範囲: RFC 4949はInformationalな用語集です. 定義はdesign reviewでcategory errorを見つける助けになりますが, それだけでarchitectureやconformanceを決定するものではありません.
A2A gatewayがclient certificateをvalidateし, backendへ`X-Agent-ID`を転送します. internal network上の任意workloadも同じheaderを作成できます. backendはheaderがresource ownerを示すことだけを根拠に削除を実行します.
debug設定により再利用可能なidentity grantがshared logへ書かれます. internal accountはlogを読め, operatorが意図的にgrantをcopyして再利用しました. profileはraw grantのunauthorized log exposureをsuccessful attackとします.
backendは1つのgatewayから届くidentityとauthorization resultだけを受理します. design文書はgatewayを“trusted”としますが, protected channel, isolation, review evidence, recovery planは示しません. reviewerはlabelだけでgatewayがpolicyへ違反できないと主張します.
Agent Card signatureはvalidで, TLSはgatewayをauthenticateし, identity grantは期限内です. gatewayはAgent IDをbackendへ転送し, backendは固有のdelete policyを適用します. 文書はrequestが全hopでconfidential, authorized, risk-freeだと結論します.