Skip to content

feat(observability): instrument identity, authorization, MCP, ACP/A2A, and provider access #114

Description

@robinbraemer

Outcome

Trace workload identity, authorization, Agentgateway enforcement, provider credential delivery, MCP/HTTP operations, ACP harness control, A2A delivery, and upstream outcomes through privacy-safe correlated operations.

Scope

  • Propagate W3C trace context through Mate, AgentOS authorizer, TokenReview, OpenFGA, agentgateway, provider adapter, upstream, A2A caller/target adapter, and supported ACP client/adapter boundaries.
  • Record bounded allow/deny reason, policy/model version, route class, capability class, protocol operation class, dependency status, and latency.
  • Correlate canonical Mate, Assignment, workload-plan, native-session, ACP-session, and A2A-operation IDs only in protected spans/logs, never metric labels.
  • Instrument MCP discovery/invocation and A2A discover/invoke/stream/cancel/artifact lifecycle without tool arguments, results, prompts, briefs, Inbox bodies, transcript chunks, or artifact content.
  • Instrument ACP session create/load/prompt/update/permission/cancel and adapter failure without plan text, tool payloads, terminal output, file bodies, or reasoning.
  • Preserve native gateway/harness spans where safe while removing unsafe/default attributes.
  • Keep protocol telemetry diagnostic: it never proves Inbox receipt, Assignment completion, authorization, or native-session state.

Acceptance criteria

  • One trace distinguishes identity, TokenReview, policy, credential, gateway, MCP/HTTP, ACP adapter/harness, A2A caller/target, and provider failures.
  • Revocation, profile reload, A2A fallback, and ACP adapter-recovery latency can be measured without polling or exporting content.
  • Denied requests never touch a credential adapter, A2A target, MCP server, or upstream provider.
  • Prompts, briefs, Inbox bodies, transcripts, plans, terminal/file/tool payloads, artifacts, headers, tokens, and provider resource IDs fail the export allowlist.
  • Protocol IDs remain protected trace/log attributes and never become metric dimensions.
  • Tracing loss cannot change authorization, protocol delivery, harness control, provider calls, or fallback behavior.

Dependencies

Coordinate with #122, especially #126, #128, #125, and #130.

References

Design record

docs/superpowers/specs/2026-07-31-resilient-delegation-access-effect-design.md

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions