<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mission-Bound OAuth MVP on Control Plane by Karl McGuinness</title><link>https://notes.karlmcguinness.com/series/mission-bound-oauth-mvp/</link><description>Recent content in Mission-Bound OAuth MVP on Control Plane by Karl McGuinness</description><generator>Hugo</generator><language>en-us</language><managingEditor>public@karlmcguinness.com (Karl McGuinness)</managingEditor><webMaster>public@karlmcguinness.com (Karl McGuinness)</webMaster><lastBuildDate>Mon, 01 Jun 2026 18:00:00 -0700</lastBuildDate><atom:link href="https://notes.karlmcguinness.com/series/mission-bound-oauth-mvp/index.xml" rel="self" type="application/rss+xml"/><item><title>The Mission is the Missing OAuth Abstraction for Agents</title><link>https://notes.karlmcguinness.com/notes/the-mission-is-the-missing-oauth-abstraction/</link><pubDate>Mon, 01 Jun 2026 18:00:00 -0700</pubDate><author>public@karlmcguinness.com (Karl McGuinness)</author><guid>https://notes.karlmcguinness.com/notes/the-mission-is-the-missing-oauth-abstraction/</guid><description>Five bodies of work converge on the same structural gap in OAuth for agents: the protocol has no durable object for the task the user approved. The Mission is that object. Part 1 frames the gap and introduces the two-layer spec proposal that closes it. The MVP and Runtime Enforcement Profile follow in Parts 2 and 3.</description></item><item><title>Mission-Bound OAuth Runtime Enforcement Profile</title><link>https://notes.karlmcguinness.com/notes/mission-bound-oauth-runtime-enforcement-profile/</link><pubDate>Mon, 01 Jun 2026 09:00:00 -0700</pubDate><author>public@karlmcguinness.com (Karl McGuinness)</author><guid>https://notes.karlmcguinness.com/notes/mission-bound-oauth-runtime-enforcement-profile/</guid><description>The MVP binds OAuth tokens to a durable Mission record. This profile adds the runtime layer: AS-side intent-to-policy compilation, mandatory escalation via AuthZEN, tool-and-action binding, mandatory actor chains, per-decision audit receipts, and a governed purpose registry. Modular by design: a Core enforcement contract plus Optional Modules that deployments adopt as their governance posture requires.</description></item><item><title>Mission-Bound OAuth MVP</title><link>https://notes.karlmcguinness.com/notes/mission-bound-oauth-mvp/</link><pubDate>Fri, 22 May 2026 14:00:00 -0700</pubDate><author>public@karlmcguinness.com (Karl McGuinness)</author><guid>https://notes.karlmcguinness.com/notes/mission-bound-oauth-mvp/</guid><description>The MVP adds five protocol surfaces on top of existing OAuth: a mission_intent RAR envelope, a resource_access RAR type, a Mission record at the AS, a mission claim on access tokens, and Mission-state enforcement across every derivation path. The result is durable task authority that survives token lifetimes, cross-AS fan-out, runtime escalation, and business-event termination.</description></item></channel></rss>