Mandato: Protocol for Verifiable AI Agent Authorization and Audit Trails

Giovanni Racioppi· August 17, 2026 View original

Key takeaways

  • Mandato provides protocol-level enforcement of digitally signed authorizations for AI agent actions.
  • It creates cryptographically chained audit trails with evidentiary value for compliance and accountability.
  • The mandate model is designed to be legible to legal and auditing professionals.
  • This framework addresses critical gaps in verifiable authorization and auditability for AI agents.

Who benefits

BFSIHealthcareLegalGovernmentCybersecurity

Summary

Mandato introduces a governance proxy that enforces digitally signed mandates on AI agent actions at the protocol level, ensuring verifiable authorization and creating cryptographically chained audit logs for evidentiary use.

As AI agents increasingly interact with external systems via tool-calling protocols, a critical gap exists in ensuring their actions are verifiably authorized by a principal. Current authorization logic often resides within application code, lacking digital signatures or independent auditability, which diminishes the evidentiary value of logs. Mandato proposes a novel governance proxy designed to enforce digitally signed mandates directly at the protocol level for AI agent actions. A mandate is a machine-readable, cryptographically signed artifact that specifies permissible tools, parameter constraints, contextual conditions, duration, and the authorizing entity. The proxy evaluates every tool call against this mandate chain, blocking unauthorized actions and recording all decisions—permits, denials, and their supporting evidence—in an append-only, hash-chained audit log. This log is periodically anchored with qualified timestamps, making it suitable for evidentiary purposes. The mandate model is intentionally structured to align with civil-law concepts of delegated authority, making it comprehensible to legal and auditing professionals, not just engineers. The paper details the mandate model, decision semantics, a reference architecture, and maps its mechanisms to key regulations like the EU AI Act, GDPR, NIS2, and eIDAS 2, outlining a path towards qualified attestation via Qualified Trust Service Providers.

Why it matters

Professionals deploying AI agents in regulated or high-stakes environments need robust mechanisms for accountability, compliance, and verifiable authorization to mitigate risks and meet legal requirements. Mandato offers a foundational solution for this.

How to implement this in your domain

  1. 1Assess current AI agent deployments for authorization and audit trail gaps, especially in sensitive operations.
  2. 2Investigate Mandato's open-source implementation or similar protocol-level governance proxies for integration.
  3. 3Define machine-readable mandates for AI agent actions, specifying tool access, parameters, and conditions.
  4. 4Implement cryptographic signing for mandates and ensure secure storage and management of keys.
  5. 5Establish processes for regularly reviewing and anchoring audit logs to meet compliance and evidentiary standards.

Original post by Giovanni Racioppi

"arXiv:2608.14074v1 Announce Type: new Abstract: AI agents increasingly act on external systems through standardized tool-calling protocols such as the Model Context Protocol (MCP), yet no infrastructure layer constrains their actions to what a principal has verifiably authorized:…"

View on X

Originally posted by Giovanni Racioppi on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses