Choose a conformance level
Each level includes everything in the one before it.
Core
Agent identifiers, the envelope, EdDSA signing, authorization, discovery and JWKS, the HTTP/2 binding, routing, idempotency and errors.
Compliance
Core, plus compliance fields and profiles, the audit trail, human oversight and broker routing.
Full
Compliance, plus all five primitives, the WebSocket binding, payload encryption and ES256.
These summaries are a starting point. The conformance section of ARSIA-Core lists the complete requirements for each level.
Know which layer is responsible
| Concern | Protocol and SDK | Application and operator |
|---|---|---|
| Message structure | Schema and semantic rules | Reject invalid incoming messages |
| Identity | Signature format and verification | Trust provisioning, key storage, revocation |
| Authorization | Capability requirements | Issue grants and enforce permissions |
| Human oversight | Approval messages and lifecycle | Pause execution, authenticate reviewers |
| Audit | Record format and retention fields | Durable storage, retention, external evidence |
| Data residency | Declarations and routing requirements | Where the deployment actually runs |
Make a claim reproducible
Record the specification revision, the implementation version, the conformance level, the commands you ran and their results. Keep schema checks separate from runtime and integration checks.
State the limits alongside the result
Schema validation is one layer
Temporal rules, cross-message behaviour, authorization context and deployment properties need checks beyond JSON Schema.
A valid signature is not trust
Verification proves a message matches a key. Whether that key belongs to a trusted agent depends on how keys are provisioned, resolved and revoked.
Audit integrity depends on the evidence model
Records produced by the protocol describe what happened. Protection against deletion or rewriting depends on how and where they are stored.
Residency is declared, then deployed
A data_residency declaration states a requirement. Showing that it is met needs evidence about the infrastructure that processed the message.