Back to F-ACT
Implementer guide

Adopt F-ACT

A practical guide for teams putting the standard to work. It takes you from reading the specification to a published, verifiable conformance claim — and it is free at every step that matters.

Read the specification

Start with the normative requirements. The specification is free to read, cite and implement — no login, no fee, no permission.

Open the standard

Map your controls

Work through the five dimensions and record how each is met today. The self-declaration checklist below is the working template.

Jump to the checklist

Self-declare in the registry

Publish a declared (L1) entry. This creates a public, dated record of what you attest — the entry point every higher tier builds on.

Go to the registry

Verify the record

Anyone can check a published entry against its signed record — no account required. Verification is the loop that makes a claim worth more than a logo.

Try verification

The conformance ladder

Conformance is a ladder, not a badge. Declare the tier you actually meet — a credible L1 is worth far more than an L3 you cannot stand behind.

L0Unattested

No conformance claim has been made. The agent may work perfectly well — but nothing about its authority, scope or audit trail has been declared, so nothing can be relied on by a third party.

L1Declared

The operator publishes a self-declaration mapping the agent to the five dimensions. This is a good-faith statement of record — free to make, and the fastest way to enter the public registry.

L2Enforced

The declared controls are demonstrably wired into the runtime: policy is checked before the agent acts, not merely described in a document. Enforcement is shown, not asserted.

L3Provable

Every material decision produces a tamper-evident record tying the action to a policy version and an accountable human. A third party can verify the record without trusting the operator.

The five dimensions you attest

Every conformance claim answers the same five questions about an agent. Together they spell the square the standard occupies.

A

Authority

Under whose authority does the agent act, and is that authority current?

S

Scope

What is the agent permitted to do — and, just as importantly, what is it not permitted to do?

D

Data

What data may the agent read, write or move, and where is it permitted to live?

A

Audit

Is every material action recorded in a way a third party can later inspect and trust?

R

Revocation

Can the authority be withdrawn quickly, and can anyone check whether it still stands?

Reading the normative language

The specification uses the key words MUST, MUST NOT, SHOULD, SHOULD NOT and MAY as defined in IETF RFC 2119. A MUST is a hard requirement for conformance; a SHOULD is a strong recommendation you may depart from with good reason; a MAY is genuinely optional. When you declare a tier, you are asserting that every MUST at that tier is met.

Self-declaration checklist

The minimum you should be able to answer before you publish a declared entry. If a line is not yet true, declare the tier below it rather than rounding up.

  • Named, current human sponsor recorded for the agent (Authority).
  • Explicit allow-list and deny-list of actions documented (Scope).
  • Data the agent may read, write or move — and its permitted residency — stated (Data).
  • Material actions written to a durable, inspectable record (Audit).
  • A defined, fast path to withdraw authority, checkable by a third party (Revocation).
  • Each claim mapped to the tier it actually meets — no rounding up (L0 to L3).
  • A named contact who stands behind the declaration.

Using the name in your claim

You may state that a system conforms to F-ACT, and cite the specification, without asking anyone for permission — that is the whole point of an open standard. The name is a trademark so that it keeps identifying the authentic standard; the trademark notice sets out how to refer to it fairly.

Ready to declare?

Publish your first entry, or read how governance and change control work.