VALIDATION / PROTOCOL · MCP · MULTICLOUD

Evidence for authority
across boundaries.

Verimand publishes validation status separately from product roadmap claims. This page records what is validated today and which identity integrations remain limited.

Protocol evidence.

VAGP 0.3 is public, conformance-tested and independently implemented from its public artifacts.

VAGP 0.3 open protocol

Public specification, schemas, vectors and baseline crypto profile.

CF-01 Core

81/81 required black-box conformance checks.

Independent Go implementation

Clean-room Core implementation validates implementability from public artifacts.

Agent interface evidence.

The Verimand MCP Authority Server is publicly available for authority resolution and inspection. Tool availability does not itself grant authority.

PUBLIC MCP AUTHORITY SERVERnpx -y @verimand/mcp-authority-server@0.1.0

dev.verimand/mcp-authority-server

SIX AUTHORITY TOOLS
  • verimand.resolve
  • verimand.explain
  • verimand.get_authority
  • verimand.get_mandate
  • verimand.get_agent_dna
  • verimand.verify_permit

Enforcement evidence.

Gateway validation demonstrates fail-closed protected execution, replay blocking and signed outcome evidence in the validated profiles.

Authority Gateway

Gateway enforcement path validated in controlled pilot and multicloud scenarios.

DENY → zero protected execution

Denied requests do not reach the protected resource.

Durable replay protection

Replay attempts are blocked before repeat downstream execution.

Signed evidence

Outcome evidence is signed and carries Evidence Certainty.

Agent-to-agent delegation evidence.

A2A delegates tasks. VAGP governs delegated authority. A2A-01 validates the boundary with the official A2A protocol without adding A2A-specific authority semantics to VAGP.

Agent A↓ A2AAgent B↓ Verimand / VAGPPERMIT / DENYProtected MCP Tool
A2A protocolOfficial A2A protocol 1.0 tested
Task receiptDoes not grant authority
Agent Card capability declarationsDo not grant authority
Bounded delegationVALIDATED
Multi-hop attenuationVALIDATED
Amplification / launderingDENIED
Revocation / replayDENIED
DENY → protected executionZERO EXECUTION

This supports a narrow interoperability claim: A2A task and Agent Card metadata can carry work intent and discovery information, but they do not bypass trusted identity binding, Agent DNA, VAGP mandates, attenuation, revocation or replay controls. It does not claim a public Verimand A2A package, production A2A Gateway or A2A certification.

Real multicloud evidence.

MC-02 validates real Azure and Google Cloud authority enforcement in a narrow controlled test scope. This is not a production SaaS availability claim.

AzureVerimand Authority Layer / VAGPGoogle Cloud
Azure → GCPREAL VALIDATED
GCP → AzureREAL VALIDATED
Real protected resourcesVALIDATED
GCP → Azure replay/revocationVALIDATED

Sanitized MC-02 evidence supports bidirectional Azure/GCP validation, Google WIF, GCP → Azure replay/revocation enforcement and real SPIFFE/SPIRE SVID issuance. It does not validate all clouds, all identity providers or production operation.

Identity status.

Identity establishes who the agent is. Verimand governs what it is authorized to do. Provider-neutral authority semantics are architecturally validated while real provider coverage is still expanding.

REAL VALIDATED

Google Workload Identity Federation

Validated through the provider-neutral trusted identity seam.

REAL SVID ISSUANCE VALIDATED

SPIFFE/SPIRE

Gateway verifier integration is not yet fully validated.

NOT YET VALIDATED

Microsoft Entra Agent ID

Blocked on the blueprint credential/token path.

VALIDATED

Local signed identity

Used as the deterministic baseline for authority semantics.

Bring your identity. Keep one authority model. Provider identity must not itself grant authority.