Protocol Stack

Where AAP sits — and why it is a missing primitive.

Protocol Stack

End-to-End Flow

What Each Layer Does

LayerProtocolAnswers
Human identityWebAuthnIs this the right human/device?
App delegationOAuthDid the user authorize this app?
Agent runtimeAAPDid this agent intend to do this, here, now?
GovernanceAgent IAMIs this allowed by policy?

Agent IAM defines governance. AAP defines how agents prove runtime authority.