Protocol Stack
Where AAP sits — and why it is a missing primitive.
Protocol Stack
End-to-End Flow
What Each Layer Does
| Layer | Protocol | Answers |
|---|---|---|
| Human identity | WebAuthn | Is this the right human/device? |
| App delegation | OAuth | Did the user authorize this app? |
| Agent runtime | AAP | Did this agent intend to do this, here, now? |
| Governance | Agent IAM | Is this allowed by policy? |
Agent IAM defines governance. AAP defines how agents prove runtime authority.