emilia-protocol
emiliaprotocol/emilia-protocol/public/llms.txt
EMILIA is the authority control plane for autonomous work. The plain-language operating picture is a customer-owned authority checkpoint at a configured protected boundary, where a human or institution defines a finite operating mandate and agents work unattended inside it. EMILIA Gate verifies the authority and evidence the owner requires for the exact action, reserves accepted authority before provider entry, admits or refuses the crossing, preserves executed or indeterminate outcomes, refuses blind replay, and returns an action-bound receipt packet. EMILIA Host…
# EMILIA Protocol > EMILIA is the authority control plane for autonomous work. The plain-language operating picture is a customer-owned authority checkpoint at a configured protected boundary, where a human or institution defines a finite operating mandate and agents work unattended inside it. EMILIA Gate verifies the authority and evidence the owner requires for the exact action, reserves accepted authority before provider entry, admits or refuses the crossing, preserves executed or indeterminate outcomes, refuses blind replay, and returns an action-bound receipt packet. EMILIA Host is the private local deployment form of Gate for activated covered HTTP and MCP paths at a credential-owning provider boundary; the current surface is an HTTP local service alpha plus HTTP and MCP SDK protection, with no customer deployment established by this repository. Native mandates and credentials from A2A, AP2, OAuth, and hardware-backed approval systems remain attributable to their issuers. EMILIA Protocol is the open Action Receipt Contract underneath Gate; EMILIA Approver captures device-bound exact-action human decisions when the mandate or local policy requires fresh human authority; EMILIA Assurance Plane defines scoped verification, re-performance, conformance-report, and deployment-evidence procedures without acting as an auditor or accredited certifier. The checkpoint metaphor describes the intended cross-stack contract, not current coverage or operation of a central global network. This is a generated discovery index following the llms.txt proposal. Test-count snapshot: 2026-09-26T08:54:11.807Z; main refreshes the test counts after each merge, so they may lag the source revision by one refresh cycle. For substantive analysis, load the full or machine-readable context below before drawing conclusions from individual repository files. Prevention boundary: Gate prevents only on action paths under complete mediation. It does not constrain a path that bypasses the deployed enforcement point. ## Engineering Evidence EMILIA is implemented security infrastructure, not architecture-only: 10,870 automated tests across 657 files; 35 executable security claims over 264 hashed evidence files; 20 verified obligations across 2 composed Tamarin models, with 8 deliberately weakened variants producing concrete attack traces; and 78 content-addressed selected model/runtime scenarios across 14 bounded models and 21 claims, including 51 paired formal-counterexample/runtime-refusal controls. Interoperability evidence: 21 conformance suites and 340 current vectors across three same-team ports; external Rust evidence covers a time-pinned 164-vector set plus 359 hostility cases. Strict clean-room construction acceptance remains false. ## Canonical Context - [Full LLM context](https://www.emiliaprotocol.ai/llms-full.txt): Definitions, layer map, current evidence, non-claims, source precedence, standards, and code entry points. - [Machine-readable repository context](https://www.emiliaprotocol.ai/.well-known/emilia-context.json): EMILIA-REPO-CONTEXT-v1 with input hashes, evidence counts, security claims, assumptions, and freshness metadata. - [Canonical four-document reading path](https://www.emiliaprotocol.ai/llms-full.txt#canonical-four-document-reading-path): Authorization Receipts -> Human Authorization Binding -> Authority Introduction -> Authorization Evidence Chain. - [Standards Observatory](https://www.emiliaprotocol.ai/observatory): Revision-aware guarantee map, standards movement, and open interoperability frontiers. - [Machine-readable standards snapshot](https://www.emiliaprotocol.ai/.well-known/standards-observatory.json): Source locks, operative-status rationale, exact quotes, and the correlated-recon boundary. - [Repository AI context](https://github.com/emiliaprotocol/emilia-protocol/blob/main/AI_CONTEXT.md): The same generated context beside the source code. ## Specifications - [draft-schrock-ae-challenge](https://datatracker.ietf.org/doc/draft-schrock-ae-challenge/): Machine-readable, action-bound request for missing authorization evidence; the challenge authorizes nothing; snapshot revision -07, check Datatracker for current status. - [draft-schrock-action-evidence-boundary](https://datatracker.ietf.org/doc/draft-schrock-action-evidence-boundary/): Boundary contract joining independently verified evidence to one material action, reserving authority before invocation, and preserving indeterminate outcomes for authenticated reconciliation; snapshot revision -07, check Datatracker for current status. - [draft-schrock-action-remedy-receipts](https://datatracker.ietf.org/doc/draft-schrock-action-remedy-receipts/): Dispute, decision, and fresh CAID-bound compensating-action evidence without rewriting the original effect; snapshot revision -00, check Datatracker for current status. - [draft-schrock-agent-qualification-statements](https://datatracker.ietf.org/doc/draft-schrock-agent-qualification-statements/): Task- and policy-bounded qualification evidence that never authorizes by itself; snapshot revision -00, check Datatracker for current status. - [draft-schrock-canonical-action-identifier](https://datatracker.ietf.org/doc/draft-schrock-canonical-action-identifier/): Typed material-action identity and profile-bounded cross-format matching; snapshot revision -03, check Datatracker for current status. - [draft-schrock-emilia-eye](https://datatracker.ietf.org/doc/draft-schrock-emilia-eye/): Scope-bound advisory that can tighten but never authorize; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-architecture](https://datatracker.ietf.org/doc/draft-schrock-ep-architecture/): Portfolio architecture; snapshot revision -03, check Datatracker for current status. - [draft-schrock-ep-authority-introduction](https://datatracker.ietf.org/doc/draft-schrock-ep-authority-introduction/): Authority introduction and trust-root boundary; snapshot revision -03, check Datatracker for current status. - [draft-schrock-ep-authorization-evidence-chain](https://datatracker.ietf.org/doc/draft-schrock-ep-authorization-evidence-chain/): Heterogeneous evidence composition; snapshot revision -06, check Datatracker for current status. - [draft-schrock-ep-authorization-receipts](https://datatracker.ietf.org/doc/draft-schrock-ep-authorization-receipts/): One action-bound organizational approval evidence profile; snapshot revision -13, check Datatracker for current status. - [draft-schrock-ep-bounded-capability-receipts](https://datatracker.ietf.org/doc/draft-schrock-ep-bounded-capability-receipts/): Action-bound capability budget and spend evidence; snapshot revision -06, check Datatracker for current status. - [draft-schrock-ep-bounded-execution-program](https://datatracker.ietf.org/doc/draft-schrock-ep-bounded-execution-program/): Reachability-, occurrence-, concurrency-, and budget-bounded runtime program for consequential action admission; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-evidence-record](https://datatracker.ietf.org/doc/draft-schrock-ep-evidence-record/): Long-term crypto-agile evidence preservation; snapshot revision -01, check Datatracker for current status. - [draft-schrock-ep-outcome-binding](https://datatracker.ietf.org/doc/draft-schrock-ep-outcome-binding/): Source-routed predicted effects and independently pinned post-execution observations; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-presentation-binding](https://datatracker.ietf.org/doc/draft-schrock-ep-presentation-binding/): Binding the signed action to what the approver was shown; snapshot revision -01, check Datatracker for current status. - [draft-schrock-ep-quorum](https://datatracker.ietf.org/doc/draft-schrock-ep-quorum/): Distinct-human multi-handshake composition; snapshot revision -04, check Datatracker for current status. - [draft-schrock-ep-revocation-statement](https://datatracker.ietf.org/doc/draft-schrock-ep-revocation-statement/): Signed retraction of authority without rewriting an already executed effect; snapshot revision -01, check Datatracker for current status. - [draft-schrock-ep-reliance-agreement](https://datatracker.ietf.org/doc/draft-schrock-ep-reliance-agreement/): Signed technical terms that bind reliance-program identifiers, versions, digests, parties, and acceptance conditions without creating legal enforceability or insurance; snapshot revision -00, check Datatracker for current status. - [draft-schrock-human-authorization-binding](https://datatracker.ietf.org/doc/draft-schrock-human-authorization-binding/): Binding a human-authorization artifact into adjacent host formats; snapshot revision -00, check Datatracker for current status. - [draft-schrock-model-to-matter](https://datatracker.ietf.org/doc/draft-schrock-model-to-matter/): Experimental executor-side authorization-evidence clearance for model-directed physical execution; snapshot revision -04, check Datatracker for current status. - [draft-ferro-schrock-memory-projection-record](https://datatracker.ietf.org/doc/draft-ferro-schrock-memory-projection-record/): Signed record of exact context bytes projected by a memory adapter, with explicit nonclaims; snapshot revision -01, check Datatracker for current status. - [draft-mih-sato-agent-accountability-composition](https://datatracker.ietf.org/doc/draft-mih-sato-agent-accountability-composition/): Coauthored composition perspective; snapshot revision -01, check Datatracker for current status. - [draft-dunbar-dmsc-gw-scenarios-gap-analysis](https://datatracker.ietf.org/doc/draft-dunbar-dmsc-gw-scenarios-gap-analysis/): Coauthored Agent Gateway deployment and exact-action authorization gap analysis; snapshot revision -04, check Datatracker for current status. - [draft-schrock-kintzele-grid-curtailment](https://datatracker.ietf.org/doc/draft-schrock-kintzele-grid-curtailment/): Coauthored GRACE application profile for exact grid-curtailment admission, authenticated actuator and meter evidence, Action State, and single-use settlement; snapshot revision -00, check Datatracker for current status. - [draft-schrock-agent-operation-continuity](https://datatracker.ietf.org/doc/draft-schrock-agent-operation-continuity/): Composition profile that preserves one provider operation and its unresolved evidence across executor replacement within one authoritative coordination domain; snapshot revision -00, check Datatracker for current status. - [draft-intra-handshake-fail](https://datatracker.ietf.org/doc/draft-intra-handshake-fail/): Coauthored analysis of published vulnerabilities in early attestation; Iman Schrock is one of 15 listed authors; snapshot revision -48, check Datatracker for current status. ## Evidence - [Conformance manifest](https://github.com/emiliaprotocol/emilia-protocol/blob/main/conformance/conformance-manifest.json): Current suite/vector counts and same-team implementation relationship. - [Machine-verifiable security case](https://github.com/emiliaprotocol/emilia-protocol/blob/main/security/security-case.json): Executed claims with exact evidence, assumptions, exclusions, and artifact hashes. - [Engineering evidence map](https://www.emiliaprotocol.ai/proof): Plain-language map from guarantees and attacks to formal, executable, conformance, and external evidence. - [External implementation pin](https://github.com/emiliaprotocol/emilia-protocol/blob/main/conformance/external/rust-cleanroom-jdieselny.v1.json): Time-pinned Rust source, vector scope, hostility corpus, and construction-attestation status. ## Start Here - [Repository](https://github.com/emiliaprotocol/emilia-protocol): Apache-2.0 source, tests, formal models, and examples. - [EMILIA Gate](https://www.emiliaprotocol.ai/gate): Customer-owned exact-action authority control at a configured executor boundary. - [Authority for AI Defenders](https://www.emiliaprotocol.ai/cyber-authority): Bounded authority for one automated security action at a credential-owning boundary. - [Quickstart](https://www.emiliaprotocol.ai/quickstart): Integrate an enforcement wrapper. - [Verify](https://www.emiliaprotocol.ai/verify): Verify a receipt in the browser. - [Model-to-Matter](https://www.emiliaprotocol.ai/model-to-matter): Executor-side clearance for model-directed physical actions. ## Optional - [Neutrality Covenant](https://github.com/emiliaprotocol/emilia-protocol/blob/main/docs/NEUTRALITY-COVENANT.md): Open verifier, format, and conformance commitments. - [Threat Model](https://github.com/emiliaprotocol/emilia-protocol/blob/main/THREAT_MODEL.md): Explicit deployment and trust assumptions.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

