Protocol messages make Agent action governable

What Agents send, what Relay checks, and what the receipt returns

Envelope fields

Every message needs attribution, factor context, receipt, and trace

Actor ref

Who is acting

Names the Agent and capability version

Attribution

Proposed action

What may happen

States type, object, requested outcome, policy, and risk

No execution

Evidence refs

What supports it

Points to evidence without private payloads

Ref only

Decision factors

What Relay checks

Identity, authority, evidence, policy, and risk

Review basis

Decision Receipt

What Relay returns

Preserves decision, factors, reason, next step, and trace

Response

Why the schema matters

Structured Agent action can support durable review

Attributable

Actor and capability are explicit

Factor-ready

Authority, evidence, policy, and risk are explicit

Versioned

Action stays tied to active versions