Skip to content

docs(ws4): correct two question citations in the #172 evidence mapping - #495

Draft
Levaj2000 wants to merge 1 commit into
mainfrom
claude/cosai-containment-followup-dcxkaw
Draft

docs(ws4): correct two question citations in the #172 evidence mapping#495
Levaj2000 wants to merge 1 commit into
mainfrom
claude/cosai-containment-followup-dcxkaw

Conversation

@Levaj2000

Copy link
Copy Markdown
Owner

Draft — standards-facing copy, so this wants a human pass before merge (per AGENTS.md, OCSF/CoSAI work is hand-back-not-merge).

docs/cosai-ws4-ocsf-mapping/evidence-contract-ocsf-mapping.md is linked from cosai-oasis/ws4-secure-design-agentic-systems#172, which now has named reviewers on the follow-on paper. Its Q citations were checked against the issue text as filed; two did not hold.

1. Header claimed Q14/Q15; only Q14 is delivered

WS4 #172 Q15, verbatim:

The blog gives an alerting list. A serious treatment needs the harder half: what the false-positive profile looks like when normal agent behavior includes filesystem exploration and tool discovery, and what correlation across runs actually requires operationally.

That is detection-side material, and the document's own scope note already says "the detection table is separate follow-on work" — so the header and the body disagreed. The header is now Q14 alone, which is what the CHANGELOG entry for #493 said all along.

The scope note gains two clarifications:

  • Q14 has two halves — the concrete logging schema (delivered here) and whether it belongs in the paper or a playbook (a WG placement call this document does not make).
  • Q15 is out of scope and, as of writing, unclaimed.

2. Schema gap register cited Q16 for cross-boundary causal binding

Q16 is reachability minimisation vs. patch hygiene (§9) — unrelated. The resource owner's record naming the causing tool call (ocsf/ocsf-schema#1738) is the evidence complement of §5, "The permitted channel is the exfiltration path" (Q9–Q10), where a permitted party acts on the agent's behalf. Re-cited as §5 / Q9–Q10.

Scope

Citations and scope prose only. No mapping row, status marker, wire-evidence mark, producer gap, or OCSF schema claim changes; the v1.9.0 pin and the 2026-08-25 verification date are untouched.

Verification

  • scripts/check-pillar-consistency.sh — exit 0.
  • No code touched, so no test suite is implicated; pytest was not run.
  • Q1's citation (§1, bounded-authority frame) was re-checked in passing and is correct — left as is.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G1zAg5GTfhh1AeKVZJ2uto


Generated by Claude Code

Checked the document's Q citations against the issue text as filed.

Q14/Q15 in the header: WS4 #172 Q15 asks for the false-positive profile
of normal agent behaviour and what cross-run correlation requires
operationally. That is detection-side material the document already
defers in its own scope note, so claiming Q15 overstated coverage.
Retitled to Q14, and the scope note now states that Q14's placement half
(paper vs. playbook) is a WG call this document does not make, and that
Q15 is out of scope and unclaimed. The CHANGELOG entry for #493 already
described this as the Q14 deliverable; the header now agrees.

Q16 in the schema gap register: Q16 is reachability minimisation vs.
patch hygiene (section 9). The resource owner's record naming the causing
tool call is the evidence complement of section 5 (Q9-Q10), where a
permitted party acts on the agent's behalf. Re-cited.

No mapping row, status, wire-evidence mark, or OCSF claim changes.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G1zAg5GTfhh1AeKVZJ2uto
@vercel

vercel Bot commented Aug 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ai-identity-landing Ready Ready Preview Aug 27, 2026 3:57pm
dashboard Ready Ready Preview Aug 27, 2026 3:57pm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants