Guarded agent identifier.
OptionaldelegatedThe principal that delegated this execution, for agent-to-agent work.
Trusted invocation path, such as an HTTP start or approval resume.
OptionalprincipalStable principal identifier. Distinct from the audit event's actor.id,
which is the identity the gate evaluated: on an approval resume the actor
is the restored original principal while the decision belongs to a human
reviewer, and a correlated trail needs to name both.
OptionalprincipalWhich kind of principal is executing: human, service, agent, or system.
OptionalpurposeWhy an automated principal exists, as declared by the host.
OptionalresourceServer-derived memory resource identifier.
OptionalrunServer-minted run identifier.
OptionaltenantTenant identifier asserted by the authenticated host.
OptionalthreadServer-minted or tenant-owned thread identifier.
Trusted scalar correlation attached to agent authorization and policy events. Hosts must derive these values instead of accepting them from prompts, tool inputs, or other untrusted payloads.