Scope: RFC 4949 is an Informational glossary. Its definitions help expose category errors in a design review; they do not by themselves prescribe an architecture or prove conformance.
An A2A gateway validates a client certificate and forwards `X-Agent-ID` to a backend. Any workload on the internal network can also create that header. The backend deletes a resource solely because the header names its owner.
A debug configuration writes reusable identity grants to a shared log. An internal account can read the log, and an operator intentionally copies a grant and reuses it. The profile treats any unauthorized log exposure of a raw grant as a successful attack.
A backend accepts identity and authorization results only from one gateway. The design document calls the gateway “trusted” but gives no protected channel, isolation argument, review evidence, or recovery plan. A reviewer says the label proves the gateway cannot violate policy.
An Agent Card signature validates, TLS authenticates a gateway, and an identity grant is current. The gateway forwards an Agent ID to a backend, which applies its own delete policy. The document concludes that the request is therefore confidential, authorized, and risk-free at every hop.