ARIA 1.0 · WHAT IS SPECIFIED BUT NOT YET RUNNING
Planned work
19 itemslinked from every [PLANNED] box
Every [PLANNED] box in the specification links to one entry here. The rule behind the list: the specification only asserts as running what runs at api.aria.bar; everything else is named, with what it depends on. No dates are promised on this page.
ℹ
Items are grouped by the section that references them. An item disappears from this page when it ships and the specification stops marking it.
Signed delegation chain for sub-agentsRegistry issuance · spec §6
Spec §6 describes delegation to sub-agents with a signed chain at every hop, scope narrowing and a traceable principal. Today the AID carries delegationDepth (signed by the issuer) and ATP compares it against depth=; no registry issues sub-agent credentials with a signed chain, so every issued credential carries delegationDepth 0.
depends on: BACKEND-deuda-atp-1_0.md
Issuance cutover to ARIA 1.0§0 · §7 · §11
Credentials issued with spec_version "1.0" by TrustLayer Foundation (issuer DID to be announced). Until then, preview credentials remain resolvable and are distinguished by issuer.
depends on: the authority signing path and a TLF issuer key
No credential above L0 has been issued. Each level opens after the operating registry is evaluated for it (AUD-04).
depends on: registry conformance evaluation per level
L0 issuance predates the Verification Requirements; its AUD-04 evaluation happens before the cutover.
A signed key document resolvable from the issuer DID and served at a well-known location, so keys stop being pinned only in the SDK and rotation becomes possible.
Signed accreditation list§5 · §3.5.2 step 10
A TLF-signed list of accredited registries with attestation key, ceiling level, accredited_from and distrust_after — the data a verifier needs to apply the forward-only distrust rule itself.
Out-of-band distribution of the root that signs the accreditation list: pinned in SDK releases, published fingerprint, ceremony record.
Emergency revocation with out-of-band identity verification, 3-of-5 secret sharing and an HSM-generated root key, modeled on the DNSSEC root ceremony.
Session key establishment. Not deployed; the live suite is FIPS 204 + RFC 8032.
Hash-based signatures for long-lived registry records. Not deployed.
A schema field naming who takes over on principal change. Schema 1.0 stable has no field for it yet.
Signed Security Event Tokens to enterprise IAM within seconds of revocation. Not deployed.
Agent Interaction Log§7 · §8
Per-ATP-event logging (each handshake, admission, rejection) as a system separate from the Trust Ledger. No committed date.
The full ATP/1 text — eleven-step algorithm, conformance vectors, SDK requirements — published as its own document linked from §8 and from /protocol.
The challenge endpoint the holder proof needs is disabled in production; ATP admission at L1+ depends on it.
Trust Seals and qualify=Appendix C
Seals are specified; qualify= is reserved in ATP/1 and never evaluated until the seals exist.
Python and Rust verifier SDKsAppendix A
Verification-only, single Rust core, golden vectors as the contract. TypeScript is live.
The canonical text is Spanish. Until the translation is published, the Spanish text governs.
The v1.3 draft is the arbitration's proposal; it becomes the Requirements when TrustLayer Foundation adopts it.