# EMILIA Protocol > EMILIA is the authority control plane for autonomous work. A human or institution defines a finite operating mandate once; agents work unattended inside it; EMILIA Gate enforces each consequential unit of work on protected executor paths. Gate accepts native mandates and credentials from A2A, AP2, OAuth, and hardware-backed approval systems, then enforces them once at the executor. Gate verifies the authority and evidence the owner requires for the exact action, consumes accepted authority before provider entry, preserves executed or indeterminate outcomes, refuses blind replay, and treats any remedy as a new authorized action rather than rewritten history. EMILIA Protocol is the open verification and evidence substrate underneath it; EMILIA Approver captures device-bound exact-action human decisions when the mandate or local policy requires fresh human authority; EMILIA Assurance Plane provides scoped verification, re-performance, conformance reports, and deployment evidence without acting as an auditor or accredited certifier. This is a generated discovery index following the llms.txt proposal. Evidence snapshot: 2026-08-13T07:33:10.084Z. For substantive analysis, load the full or machine-readable context below before drawing conclusions from individual repository files. Prevention boundary: Gate prevents only on action paths under complete mediation. It does not constrain a path that bypasses the deployed enforcement point. ## Engineering Evidence EMILIA is implemented security infrastructure, not architecture-only: 8,865 automated tests across 533 files; 35 executable security claims over 259 hashed evidence files; 20 verified obligations across 2 composed Tamarin models, with 8 deliberately weakened variants producing concrete attack traces; and 78 content-addressed selected model/runtime scenarios across 14 bounded models and 21 claims, including 51 paired formal-counterexample/runtime-refusal controls. Interoperability evidence: 21 conformance suites and 331 current vectors across three same-team ports; external Rust evidence covers a time-pinned 164-vector set plus 359 hostility cases. Strict clean-room construction acceptance remains false. ## Canonical Context - [Full LLM context](https://www.emiliaprotocol.ai/llms-full.txt): Definitions, layer map, current evidence, non-claims, source precedence, standards, and code entry points. - [Machine-readable repository context](https://www.emiliaprotocol.ai/.well-known/emilia-context.json): EMILIA-REPO-CONTEXT-v1 with input hashes, evidence counts, security claims, assumptions, and freshness metadata. - [Canonical four-document reading path](https://www.emiliaprotocol.ai/llms-full.txt#canonical-four-document-reading-path): Authorization Receipts -> Human Authorization Binding -> Authority Introduction -> Authorization Evidence Chain. - [Standards Observatory](https://www.emiliaprotocol.ai/observatory): Revision-aware guarantee map, standards movement, and open interoperability frontiers. - [Machine-readable standards snapshot](https://www.emiliaprotocol.ai/.well-known/standards-observatory.json): Source locks, operative-status rationale, exact quotes, and the correlated-recon boundary. - [Repository AI context](https://github.com/emiliaprotocol/emilia-protocol/blob/main/AI_CONTEXT.md): The same generated context beside the source code. ## Specifications - [draft-schrock-ae-challenge](https://datatracker.ietf.org/doc/draft-schrock-ae-challenge/): Machine-readable, action-bound request for missing authorization evidence; the challenge authorizes nothing; snapshot revision -06, check Datatracker for current status. - [draft-schrock-action-evidence-boundary](https://datatracker.ietf.org/doc/draft-schrock-action-evidence-boundary/): Boundary contract joining independently verified evidence to one material action, reserving authority before invocation, and preserving indeterminate outcomes for authenticated reconciliation; snapshot revision -03, check Datatracker for current status. - [draft-schrock-action-remedy-receipts](https://datatracker.ietf.org/doc/draft-schrock-action-remedy-receipts/): Dispute, decision, and fresh CAID-bound compensating-action evidence without rewriting the original effect; snapshot revision -00, check Datatracker for current status. - [draft-schrock-agent-qualification-statements](https://datatracker.ietf.org/doc/draft-schrock-agent-qualification-statements/): Task- and policy-bounded qualification evidence that never authorizes by itself; snapshot revision -00, check Datatracker for current status. - [draft-schrock-canonical-action-identifier](https://datatracker.ietf.org/doc/draft-schrock-canonical-action-identifier/): Typed material-action identity and profile-bounded cross-format matching; snapshot revision -02, check Datatracker for current status. - [draft-schrock-emilia-eye](https://datatracker.ietf.org/doc/draft-schrock-emilia-eye/): Scope-bound advisory that can tighten but never authorize; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-architecture](https://datatracker.ietf.org/doc/draft-schrock-ep-architecture/): Portfolio architecture; snapshot revision -02, check Datatracker for current status. - [draft-schrock-ep-authority-introduction](https://datatracker.ietf.org/doc/draft-schrock-ep-authority-introduction/): Authority introduction and trust-root boundary; snapshot revision -03, check Datatracker for current status. - [draft-schrock-ep-authorization-evidence-chain](https://datatracker.ietf.org/doc/draft-schrock-ep-authorization-evidence-chain/): Heterogeneous evidence composition; snapshot revision -05, check Datatracker for current status. - [draft-schrock-ep-authorization-receipts](https://datatracker.ietf.org/doc/draft-schrock-ep-authorization-receipts/): One action-bound organizational approval evidence profile; snapshot revision -11, check Datatracker for current status. - [draft-schrock-ep-bounded-capability-receipts](https://datatracker.ietf.org/doc/draft-schrock-ep-bounded-capability-receipts/): Action-bound capability budget and spend evidence; snapshot revision -04, check Datatracker for current status. - [draft-schrock-ep-bounded-execution-program](https://datatracker.ietf.org/doc/draft-schrock-ep-bounded-execution-program/): Reachability-, occurrence-, concurrency-, and budget-bounded runtime program for consequential action admission; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-evidence-record](https://datatracker.ietf.org/doc/draft-schrock-ep-evidence-record/): Long-term crypto-agile evidence preservation; snapshot revision -01, check Datatracker for current status. - [draft-schrock-ep-outcome-binding](https://datatracker.ietf.org/doc/draft-schrock-ep-outcome-binding/): Source-routed predicted effects and independently pinned post-execution observations; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-presentation-binding](https://datatracker.ietf.org/doc/draft-schrock-ep-presentation-binding/): Binding the signed action to what the approver was shown; snapshot revision -00, check Datatracker for current status. - [draft-schrock-ep-quorum](https://datatracker.ietf.org/doc/draft-schrock-ep-quorum/): Distinct-human multi-handshake composition; snapshot revision -03, check Datatracker for current status. - [draft-schrock-ep-revocation-statement](https://datatracker.ietf.org/doc/draft-schrock-ep-revocation-statement/): Signed retraction of authority without rewriting an already executed effect; snapshot revision -01, check Datatracker for current status. - [draft-schrock-ep-reliance-agreement](https://datatracker.ietf.org/doc/draft-schrock-ep-reliance-agreement/): Signed technical terms that bind reliance-program identifiers, versions, digests, parties, and acceptance conditions without creating legal enforceability or insurance; snapshot revision -00, check Datatracker for current status. - [draft-schrock-human-authorization-binding](https://datatracker.ietf.org/doc/draft-schrock-human-authorization-binding/): Binding a human-authorization artifact into adjacent host formats; snapshot revision -00, check Datatracker for current status. - [draft-schrock-model-to-matter](https://datatracker.ietf.org/doc/draft-schrock-model-to-matter/): Experimental executor-side authorization-evidence clearance for model-directed physical execution; snapshot revision -04, check Datatracker for current status. - [draft-ferro-schrock-memory-projection-record](https://datatracker.ietf.org/doc/draft-ferro-schrock-memory-projection-record/): Signed record of exact context bytes projected by a memory adapter, with explicit nonclaims; snapshot revision -01, check Datatracker for current status. - [draft-mih-sato-agent-accountability-composition](https://datatracker.ietf.org/doc/draft-mih-sato-agent-accountability-composition/): Coauthored composition perspective; snapshot revision -00, check Datatracker for current status. - [draft-dunbar-dmsc-gw-scenarios-gap-analysis](https://datatracker.ietf.org/doc/draft-dunbar-dmsc-gw-scenarios-gap-analysis/): Coauthored Agent Gateway deployment and exact-action authorization gap analysis; snapshot revision -03, check Datatracker for current status. ## Evidence - [Conformance manifest](https://github.com/emiliaprotocol/emilia-protocol/blob/main/conformance/conformance-manifest.json): Current suite/vector counts and same-team implementation relationship. - [Machine-verifiable security case](https://github.com/emiliaprotocol/emilia-protocol/blob/main/security/security-case.json): Executed claims with exact evidence, assumptions, exclusions, and artifact hashes. - [Engineering evidence map](https://www.emiliaprotocol.ai/proof): Plain-language map from guarantees and attacks to formal, executable, conformance, and external evidence. - [External implementation pin](https://github.com/emiliaprotocol/emilia-protocol/blob/main/conformance/external/rust-cleanroom-jdieselny.v1.json): Time-pinned Rust source, vector scope, hostility corpus, and construction-attestation status. ## Start Here - [Repository](https://github.com/emiliaprotocol/emilia-protocol): Apache-2.0 source, tests, formal models, and examples. - [Quickstart](https://www.emiliaprotocol.ai/quickstart): Integrate an enforcement wrapper. - [Verify](https://www.emiliaprotocol.ai/verify): Verify a receipt in the browser. - [Model-to-Matter](https://www.emiliaprotocol.ai/model-to-matter): Executor-side clearance for model-directed physical actions. ## Optional - [Neutrality Covenant](https://github.com/emiliaprotocol/emilia-protocol/blob/main/docs/NEUTRALITY-COVENANT.md): Open verifier, format, and conformance commitments. - [Threat Model](https://github.com/emiliaprotocol/emilia-protocol/blob/main/THREAT_MODEL.md): Explicit deployment and trust assumptions.