Rosetta Protocol 3.0.0 / Core 1.0 Standards Candidate

Safety control and evidence for autonomous AI agents.

Rosetta is an open, protocol-independent control plane for consequential agent actions. It binds structured intent, independently observed action requests, independent authorization, policy decisions, enforcement, and observed effects into verifiable safety transactions.

Research standards candidate and reference implementation. Not a production certification.

THE CORE LIFECYCLE

Rosetta Core lifecycle

  1. 01IntentStructured manifest
  2. 02ObserveIndependent request
  3. 03AuthorizeExact grant binding
  4. 04DecidePolicy at enforcement
  5. 05EnforcePre-effect control
  6. 06ReceiptObserved effect evidence
SYSTEM VIEW

Rosetta Core across independently administered principals.

Host protocols stay in place. Rosetta adds request-bound authorization, local deterministic policy, enforcement, and effect evidence at each mediated boundary.

Rosetta Core experimental architecture. Host protocols remain in place while Rosetta adds bounded safety semantics at mediated boundaries. Open full-size SVG โ†—
ARCHITECTURE

A small core with optional safety layers.

Rosetta separates authority from model-generated content. Probabilistic detection can tighten controls, but it cannot create authority.

ENFORCEMENT

Rosetta Guard

Reference policy-enforcement runtime and gateways that perform pre-forward evaluation and attach lifecycle receipts.

ADAPTATION

Rosetta Reflex

Optional bounded adaptive control with regimes, hysteresis, dwell, and verification-budget allocation.

DETECTION

Rosetta Detect

Optional LECR, trajectory, semantic, and coordination detectors. Detection evidence may tighten controls but never expand authority.

INTEROPERABILITY

Complements MCP and A2A. Does not replace them.

Protocol adapters carry Rosetta intent and receipt references through additive, namespaced metadata while the Core remains transport neutral.

MCP A2A SPIFFE OAuth RAR OPA CloudEvents OpenTelemetry in-toto style attestations
RELEASE EVIDENCE

Inspectable implementation, conformance, and verification.

Open verification report โ†—
326tests passed0 failed, 0 skipped
12/12conformance vectorsnormative vectors passed
85.55%branch-aware coverageagainst an 85% gate
5,000measured lifecyclesAPI-free evidence benchmark

Benchmarks are single-process Python reference measurements and exclude network transit, external policy decision points, durable remote storage, and model-verifier latency. See the repository for methodology, artifacts, manifests, residual risks, and scope.

ARCHIVE & CITATION

A versioned public release with a persistent DOI.

The source repository is the living technical implementation. The tagged GitHub release identifies version 3.0.0. Zenodo provides the persistent archival and citation record.

SOFTWARE CITATION

Behzadi, David. Rosetta Protocol 3.0.0 - Core 1.0 Standards Candidate. Version 3.0.0, 2026. DOI: 10.5281/zenodo.21740730.

10.5281/zenodo.21740730
SCOPE

Explicit boundaries, not universal claims.

Rosetta 3.0 is a research standards candidate and reference implementation. It does not claim universal covert-channel detection, full MCP/A2A server conformance, control over non-cooperating remote principals, or suitability for regulated deployment without independent security review and a domain-specific policy profile.