A practical guide for teams putting the standard to work. It takes you from reading the specification to a published, verifiable conformance claim — and it is free at every step that matters.
Start with the normative requirements. The specification is free to read, cite and implement — no login, no fee, no permission.
Open the standardWork through the five dimensions and record how each is met today. The self-declaration checklist below is the working template.
Jump to the checklistPublish a declared (L1) entry. This creates a public, dated record of what you attest — the entry point every higher tier builds on.
Go to the registryAnyone can check a published entry against its signed record — no account required. Verification is the loop that makes a claim worth more than a logo.
Try verificationConformance is a ladder, not a badge. Declare the tier you actually meet — a credible L1 is worth far more than an L3 you cannot stand behind.
No conformance claim has been made. The agent may work perfectly well — but nothing about its authority, scope or audit trail has been declared, so nothing can be relied on by a third party.
The operator publishes a self-declaration mapping the agent to the five dimensions. This is a good-faith statement of record — free to make, and the fastest way to enter the public registry.
The declared controls are demonstrably wired into the runtime: policy is checked before the agent acts, not merely described in a document. Enforcement is shown, not asserted.
Every material decision produces a tamper-evident record tying the action to a policy version and an accountable human. A third party can verify the record without trusting the operator.
Every conformance claim answers the same five questions about an agent. Together they spell the square the standard occupies.
Under whose authority does the agent act, and is that authority current?
What is the agent permitted to do — and, just as importantly, what is it not permitted to do?
What data may the agent read, write or move, and where is it permitted to live?
Is every material action recorded in a way a third party can later inspect and trust?
Can the authority be withdrawn quickly, and can anyone check whether it still stands?
The specification uses the key words MUST, MUST NOT, SHOULD, SHOULD NOT and MAY as defined in IETF RFC 2119. A MUST is a hard requirement for conformance; a SHOULD is a strong recommendation you may depart from with good reason; a MAY is genuinely optional. When you declare a tier, you are asserting that every MUST at that tier is met.
The minimum you should be able to answer before you publish a declared entry. If a line is not yet true, declare the tier below it rather than rounding up.
You may state that a system conforms to F-ACT, and cite the specification, without asking anyone for permission — that is the whole point of an open standard. The name is a trademark so that it keeps identifying the authentic standard; the trademark notice sets out how to refer to it fairly.
Publish your first entry, or read how governance and change control work.