Opportunity
The current README now leads with interoperability and conformance. Those are important credibility and ecosystem mechanisms, but they make AgentPass appear to be primarily a standards-testing utility rather than an operational action-authorization product.
AgentPass needs one consistent hierarchy: product category first, operational promise second, portable provider trust as the differentiator, and standards/conformance as the open ecosystem strategy.
Scope
- Restore a product-led README headline and opening description centered on action authorization and execution assurance.
- Add one canonical positioning document covering category, core promise, capability hierarchy, audience-specific entry points, differentiation, standards posture, and explicit non-positioning claims.
- Align the README roadmap and action-gate roadmap around three layers:
- runtime authorization and control;
- portable provider trust and interoperability; and
- execution and outcome assurance.
- Keep framework integrations and conformance suites as delivery mechanisms within that hierarchy, not parallel product categories.
- Align package metadata where it presents the public project description.
- Add automated documentation assertions for the canonical language, links, hierarchy, and standards boundary.
Non-goals
- No project rename or package rename.
- No removal of the standards crosswalk, conformance suites, provider middleware, observability, or assurance work.
- No new protocol, receipt schema, runtime behavior, API, dependency, or hosted deployment.
- No marketing campaign, social post, or external standards submission.
- No claim that AgentPass replaces IAM, OAuth, MCP authorization, AuthZEN, SPIFFE, WIMSE, OPA, Cedar, or provider business authorization.
Acceptance criteria
Acceptance-test plan
Automated:
- Assert the README headline, positioning-document link, and three roadmap layers.
- Assert the canonical positioning document contains the category, core promise, audience map, standards boundary, and non-replacement language.
- Assert the action-gate roadmap links the canonical positioning document and uses the same three layers.
- Run the full repository test suite and documentation whitespace/link-path checks.
Human validation: none required; the requested messaging and hierarchy are explicitly captured above and can be asserted from the repository content.
Risks and security considerations
This is documentation and package-description work only. The primary risk is overclaiming interoperability or obscuring existing product capabilities. The change must preserve experimental labels, avoid certification claims, and make no authentication, authorization, data, permission, dependency, or network change.
Opportunity
The current README now leads with interoperability and conformance. Those are important credibility and ecosystem mechanisms, but they make AgentPass appear to be primarily a standards-testing utility rather than an operational action-authorization product.
AgentPass needs one consistent hierarchy: product category first, operational promise second, portable provider trust as the differentiator, and standards/conformance as the open ecosystem strategy.
Scope
Non-goals
Acceptance criteria
Acceptance-test plan
Automated:
Human validation: none required; the requested messaging and hierarchy are explicitly captured above and can be asserted from the repository content.
Risks and security considerations
This is documentation and package-description work only. The primary risk is overclaiming interoperability or obscuring existing product capabilities. The change must preserve experimental labels, avoid certification claims, and make no authentication, authorization, data, permission, dependency, or network change.