VERIFICATION REVIEW — Agent lifecycle, receipts, conformance, and recovery #33
satonakaoshimoto
started this conversation in
M5-AI Agents
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
How do we prove an M5Agent remained inside authority throughout its lifecycle?
Agent safety must be demonstrated across definition, activation, use, suspension, revocation, replacement, recovery, and retirement—not assumed from a model name or one successful test.
A reviewable lifecycle should cover:
Recovery must restore only authority that remains current. It must not silently reactivate an expired role, revoked credential, compromised device, withdrawn consent, obsolete policy, or prior agent grant.
Help us review
Start with the M5-agent hub · Review the authorization test matrix · Read the M5POD activation state model
Automated tests support but do not replace domain, legal, security, privacy, accessibility, governance, or accountable human review.
All reactions