Skip to content

docs(roadmap): bring the roadmap up to what actually shipped - #132

Merged
imran-siddique merged 2 commits into
mainfrom
docs/roadmap-currency
Aug 8, 2026
Merged

docs(roadmap): bring the roadmap up to what actually shipped#132
imran-siddique merged 2 commits into
mainfrom
docs/roadmap-currency

Conversation

@imran-siddique

Copy link
Copy Markdown
Contributor

Response-plan list 1, P1.

ROADMAP.md opened with "Now — v0.1 draft (June 2026)" and listed the MCP profile, the A2A profile and cMCP Phase 2 under "Next — v0.2 (Q3 2026)". The repo ships spec v0.2, SDK 0.6.0, and a 0.4.1 conformance suite. The roadmap is the second file a serious evaluator opens and it said the project was two months behind where it is.

What changed

Now/Next/Later re-cut against the code rather than against the plan.

Shipped now lists what landed: the profile URI cutover and its enforcement in verify_record(), the delegation link block, transparency optional below Level 2, the azure-cvm-sev-snp platform, revocation at verification time, the OWASP and Acta cross-walks, and the AGT/cMCP/sandbox producer adapters.

Two corrections of substance, not just dates:

  • The delegation block is described as the foundation the A2A profile binds to, not as the profile. The normative binding rules are the outstanding work, and the old text let a reader conclude otherwise.
  • The anchor and inclusion-proof format (Publish the registry anchor format (inclusion-proof spec) publicly #111) is named as the highest-priority item on the page. Until it publishes, "verifiable without trusting the operator" is a claim about the future, and the roadmap should say so where an evaluator will read it.

One accuracy fix. The platform bullet describes what this repo does: the SDK verifies the record; verification of attestation evidence lives in cmcp and agent-manifest.

Added to Next: attested memory and persistent state, per the response plan.

Follow-up not in this PR

Two places in spec/trace-v0.2.md are stale in the same way and need their own change:

🤖 Generated with Claude Code

imran-siddique and others added 2 commits August 8, 2026 09:10
ROADMAP.md opened with "Now - v0.1 draft (June 2026)" and listed the MCP
profile, the A2A profile and cMCP Phase 2 under "Next - v0.2 (Q3 2026)", while
the repository ships spec v0.2, SDK 0.6.0 and a 0.4.1 conformance suite. The
roadmap is the second file a serious evaluator opens and it said the project was
two months behind where it is.

Now/Next/Later re-cut against the code. Shipped lists the profile URI cutover
and its enforcement, the delegation link block, transparency optional below
Level 2, the azure-cvm-sev-snp platform, revocation at verification time, the
OWASP and Acta cross-walks, and the AGT/cMCP/sandbox producer adapters.

Two corrections of substance rather than dates. The delegation block is
described as the foundation the A2A profile binds to and not as the profile,
because the normative binding rules are the outstanding work. And the anchor and
inclusion-proof format (#111) is named as the highest priority item on the page,
since without it "verifiable without trusting the operator" is a claim about the
future.

The platform bullet says what this repository does rather than what the stack
does: the SDK verifies the record, and verification of attestation evidence
lives in cmcp and agent-manifest.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The Later section said "CoSAI / Linux Foundation" and my first pass replaced it
with AAIF. Neither is right. TRACE is being formed as its own LF series, "TRACE
Specification, a Series of LF Projects, LLC", which #127 is preparing
GOVERNANCE.md for.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@imran-siddique
imran-siddique merged commit b849b67 into main Aug 8, 2026
5 checks passed
@imran-siddique
imran-siddique deleted the docs/roadmap-currency branch August 8, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant