Conformance Levels
| Level | Requirements |
|---|---|
| AARM Core | R1–R5 (all MUST) |
| AARM Extended | R1–R8 (all MUST + SHOULD) |
Required (MUST)
R1: In-Line Authorization
Block actions before execution based on policy.R2: Parameter Validation
Validate parameters against constraints.R3: Step-Up Authorization
Support human approval workflows.R4: Tamper-Evident Receipts
Generate signed receipts for all actions.R5: Identity Binding
Bind actions to a non-forgeable requester context.Recommended (SHOULD)
R6: Least Privilege
Support credential scoping.R7: Telemetry Export
Export to security platforms.R8: Effect Capture
Record downstream state changes.Summary Table
| ID | Level | Requirement |
|---|---|---|
| R1 | MUST | Block before execution |
| R2 | MUST | Parameter validation |
| R3 | MUST | Human approval workflows |
| R4 | MUST | Signed receipts |
| R5 | MUST | Identity binding |
| R6 | SHOULD | Least privilege |
| R7 | SHOULD | Telemetry export |
| R8 | SHOULD | Effect capture |