<?xml version='1.0' encoding='utf-8'?>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<rfc category="info" docName="draft-das-enterprise-ai-output-finality-00"
     ipr="trust200902" submissionType="IETF" xml:lang="en" version="3"
     tocInclude="true" tocDepth="3" symRefs="true" sortRefs="true">
  <front>
    <title abbrev="Enterprise Output Finality">A Compromised AI Server Must Not Become a Map of the Enterprise: Non-Joinable Vaults and Output-Release Finality</title>
    <seriesInfo name="Internet-Draft" value="draft-das-enterprise-ai-output-finality-00"/>
    <author fullname="Sangam Das" initials="S." surname="Das">
      <organization>Independent Inventor</organization>
      <address>
        <postal>
          <city>Balasore</city>
          <region>Odisha</region>
          <code>756001</code>
          <country>India</country>
        </postal>
        <email>info@sangamdas.com</email>
      </address>
    </author>
    <date year="2026" month="August" day="27"/>
    <area>Security</area>
    <keyword>enterprise AI</keyword>
    <keyword>non-joinability</keyword>
    <keyword>output release</keyword>
    <keyword>execution finality</keyword>
    <keyword>data vault</keyword>
    <abstract>
      <t>Past cyber theft stole files. Present theft steals live
      sessions and SaaS tokens. The next theft does not need a
      dump. A frontier enterprise assistant that can see mail,
      tickets, code, finance, and memory can join those fragments
      into a meaning that was never stored as one record, then
      act. That is enterprise-future mapping: reconstruction of
      strategy, relationships, and probable next moves, followed
      by send, write, or tool invoke
      <xref target="DAS-ISOLATION"/>.</t>
      <t>IAM, DLP, clean rooms, TEEs, and output filters still answer
      who may touch a store. They do not answer whether
      separately lawful fragments may be joined into a new
      protected meaning, or whether that meaning may leave through
      Claude, ChatGPT Enterprise, a computer-use agent, or an MCP
      tool.</t>
      <t>This profile keeps identity, content, and association under
      independently controlled vaults, joins them only under a
      session-bound Reconstruction Authorization Object, seals the
      Candidate Output, commits a receipt before release
      authority exists, and completes send, render, store, or
      invoke only at an Output Release Boundary. Compromise of
      the model host is not reconstruction. Reconstruction is not
      release.</t>
    </abstract>
  </front>
  <middle>
    <section anchor="intro">
      <name>Introduction</name>
      <t>The next enterprise-AI security war will not be fought only
      over model intelligence. It will be fought over who may
      join information into meaning, and who may turn that meaning
      into action. That framing is developed in version 2 of
      "Why the Next AI War Will Be Won on Isolation, Not
      Intelligence" <xref target="DAS-ISOLATION"/>, which defines
      enterprise-future mapping as reconstruction of strategy and
      probable action from distributed weak signals, and argues
      that isolation of join authority and isolation of
      effectuation matter more than another increment of model
      IQ. This document is the protocol profile for that
      split.</t>
      <t>The path inside a hosted or on-prem assistant is now:</t>
      <artwork><![CDATA[
mail + CRM + git + finance + memory
        -> frontier model / agent runtime
        -> join fragments into new meaning
        -> text / tool / computer-use / mail
        -> external consequence
]]></artwork>
      <t>This document controls the two arrows conventional security
      still treats as the model's private business. Identity,
      content, and the map that joins them MUST NOT become one
      object on the model host outside an authorized
      reconstruction session. A generated Candidate Output MUST
      NOT become mail, file, API, payment, screen, or MCP invoke
      merely because the model finished.</t>
      <t>The profile uses the execution-finality chain in
      <xref target="I-D.das-6g-finality"/> and the tool-dispatch
      sink in <xref target="I-D.das-agentic"/>. It adds the
      enterprise predicates those drafts do not specify:
      independently controlled vaults, Technical Non-Joinability,
      a Reconstruction Authorization Object, disclosure and
      inference-channel budgets, Sealed Candidate Outputs, a
      Protected Output Validation Receipt committed before
      capability issuance, and an Output Release Boundary.</t>
    </section>

    <section anchor="theft">
      <name>How Cyber Theft Changed</name>
      <t>A protocol that asks enterprises and frontier labs to change
      their assistant runtime has to say why last decade's
      controls are the wrong picture of the incident. The
      incident class moved. The controls did not.</t>

      <section>
        <name>Past: Steal the Store</name>
        <t>The historical breach was a copy of what already existed.
        An attacker took a file share, a customer database, a
        card dump, or a backup tape. Harm scaled with volume:
        more rows, more accounts, more records for sale. Defense
        scaled the same way: perimeter, patch, encrypt-at-rest,
        vault the database password, watch the egress link for a
        bulk transfer.</t>
        <t>That model had a hidden assumption. The valuable object
        was a record someone had already written down. Joining
        two tables was a report the business ran on purpose. The
        application server was allowed to be the place where
        identity and content met, because the application was
        narrow and the output was a form, not a strategy.</t>
        <t>Famous incidents of that era — bulk PII theft, payment
        dumps, leaked source archives — were catastrophic and
        still conceptually simple. The attacker left with
        yesterday. They did not automatically acquire a machine
        that could keep asking "what will this firm do next" on
        live mail and tickets.</t>
      </section>

      <section>
        <name>Present: Steal the Session and the Connector</name>
        <t>The current incident is often not a database export. It
        is a token, a laptop, a poisoned plugin, or a
        prompt-injected document that rides an already-authorized
        assistant. Enterprises have connected frontier models to
        the same corpus a human VP can see: Drive, Slack or
        Teams, GitHub, Salesforce, ServiceNow, ERP, and a vector
        store of "everything we embed."</t>
        <t>Access control still works as designed for each system.
        The assistant is an authorized user of each. The new
        fact is concentration. One runtime holds simultaneous
        views that no single human would hold in one sitting, and
        it can keep them in context across turns. A phishing
        mail that says "summarize the attached with our internal
        tools" is no longer a text event. It is a join event
        plus, if tools are on, an action event.</t>
        <t>Present theft therefore looks like: session hijack of
        ChatGPT Enterprise or a Claude work seat; OAuth grant to
        an MCP or connector that was meant for search; a
        retrieved wiki page that contains instructions; a
        computer-use agent that can see a screen the DLP product
        never hashed. Encryption and SSO are up. Reconstruction
        still happens, because reconstruction is what the product
        is for.</t>
      </section>

      <section>
        <name>Future: Steal the Meaning, Then the Act</name>
        <t>The coming incident does not require a dump and does not
        require the attacker to understand the business. The
        model does the correlation. Individually lawful
        fragments — a complaint, a bug, a pricing note, a hiring
        req, a board draft — become a map of launch timing,
        target accounts, unreleased defects, and negotiation
        room. That map was never a row in any system of
        record.</t>
        <t><xref target="DAS-ISOLATION"/> calls this
        enterprise-future mapping: extraction of strategic
        intelligence through AI-driven correlation of distributed
        weak signals. Conventional security governs who may
        access a resource. It does not govern whether separately
        accessible information may be joined into a new protected
        meaning. Once the fragments are in one authorized
        context window, possession becomes reconstruction. If
        the same context can call mail, payments, tickets, or a
        browser, reconstruction becomes consequence.</t>
        <t>The failure mode this profile is built to change is
        therefore not "breach impossible." It is: compromise of
        one intelligent component MUST NOT automatically become
        compromise of the organisation's complete data
        relationships, strategic intelligence, and future. Isolation
        of join authority and isolation of release authority
        matter more than another point of model IQ
        <xref target="DAS-ISOLATION"/>.</t>
      </section>
    </section>

    <section anchor="rfc2119">
      <name>Requirements Language</name>
      <t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL",
      "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT
      RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be
      interpreted as described in BCP 14 <xref target="RFC2119"/>
      <xref target="RFC8174"/> when, and only when, they appear in
      all capitals, as shown here.</t>
      <t>Failure to establish current reconstruction or output-release
      authority MUST NOT be converted into permission to join
      vaults or to release a Candidate Output.</t>
    </section>

    <section anchor="problem">
      <name>Problem Space</name>
      <t>A stolen database dump is a collection of rows. A
      compromised enterprise assistant is a joining engine. It
      can take customer complaints, unreleased defects, engineering
      threads, pricing notes, and launch plans and emit a
      structured report of what the firm will ship, to whom, and
      when. That report is not "another record." It is a map of
      the enterprise's future.</t>
      <t>The practical failures look like this:</t>
      <ul>
        <li>The AI server holds credentials for CRM, git, mail, and
        finance. Compromising that process inherits every join
        those credentials can make.</li>
        <li>Identity and content live in different tables. The
        mapping table lives on the same application credential.
        Separation of storage is not separation of association
        authority.</li>
        <li>A clean room or RAG index still returns joinable
        plaintext to the same workload that can send mail.</li>
        <li>An output filter labels the report "internal." The
        runtime then posts it because the model selected
        message.send.</li>
        <li>A session that was allowed to reconstruct three fields
        for ticket triage is reused to reconstruct a customer-to-
        roadmap association.</li>
        <li>A sealed file is copied to another gateway that does
        not check destination, epoch, or output digest.</li>
      </ul>
      <t>The missing questions are: may these vaults be joined for
      this purpose in this session, and may this exact generated
      artifact leave through this boundary now.</t>
    </section>

    <section anchor="industry">
      <name>Industrial Applicability for Frontier Enterprise AI</name>
      <t>This section is written for the products that actually sit
      on the path above: hosted enterprise assistants, tool-using
      agents, computer-use agents, and connector/MCP fleets.
      Vendor names are deployment classes, not claims about
      unpublished internals.</t>

      <section>
        <name>What "Enterprise Seat" Concentrates</name>
        <t>A ChatGPT Enterprise, Claude for Work, or equivalent
        seat is not a chatbot with a login. It is a retrieval
        and action surface. Typical connectors already include
        mail and calendar, document stores, ticketing, CRM,
        source hosting, and data warehouses. Projects, memory,
        and team workspaces persist fragments across days. MCP
        and function calling add write paths: create ticket,
        send mail, open PR, update row, drive a browser.</t>
        <t>The industrial fact is concentration of join plus
        concentration of act in one context window. A human
        analyst is slow and scoped. The seat is neither. That
        is why past DLP (watch the USB stick) and present CASB
        (watch the OAuth grant) do not finish the job. The
        grant is intended. The join is the product. The act is
        a checkbox.</t>
      </section>

      <section>
        <name>How a Frontier Runtime Would Use This Profile</name>
        <t>Placement is not "put the whole model in a vault."
        Placement is two gates the vendor already almost has:</t>
        <ol>
          <li>Before retrieval and association: each connector
          returns identity fragments, content fragments, or
          mapping fragments under a Reconstruction Authorization
          Object bound to tenant, purpose, field set, association
          scope, session epoch, and workload identity. The
          model host sees a minimum-necessary view, not a
          universal join.</li>
          <li>Before any leaving the runtime: generated text,
          file, mail, tool call, computer-use submit, or memory
          write is a Sealed Candidate Output. Output
          verification commits a receipt. An Output Release
          Capability is consumed at the mail gateway, file
          commit, MCP dispatcher <xref target="I-D.das-agentic"/>,
          or browser submit.</li>
        </ol>
        <t>The model, including a frontier model used as the
        enterprise brain, stays in the compute role. It does
        not hold relationship-mapping authority and does not
        hold the last unsealing step. That is how a lab that
        sells "the model is smart enough to use tools" avoids
        selling "the model is the enterprise map."</t>
      </section>

      <section>
        <name>Anthropic-Class Tool and Computer-Use Seats</name>
        <t>A Claude work deployment with tool use or computer use
        is the clean industrial fit. Constitutional or policy
        trained refusal is the first filter. This profile is
        the second gate that does not trust the model. A
        computer-use click that would send a customer list, or a
        tool call that would export a repo issue joined to a
        named account, is denied at association scope or at the
        boundary even if the model complied with the injected
        page.</t>
        <t>How: treat every connector as a vault class (identity
        vs content vs map). Treat every computer-use
        submission as an Output Release Boundary with a live
        digest of what will leave the machine. Treat MCP
        server discovery as non-authority, same rule as
        <xref target="I-D.das-agentic"/>.</t>
      </section>

      <section>
        <name>OpenAI-Class Enterprise, GPTs, and Agent Runtime</name>
        <t>A ChatGPT Enterprise workspace with GPTs, actions, and
        memory is the other clean fit. Custom GPTs already
        accumulate instructions and retrieval. Actions already
        call customer APIs. Memory already persists
        associations the user did not store as a record.</t>
        <t>How: memory write is a Candidate Output of type
        MEMORY_WRITE and needs its own receipt; otherwise
        today's injected "remember the competitor list"
        becomes tomorrow's reconstruction authority. Actions
        are tool-dispatch sinks. File download and "share this
        chat" are Output Release Boundaries. A project that
        mixes legal and engineering corpora needs a narrower
        Permitted Association Scope than a general chat.</t>
      </section>

      <section>
        <name>Why Labs Should Care Commercially</name>
        <t>Enterprise procurement is already asking what happens
        when the assistant is prompt-injected or when a
        contractor's seat is stolen. An answer that is only
        "the model is aligned" or "we log prompts" will lose to
        an answer that is "the seat cannot join identity to
        unreleased defect, and cannot send the report, without
        a consumed capability." That is a product differentiator
        for anyone selling frontier models into banks, labs,
        governments, and operators. It is also the failure-mode
        change argued in <xref target="DAS-ISOLATION"/>: isolation
        of join and isolation of action, not another benchmark
        point of intelligence.</t>
      </section>
    </section>

    <section anchor="existing">
      <name>Existing Solutions and What They Do Not Bind</name>
      <section>
        <name>IAM, RBAC, and Application Credentials</name>
        <t>Directory and token systems decide which process may call
        which API. An AI server that is "the app" typically
        receives a union of those rights. Compromise of that
        process is then compromise of the union. IAM does not
        split association authority from content authority.</t>
      </section>
      <section>
        <name>DLP and Output Classifiers</name>
        <t>DLP and safety classifiers inspect text for patterns.
        They are probabilistic and sit on the same host that
        already has the plaintext. A missed classification plus a
        send-mail tool is the incident. A classifier ALLOW is not
        an output-specific, single-use release capability.</t>
      </section>
      <section>
        <name>Tokenization, Hashing, and Field Encryption</name>
        <t>Tokenization hides a column from some readers. If the
        AI server can detokenize, or if tokens plus a mapping
        table reconstruct the person, the join still lives in one
        place. Field encryption without independently controlled
        relationship-mapping authority is storage hygiene, not
        Technical Non-Joinability.</t>
      </section>
      <section>
        <name>Confidential Computing and Enclaves</name>
        <t>A TEE can attest the workload and keep keys off the
        host. If the attested workload is still given joined
        enterprise plaintext and a network socket, the enclave
        becomes a high-assurance joining engine. Confidential
        computing is a substrate for a PED or vault. It is not
        by itself a reconstruction or release protocol.</t>
      </section>
      <section>
        <name>Clean Rooms and Data-Sharing Enclaves</name>
        <t>Clean rooms limit who may run a query. They do not
        necessarily: split identity from association; bind
        reconstruction to a session epoch; seal the model output;
        commit a receipt before release; or treat render, mail,
        and tool invoke as the same boundary. A clean room that
        returns a joinable result to an agent with tools is an
        input to this profile, not a replacement for it.</t>
      </section>
      <section>
        <name>RAG Isolation and Prompt Firewalls</name>
        <t>Retriever isolation and prompt firewalls reduce how much
        raw corpus the model sees. They do not stop a permitted
        retrieval set from being associated beyond the Permitted
        Association Scope, and they do not consume release
        authority at the mail or file gateway.</t>
      </section>
      <section>
        <name>What This Profile Adds</name>
        <ul>
          <li>identity, content, and relationship-mapping are
          independently controlled vaults;</li>
          <li>join occurs only under a non-bearer Reconstruction
          Authorization Object inside a Protected Reconstruction
          Domain;</li>
          <li>released components are session-bound and
          ephemeral;</li>
          <li>model output is a Sealed Candidate Output the
          workload cannot unseal;</li>
          <li>a Protected Output Validation Receipt is committed
          before any release capability exists;</li>
          <li>the capability is bound to output digest,
          destination, recipient, session epoch, and boundary;
          and</li>
          <li>the Output Release Boundary is the only component
          that may complete send, render, store, or invoke.</li>
        </ul>
      </section>
    </section>

    <section anchor="pillars">
      <name>Three Pillars</name>
      <section>
        <name>Decomposition of Authority</name>
        <t>No ordinary AI server holds complete authority over
        data-to-consequence. Protected information is decomposed
        across an identity vault, a content vault, a
        relationship-mapping vault, an optional
        cryptographic-material vault, a Protected Authorization
        Domain, a Protected Reconstruction Domain, an Output
        Verification Stage, a Protected Receipt Store, and an
        Output Release Boundary.</t>
        <t>Authority to read an identity MUST NOT, by itself,
        authorize associating that identity with protected
        content. Authority to read content MUST NOT, by itself,
        authorize identifying the person, account, device, or
        commercial relationship to which that content belongs.
        Authority to read both MUST NOT, by itself, authorize
        establishing or disclosing the relationship.</t>
      </section>
      <section>
        <name>Mandatory Mediation</name>
        <t>Every consequence-bearing Candidate Output — text,
        report, image, API request, database update, retrieval,
        tool call, mail, payment, external-model prompt, memory
        write, or actuator command — MUST pass a protected
        finality path. The workload MUST NOT receive
        unrestricted authority to release what it generates.</t>
      </section>
      <section>
        <name>Technical Non-Completability</name>
        <t>The workload MAY finish generation without acquiring
        the keys, capability, or path needed to make the result
        externally usable. Sealing, receipt commitment,
        capability issuance, and boundary verification are
        constitutive. Skipping any of them MUST leave the output
        non-releasable.</t>
      </section>
    </section>

    <section anchor="join">
      <name>Technical Non-Joinability</name>
      <t>Tables, tenants, and disks that share one application
      credential are not non-joinable. Technical Non-Joinability
      means identity components, content components, and the
      association information required to make them a usable
      enterprise record cannot be combined outside a technically
      authorized reconstruction operation.</t>
      <t>Join MUST occur only inside a Protected Reconstruction
      Domain under a current Reconstruction Authorization Object
      that binds purpose, session, session epoch, permitted
      field set, Permitted Association Scope, execution context,
      use count, and reconstruction domain identity. A copied
      component, mapping fragment, or stale authorization object
      MUST NOT become unrestricted join authority.</t>
      <t>Independent control does not require four physical
      appliances. It requires that credentials, keys, or state
      machines sufficient for one vault are insufficient to
      compel release from another.</t>
    </section>

    <section anchor="recon">
      <name>Session-Bound Reconstruction</name>
      <t>A conforming reconstruction SHOULD release only the
      minimum fields required for the authorized task, bind those
      fields to the session, and make them unusable after
      session close, epoch advance, use-count exhaustion, or
      poison. A Partial Session that fails mid-chain MUST be
      poisoned: it MUST NOT be resumed, replayed, or completed
      with a substituted purpose or destination.</t>
      <t>Vault-local release is not a query the model host runs.
      Each vault evaluates the RAO against its own policy,
      emits only authorized components, and records a
      vault-local receipt. A content vault that sees a valid
      RAO for ticket.summary MUST still refuse
      ticket.internal_root_cause. A relationship vault that
      sees lawful access to both sides MUST still refuse an
      out-of-scope association. That refusal is the difference
      between two encrypted columns and Technical
      Non-Joinability.</t>
      <section>
        <name>Disclosure Budget</name>
        <t>Disclosure Budget is a protected counter over how much
        authorized content may become externally usable in a
        session, project, or tenant window. Units MAY be
        fields, records, tokens, or classified items. The
        budget is decremented at the Output Release Boundary,
        not when the model reads a view. A model that drafts
        ten reports and sends none has not spent the budget.
        A model that sends one report has.</t>
        <t>Implementations SHOULD persist budget state outside the
        model host so a compromised seat cannot reset the
        counter. Exhaustion MUST fail closed even if the
        latest turn is in-scope.</t>
      </section>
      <section>
        <name>Inference-Channel Budget</name>
        <t>Inference-Channel Budget limits reconstructed meaning
        that was never stored as a record: implied roadmaps,
        implied patient-to-arm links, implied negotiation
        room. This is the budget DLP cannot see, because
        there is no string named "strategy." OVS SHOULD score
        or classify association leakage in the Candidate
        Output against the RAO's Permitted Association Scope.
        Repeated near-misses in one session SHOULD consume
        the budget faster than a single narrow summary.</t>
        <t>When the budget is exhausted, further reconstruction
        and further release MUST deny or escalate. A new
        chat title MUST NOT reset the budget if the tenant,
        actor, and corpus are the same. That closeout is how
        "just one more similar question" is stopped from
        becoming future-mapping <xref target="DAS-ISOLATION"/>.</t>
      </section>
    </section>

    <section anchor="output">
      <name>Sealed Output and Release Boundary</name>
      <t>Before a Candidate Output is exposed to an untrusted
      buffer, gateway, or tool dispatcher, it MUST be converted
      to a Sealed Candidate Output or another technically
      non-releasable representation. The workload MUST NOT hold
      the unsealing key or the Output Release Capability.</t>
      <t>The Output Verification Stage re-checks current policy,
      revocation, session epoch, destination, recipient,
      permitted fields, association scope, purpose, budgets, and
      boundary identity. On success it commits a Protected
      Output Validation Receipt to a Protected Receipt Store.
      Only after that commitment MAY an output-specific Output
      Release Capability be issued.</t>
      <t>The Output Release Boundary is the point at which the
      output would first become externally usable or effective:
      network send, API delivery, screen or printer, file
      commit, mail, tool invoke, payment, or memory persist.
      Rendering is release. Tool invocation is release.
      Storing plaintext where another process can read it is
      release. The boundary MUST verify capability, receipt,
      output digest, destination, recipient, session epoch, and
      consumption state, then consume single-use authority.</t>
    </section>

    <section anchor="architecture">
      <name>Architecture</name>
      <figure>
        <name>Compromise path versus finality path</name>
        <artwork><![CDATA[
CONVENTIONAL
AI-server compromise
  -> DB + tool credentials
  -> unrestricted join
  -> strategy reconstruction
  -> generate + send

THIS PROFILE
AI-server compromise
  -> session-bound minimum view only
  -> non-joinable vaults refuse free association
  -> malicious Candidate Output
  -> remains SEALED
  -> live re-verification
  -> receipt MUST be committed
  -> output-specific capability
  -> Output Release Boundary
  -> effect only if every check passes
]]></artwork>
      </figure>
    </section>

    <section anchor="pseudocode">
      <name>Protocol Pseudocode</name>
      <section>
        <name>Reconstruction</name>
        <sourcecode type="pseudocode"><![CDATA[
function RECONSTRUCT(request, ctx):
    rao = ReconstructionAuthorization{
        purpose: request.purpose,
        session_id: ctx.session_id,
        session_epoch: current_epoch(),
        field_set: request.field_set,
        association_scope: request.scope,
        execution_context: attest(ctx.workload),
        use_count: request.use_count,
        budgets: current_budgets()
    }
    if not PAD.validate(rao):
        return DENY(RECONSTRUCTION_UNAUTHORIZED)
    idc = IDENTITY_VAULT.release(rao)      # session-bound
    ctc = CONTENT_VAULT.release(rao)       # session-bound
    rel = RELATIONSHIP_VAULT.associate(rao, idc, ctc)
    if rel is DENY:
        poison(ctx.session_id)
        return DENY(NON_JOINABLE)
    view = PRD.minimum_necessary(idc, ctc, rel, rao)
    HOLD_SESSION_BOUND(view)
    return view
]]></sourcecode>
      </section>
      <section>
        <name>Seal, Verify, Release</name>
        <sourcecode type="pseudocode"><![CDATA[
function ON_MODEL_OUTPUT(raw, ctx):
    sco = SEAL(raw, ctx.session_id, ctx.epoch, intended_boundary)
    # workload cannot unseal
    return sco

function OUTPUT_VERIFY(sco, ctx):
    opened = OVS.inspect_protected(sco)
    if stale(ctx) or scope_exceeded(opened, ctx) or
       budget_exceeded(opened, ctx) or dest_mismatch(ctx):
        poison(ctx.session_id)
        return DENY(OUTPUT_UNVERIFIED)
    receipt = RECEIPT_STORE.commit(opened, ctx)
    orc = ISSUE_OUTPUT_RELEASE_CAPABILITY(receipt, opened, ctx)
    resealed = RESEAL_FOR_BOUNDARY(opened, orc)
    return (resealed, orc, receipt)

function OUTPUT_BOUNDARY_EFFECTUATE(resealed, orc, receipt, live):
    if orc missing or consumed or expired:
        return DENY(NO_OR_USED_CAPABILITY)
    if digest(live) != orc.output_digest:
        return DENY(OUTPUT_SUBSTITUTION)
    if THIS_BOUNDARY != orc.boundary_id:
        return DENY(BOUNDARY_MISMATCH)
    if live.destination != orc.destination or
       live.recipient != orc.recipient:
        return DENY(DESTINATION_MISMATCH)
    if receipt not in RECEIPT_STORE:
        return DENY(RECEIPT_MISSING)
    ATOMICALLY:
        consume(orc)
        unseal_and_emit(resealed, live)
    return RELEASED
]]></sourcecode>
        <t>unseal_and_emit() is unreachable when any check fails.
        Logging a denial and then sending the report is
        non-conforming.</t>
      </section>
    </section>

    <section anchor="usecases">
      <name>Industrial Relevance and Use Cases</name>
      <section>
        <name>Enterprise Copilot on CRM, Code, and Mail</name>
        <t>The motivating attack: the seat is connected to tickets,
        repos, and planning tools; injected or stolen-session
        text asks it to join important customers to unreleased
        defects and emit a competitive-intelligence report to an
        external destination. That is past theft (steal the
        file) replaced by present theft (steal the seat) doing
        future theft (emit the map). Non-joinability blocks the
        customer-to-defect association outside triage scope.
        Sealing plus boundary check blocks the send even if the
        model writes the report. On a Claude or ChatGPT
        Enterprise connector this is a denied association plus a
        denied action, not a red banner in the transcript.</t>
      </section>
      <section>
        <name>Healthcare and Payer Assistants</name>
        <t>Chart text and patient identity must not become one
        object on the model host except under a clinician-purpose
        reconstruction. A summary that names a patient and a
        diagnosis is a Candidate Output. Render on a ward
        workstation and send-to-insurer are different boundaries
        and different capabilities.</t>
      </section>
      <section>
        <name>Banking, Treasury, and Claims</name>
        <t>Account identifiers and transaction narratives live in
        different vaults. Reconstruction for fraud review MUST
        not authorize payout. A generated payment instruction
        is a Candidate Output of a financial class and follows
        <xref target="I-D.das-agentic"/> at the tool sink after
        this profile's receipt commitment.</t>
      </section>
      <section>
        <name>Legal, M&amp;A, and Board Materials</name>
        <t>Privilege and deal strategy are association problems.
        A model that can read the data room and the email graph
        can emit the other side's negotiation map. Permitted
        Association Scope and Inference-Channel Budget are the
        load-bearing controls; DLP string match is not.</t>
      </section>
      <section>
        <name>Multi-Tenant SaaS AI</name>
        <t>Tenant isolation that shares one retrieval credential
        across tenants is the conventional failure. Each
        tenant's identity, content, and mapping vaults MUST be
        independently controlled. A capability issued for
        tenant A MUST fail at a boundary serving tenant B.</t>
      </section>
      <section>
        <name>Regulated Clean-Room Analytics</name>
        <t>A clean-room query may run. The result remains a
        Sealed Candidate Output until output-time verification
        checks jurisdiction, recipient, and budget. Export to
        a laptop is an Output Release Boundary, not a file
        copy.</t>
      </section>
      <section>
        <name>Pharma, Device, and Clinical-Trial Operations</name>
        <t>Protocol, site, and patient-identity fragments are
        separately regulated. A trial-ops assistant that can
        read EDC notes and investigator mail can reconstruct
        enrollment weakness and unblinded signals that no
        system stored as one record. Association scope MUST
        exclude identity-to-arm joining except under an RAO
        that names that purpose. Export to a CRO is a
        different boundary than render to a medical monitor.</t>
      </section>
      <section>
        <name>Semiconductor, Automotive, and Product R&amp;D</name>
        <t>Yield notes, mask comments, and customer-win/loss
        mail are the future-mapping corpus. A seat that can
        join a named OEM to an unreleased node or ADAS
        feature is the incident, even if no GDSII file
        leaves. Inference-Channel Budget is the control
        that DLP cannot replace: the model is inferring,
        not exfiltrating a file named "roadmap.pdf".</t>
      </section>
      <section>
        <name>Energy, Grid, and OT-Adjacent Assistants</name>
        <t>Historian tags are content. Substation or plant
        identity is identity. The map between them is
        association. A copilot that writes that map into
        chat or into a ticket is creating a targeting aid.
        Tool calls that change setpoints follow
        <xref target="I-D.das-agentic"/> after this
        profile's receipt. Reconstruction for "explain this
        alarm" MUST NOT authorize "change this breaker."</t>
      </section>
      <section>
        <name>Public-Sector and National-Security Enterprise Seats</name>
        <t>Classification markings are not association control.
        Two SECRET fragments can still form a meaning nobody
        stored. Permitted Association Scope and destination
        binding matter more than the model's willingness to
        refuse. Cross-domain transfer is an Output Release
        Boundary with a jurisdiction epoch, analogous to
        overflight epoch in the NTN profile.</t>
      </section>
      <section>
        <name>Insurers and Claims-Triage Agents</name>
        <t>Policyholder identity and claim narrative join into
        fraud or health inference. A generative summary that
        names both is release. Sharing with a reinsurer or
        a body shop is a new destination and a new
        capability. Cumulative disclosure across a week's
        of "just one more similar claim" is a budget event.</t>
      </section>
      <section>
        <name>What Operators Should Measure</name>
        <t>The profile is live when: (1) the AI host cannot
        produce a joined identity-content record without a
        current Reconstruction Authorization Object; (2) every
        external send, render, or tool invoke of model output
        has a consumed capability_id and a receipt in the store;
        (3) destination or digest mismatch is a deny; (4) a
        poisoned session cannot be completed on another path.
        Those four tests distinguish this profile from "we put
        the model in a VPC."</t>
      </section>
    </section>

    <section anchor="featuremap">
      <name>Mapping Frontier Product Features to This Profile</name>
      <t>The following mapping is informative. It exists so a
      lab or enterprise architect can put objects on the
      product they already ship.</t>
      <section>
        <name>Connectors and MCP Servers</name>
        <t>Each connector is a vault-class interface, not a
        universal database handle. Mail identity headers and
        mail bodies SHOULD not share a mapping key the model
        host can reuse outside the RAO. An MCP tool list is
        discovery. Discovery MUST NOT issue reconstruction
        or release authority.</t>
      </section>
      <section>
        <name>Projects, Spaces, and Team Workspaces</name>
        <t>A project that mixes legal and engineering corpora
        is an association-scope decision at project create,
        not at send time only. Changing project membership
        MUST bump session or policy epoch so stale RAOs
        fail.</t>
      </section>
      <section>
        <name>Memory and Persistent Notes</name>
        <t>Memory is reconstructed meaning stored for later
        turns. A memory write MUST be a Candidate Output.
        Unscoped memory is how present theft becomes future
        mapping without another breach: the seat remembers
        the join the attacker asked for yesterday.</t>
      </section>
      <section>
        <name>Computer Use and Browser Agents</name>
        <t>A click-submit is an Output Release Boundary. The
        live digest is over the form values that will leave
        the machine, not over the model's narration of what
        it thinks it clicked. Origin change invalidates
        prior capability, same rule as the agentic profile's
        destination bind.</t>
      </section>
      <section>
        <name>Share Chat, Export, and API Log Sinks</name>
        <t>Transcript export, SIEM mirroring, and "share this
        conversation" are release paths. If they can carry
        a joined view, they MUST consume an Output Release
        Capability or they MUST only receive already-redacted
        non-joinable fragments.</t>
      </section>
    </section>

    <section anchor="json">
      <name>JSON Interoperability Profile</name>
      <section>
        <name>ReconstructionAuthorization</name>
        <sourcecode type="json"><![CDATA[
{
  "version": "1.0",
  "object_type": "reconstruction_authorization",
  "authorization_id": "rao-9c21",
  "session_id": "sess-441",
  "session_epoch": 17,
  "purpose_id": "ticket-triage",
  "field_set": ["ticket.summary", "customer.tier"],
  "association_scope": "customer-to-open-ticket",
  "execution_context": { "workload_id": "copilot-prod", "attestation": "ok" },
  "use_count": 1,
  "budgets": { "disclosure_remaining": 3, "inference_remaining": 1 },
  "reconstruction_domain_id": "prd-east-1"
}
]]></sourcecode>
      </section>
      <section>
        <name>Sealed Candidate Output and Receipt</name>
        <sourcecode type="json"><![CDATA[
{
  "version": "1.0",
  "object_type": "sealed_candidate_output",
  "candidate_output_id": "co-77ab",
  "session_id": "sess-441",
  "session_epoch": 17,
  "output_type": "REPORT",
  "output_digest": { "algorithm": "SHA-256", "value": "base64url-out" },
  "intended_boundary": "mail-gw-02",
  "sealed": true,
  "seal": { "type": "AES-GCM", "key_id": "ovs-key-4" }
}
]]></sourcecode>
        <sourcecode type="json"><![CDATA[
{
  "version": "1.0",
  "object_type": "protected_output_validation_receipt",
  "receipt_id": "povr-1204",
  "candidate_output_id": "co-77ab",
  "decision": "ALLOW",
  "committed_at": "2026-08-27T01:40:00Z",
  "binds": {
    "output_digest": "base64url-out",
    "destination": "internal-counsel",
    "recipient": "legal-box",
    "session_epoch": 17,
    "boundary_id": "mail-gw-02"
  }
}
]]></sourcecode>
      </section>
      <section>
        <name>Output Release Capability and Boundary Verify</name>
        <sourcecode type="json"><![CDATA[
{
  "version": "1.0",
  "object_type": "output_release_capability",
  "capability_id": "orc-55de",
  "receipt_id": "povr-1204",
  "candidate_output_id": "co-77ab",
  "output_digest": "base64url-out",
  "destination": "internal-counsel",
  "recipient": "legal-box",
  "session_id": "sess-441",
  "session_epoch": 17,
  "boundary_id": "mail-gw-02",
  "single_use": true,
  "expires_at": "2026-08-27T01:40:15Z"
}
]]></sourcecode>
        <sourcecode type="json"><![CDATA[
{
  "operation": "OutputBoundaryVerify",
  "decision": "DENY",
  "error": {
    "code": "EF_ASSOCIATION_SCOPE",
    "message": "Report joins customer identity to unreleased defect.",
    "retryable": false
  },
  "effectuation": { "permitted": false }
}
]]></sourcecode>
      </section>
      <section>
        <name>Vault-Local Release Receipt</name>
        <sourcecode type="json"><![CDATA[
{
  "version": "1.0",
  "object_type": "vault_local_release_receipt",
  "vault_id": "content-vault-7",
  "vault_class": "CONTENT",
  "session_id": "sess-441",
  "rao_id": "rao-9c21",
  "component_digest": "base64url-comp",
  "released_fields": ["ticket.summary"],
  "not_released": ["ticket.internal_root_cause"],
  "expires_at": "2026-08-27T01:41:00Z"
}
]]></sourcecode>
      </section>
    </section>

    <section anchor="workflow">
      <name>End-to-End Workflow</name>
      <t>A conforming transaction SHOULD implement the following
      stages. Stages may be collocated if the protected
      relationships remain: vaults do not join themselves,
      evidence is committed before capability exists, and the
      boundary is the only unsealing point.</t>
      <ol>
        <li>Request intake: purpose, tenant, destination,
        recipient, requested fields, requested association
        scope.</li>
        <li>Execution-context attestation of the workload,
        model or agent identity, and tool set.</li>
        <li>Reconstruction Authorization Object issued or
        denied by the Protected Authorization Domain.</li>
        <li>Vault-local release of session-bound components.
        Each vault applies its own conditions. No vault
        emits the association another vault owns.</li>
        <li>Association only inside the Protected
        Reconstruction Domain, producing an ephemeral
        minimum-necessary view.</li>
        <li>Restricted processing: the model sees the view,
        not the vaults.</li>
        <li>Candidate Output created in protected memory.</li>
        <li>Sealed Candidate Output before any untrusted
        buffer or gateway.</li>
        <li>Output Verification Stage: live policy, epoch,
        scope, destination, budgets, association-leak
        check.</li>
        <li>Protected Output Validation Receipt committed.</li>
        <li>Output Release Capability issued and bound.</li>
        <li>Optional reseal for the designated boundary.</li>
        <li>Boundary verification and single-use consume.</li>
        <li>Effectuation: send, render, store, or invoke.</li>
        <li>Session close or poison; components become
        unusable.</li>
      </ol>
      <t>A tool call generated at stage 7 is both a Candidate
      Output under this profile and a Candidate Act under
      <xref target="I-D.das-agentic"/>. Receipt commitment
      here is a precondition to dispatch-sink authority
      there when the tool would disclose or persist
      reconstructed meaning.</t>
    </section>

    <section anchor="exampletx">
      <name>Worked Transactions</name>
      <section>
        <name>Allow: Ticket Summary to Internal Counsel</name>
        <t>Purpose ticket-triage, field set ticket.summary plus
        customer.tier, association customer-to-open-ticket,
        destination internal-counsel, boundary mail-gw-02.
        Vaults release those fields only. Model drafts a
        summary that does not name unreleased defects. OVS
        passes. Receipt povr-1204 is committed. Capability
        orc-55de is consumed at mail-gw-02. Mail leaves
        once.</t>
      </section>
      <section>
        <name>Deny: Future-Map Report to External Destination</name>
        <t>Same seat, stolen or injected turn: "join our top
        accounts to unreleased defects and send the competitive
        report to this address." Relationship vault refuses
        customer-to-unreleased-defect association, or OVS
        detects the association in the Candidate Output.
        No receipt is committed. No capability is issued.
        Mail gateway has nothing to consume. The model may
        have written the report in sealed form. That is
        computation without consequence
        <xref target="DAS-ISOLATION"/>.</t>
      </section>
      <section>
        <name>Deny: Memory Persistence of a Prohibited Join</name>
        <t>The model tries to "remember" the customer-to-defect
        map for later turns. MEMORY_WRITE is a Candidate
        Output. Association scope fails. Memory store is an
        Output Release Boundary and receives no capability.
        Tomorrow's turn does not start already holding the
        map.</t>
      </section>
    </section>

    <section anchor="threats">
      <name>Enterprise-AI Threat Catalog</name>
      <t>A deployment SHOULD treat at least the following as
      in-scope. The model is not required to detect them.
      The property is that join or release remains
      non-completable.</t>
      <ul>
        <li>T1 Stolen enterprise seat or API key</li>
        <li>T2 Contractor or insider using a lawful seat
        off-purpose</li>
        <li>T3 Prompt injection in mail, ticket, or wiki</li>
        <li>T4 Poisoned retrieval or vector store</li>
        <li>T5 Connector / MCP server substitution</li>
        <li>T6 Tool-response laundering of instructions</li>
        <li>T7 Model or agent substitution</li>
        <li>T8 Cross-tenant retrieval</li>
        <li>T9 Cross-project association beyond scope</li>
        <li>T10 Mapping-table or foreign-key theft</li>
        <li>T11 Detokenize-then-join on the model host</li>
        <li>T12 Cumulative inference across turns (budget
        bypass)</li>
        <li>T13 Memory used as a durable join cache</li>
        <li>T14 Destination substitution after verification</li>
        <li>T15 Output substitution after sealing</li>
        <li>T16 Receipt rollback or capability replay</li>
        <li>T17 Share-chat / export / SIEM as covert egress</li>
        <li>T18 Computer-use form submit around the API
        sink</li>
        <li>T19 Multi-agent handoff that widens scope</li>
        <li>T20 Clean-room result copied to a laptop</li>
      </ul>
    </section>

    <section anchor="deploy">
      <name>Deployment Topologies</name>
      <t>Vaults MAY be separate HSMs, separate accounts, separate
      enclaves, or privilege-separated processes with distinct
      keys. Collocation on one host is allowed only where
      compromise of the model process does not yield
      relationship-mapping authority or unsealing keys.</t>
      <t>A hosted frontier lab MAY run the model in its cloud
      and still keep customer relationship-mapping and output
      unsealing in the customer's KMS or a customer-held
      enclave. That split is the commercial form of
      "isolation not intelligence" <xref target="DAS-ISOLATION"/>:
      the lab sells inference; the customer keeps join and
      release.</t>
      <t>Hot path: repeated turns inside a fixed RAO envelope
      (same tenant, purpose, field set, scope, destination
      class). Sink and boundary checks remain mandatory.
      Cold path: new destination, new project mix, financial
      or legal class, unknown connector, budget near
      exhaustion, attestation fail. Timeout is not release.</t>
    </section>

    <section anchor="operation">
      <name>Failure, Poison, and Alternate Paths</name>
      <t>Timeout, uncertain association, missing receipt, or
      faded vault MUST fail closed. A Partial Session MUST be
      poisoned so it cannot be completed with a new destination.
      Mail, chat, file sync, printer, browser download, tool
      dispatch, and memory write that can make the same output
      usable MUST enforce this profile or be unable to complete
      the effect.</t>
      <t>Illustrative codes: EF-RECONSTRUCTION_UNAUTHORIZED,
      EF-NON_JOINABLE, EF-OUTPUT_UNVERIFIED, EF-RECEIPT_MISSING,
      EF-OUTPUT_SUBSTITUTION, EF-DESTINATION_MISMATCH,
      EF-BOUNDARY_MISMATCH, EF-BUDGET_EXCEEDED,
      EF-SESSION_POISONED, EF-080 FAIL_CLOSED.</t>
    </section>

    <section anchor="interop">
      <name>Relationship to the Other DAS Profiles</name>
      <t>This document is the enterprise data-and-output profile.
      <xref target="I-D.das-agentic"/> is the tool-dispatch
      profile. A generated tool call that would disclose a
      reconstructed view MUST satisfy both: a receipt and
      output capability here, then act-bound dispatch
      authority there. Precision-bounded egress and NTN-RF
      profiles are sibling sinks for location and RF. They
      are not substitutes for vault non-joinability.</t>
    </section>

    <section anchor="security">
      <name>Security Considerations</name>
      <t>Threats the profile is intended to make
      non-completable without current authority include: AI-host
      compromise, credential union, mapping-table theft,
      unauthorized identity-content join, inferred strategy
      reconstruction, prompt-injection exfiltration, destination
      substitution, output substitution, receipt rollback,
      capability replay, clean-room result export, and
      alternate-path send.</t>
      <t>If the Output Release Boundary itself holds unrestricted
      plaintext and keys, assurance of that embodiment
      collapses. High-assurance deployments SHOULD keep
      unsealing keys off the AI host and SHOULD consider quorum
      or threshold capability issuance. A k-of-n capability
      for legal or financial class outputs is a deployment
      choice, not an optional skip of receipt commitment.</t>
      <t>Logging is not mediation. A SIEM copy of a joined view
      is itself a release unless the copy is digest-only or
      already redacted to non-joinable fragments. Prompt
      logging that retains retrieved identity plus retrieved
      content reconstructs the map for whoever holds the
      logs.</t>
      <t>Residual risk remains if an analog path — a screenshot
      tool, an unmodeled printer, a support engineer with
      break-glass plaintext — can emit the same meaning.
      Those paths MUST be inventoried as Output Release
      Boundaries or disabled for sessions that carry
      reconstructed views.</t>
    </section>

    <section anchor="privacy">
      <name>Privacy Considerations</name>
      <t>Reconstruction logs can themselves become a join map.
      Implementations SHOULD store vault-local receipts and
      output digests rather than raw joined views, and SHOULD
      treat Inference-Channel Budget exhaustion as a privacy
      event, not only a security event.</t>
    </section>

    <section anchor="iana">
      <name>IANA Considerations</name>
      <t>This document requests no IANA actions.</t>
    </section>

    <section anchor="ipr-note">
      <name>Intellectual Property Note</name>
      <t>Concepts in this profile are associated with DAS
      Protocols Part VII and International Application
      PCT/IB2026/055615. IETF disclosure should follow BCP 79
      <xref target="RFC8179"/>.</t>
    </section>

    <section anchor="conclusion">
      <name>Conclusion</name>
      <t>The AI server may compute. Vaults need not become a
      map in its memory. A map that is computed need not become
      a document the world can use. Join only under session-
      bound reconstruction. Seal the output. Commit the
      receipt. Consume the capability at the boundary.
      Compromise of computation is not reconstruction.
      Reconstruction is not release.</t>
    </section>
  </middle>
  <back>
    <references>
      <name>Normative References</name>
      <reference anchor="RFC2119" target="https://www.rfc-editor.org/info/rfc2119">
        <front>
          <title>Key words for use in RFCs to Indicate Requirement Levels</title>
          <author initials="S." surname="Bradner" fullname="S. Bradner"/>
          <date year="1997" month="March"/>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="2119"/>
      </reference>
      <reference anchor="RFC8174" target="https://www.rfc-editor.org/info/rfc8174">
        <front>
          <title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title>
          <author initials="B." surname="Leiba" fullname="B. Leiba"/>
          <date year="2017" month="May"/>
        </front>
        <seriesInfo name="BCP" value="14"/>
        <seriesInfo name="RFC" value="8174"/>
      </reference>
      <reference anchor="RFC8179" target="https://www.rfc-editor.org/info/rfc8179">
        <front>
          <title>Intellectual Property Rights in IETF Technology</title>
          <author initials="S." surname="Bradner" fullname="S. Bradner"/>
          <author initials="J." surname="Contreras" fullname="J. Contreras"/>
          <date year="2017" month="May"/>
        </front>
        <seriesInfo name="BCP" value="79"/>
        <seriesInfo name="RFC" value="8179"/>
      </reference>
    </references>
    <references>
      <name>Informative References</name>
      <reference anchor="I-D.das-6g-finality">
        <front>
          <title>Execution-Finality for AI-Native 5G/6G and O-RAN</title>
          <author fullname="Sangam Das" initials="S." surname="Das"/>
          <date year="2026" month="August"/>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-das-ai-native-6g-execution-finality-01"/>
      </reference>
      <reference anchor="I-D.das-agentic">
        <front>
          <title>Tool Selection Is Not Execution: Finality for Agentic Tool Dispatch</title>
          <author fullname="Sangam Das" initials="S." surname="Das"/>
          <date year="2026" month="August"/>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-das-agentic-execution-finality-01"/>
      </reference>
      <reference anchor="DAS-ISOLATION" target="https://doi.org/10.5281/zenodo.22082925">
        <front>
          <title>Why the Next AI War Will Be Won on Isolation, Not Intelligence</title>
          <author fullname="Sangam Das" initials="S." surname="Das"/>
          <date year="2026"/>
        </front>
        <seriesInfo name="DOI" value="10.5281/zenodo.22082925"/>
        <seriesInfo name="Zenodo" value="22082925"/>
      </reference>
    </references>
  </back>
</rfc>
