Evaluate · Conformance

Make the implementation
verifiable.

A useful conformance claim names its scope, shows its evidence and states its limits.

3 levels611 test vectorsDraft-01.1

Choose a conformance level

Each level includes everything in the one before it.

Level 01

Core

Agent identifiers, the envelope, EdDSA signing, authorization, discovery and JWKS, the HTTP/2 binding, routing, idempotency and errors.

Level 02

Compliance

Core, plus compliance fields and profiles, the audit trail, human oversight and broker routing.

Level 03

Full

Compliance, plus all five primitives, the WebSocket binding, payload encryption and ES256.

These summaries are a starting point. The conformance section of ARSIA-Core lists the complete requirements for each level.

Know which layer is responsible

ConcernProtocol and SDKApplication and operator
Message structureSchema and semantic rulesReject invalid incoming messages
IdentitySignature format and verificationTrust provisioning, key storage, revocation
AuthorizationCapability requirementsIssue grants and enforce permissions
Human oversightApproval messages and lifecyclePause execution, authenticate reviewers
AuditRecord format and retention fieldsDurable storage, retention, external evidence
Data residencyDeclarations and routing requirementsWhere the deployment actually runs

Make a claim reproducible

Record the specification revision, the implementation version, the conformance level, the commands you ran and their results. Keep schema checks separate from runtime and integration checks.

State the limits alongside the result

Schema validation is one layer

Temporal rules, cross-message behaviour, authorization context and deployment properties need checks beyond JSON Schema.

A valid signature is not trust

Verification proves a message matches a key. Whether that key belongs to a trusted agent depends on how keys are provisioned, resolved and revoked.

Audit integrity depends on the evidence model

Records produced by the protocol describe what happened. Protection against deletion or rewriting depends on how and where they are stored.

Residency is declared, then deployed

A data_residency declaration states a requirement. Showing that it is met needs evidence about the infrastructure that processed the message.

Esc