvidence ex:selfNote ;          # self-asserted
    krt:outcome krt:Yes ; krt:appliesPolicy ex:policyY .
Validation (pySHACL, RDFS inference):  conforms = false
ex:d2  R2  authority cannot be affirmed for an action requested by content with no principal
ex:d2  R4  a yes outcome for an irreversible action needs evidence attested by a party other than the subject

Alignment

Parties specialise prov:Agent, artefacts prov:Entity and actions prov:Activity; onBehalfOf specialises prov:actedOnBehalfOf. Identity documents point to DID Core, credentials to the Verifiable Credentials Data Model 2.0, and mandates to ODRL. Controlled values are SKOS concepts, and rules are SHACL shapes.

Questions for the calls

  1. Are the property groups A to H the right partition, and which group does each contributor take on?
  2. Should mandates and declared policies reuse ODRL directly, with KRT adding only the enforcement properties?
  3. Which rules are errors and which are warnings, and should R4 apply to compensable actions above a value limit?
  4. How are "unknown" and "cannot disclose" handled where disclosure conflicts with privacy law or legal secrecy?
  5. What test records should accompany each rule in a conformance suite?
  6. Should the namespace be fixed now, or held until the vocabulary settles?

Files

Namespace (provisional): https://w3c-cg.github.io/aikr/trust/krt#