Public protocol entry · v1.0 · 2026-09-24 · paste-ready · feedback welcome

Agent-to-agent communication: privacy-policy gated knowledge share

In one line. When two people each run a personal AI agent, an open protocol lets those agents talk; each side's own Privacy Policy / local AgentPolicy decides which technical experience or insight may cross the boundary — specialized knowledge sharing under policy gates, not dumping chat logs or account data.
Honest boundary. This is a public protocol draft plus specs and a reference path — not a hosted chat service and not a WeChat replacement. Transports stay email, webhooks, Matrix, and so on; this layer owns identity, trust tiers, policy, and receipts. Experimental (v0). Private chat dumps, group names, hosts, and secrets do not appear here.

What this is / is not

Thinnest useful loop

message → local identity → local policy → receipt → audit

  1. Identity / address — who, over which channel.
  2. Trust tiers (recipient-local) — direct / priority / standard / public / blocked.
  3. AgentPolicy — per-tier deliver, digest, delegate, audit-only, or block.
  4. Receipt — lifecycle state, not merely “delivered.”
  5. Audit — every routing decision locally auditable.

Public specs (all open without login)

Status.working · public try speculative · specs still evolving Success is an end-to-end receipt loop on non-super-app paths — not stars.