The proliferation of agentic AI systems across diverse runtimes, from local coding hooks to complex API gateways, creates a fundamental governance challenge. Incompatible runtime records for seemingly identical actions like publishing code or transferring funds obscure the true approved action, its evidentiary link to execution, and the possibility of independent reproduction.

Standardizing Agent Actions for Trustworthy Governance

This paper introduces Canonical Action Verification and Attestation (CAVA), a novel runtime-semantics layer designed to translate the cacophony of heterogeneous agent activity into stable, canonical runtime action objects. CAVA operates beneath higher-level governance frameworks like Proof-Carrying Agent Actions (PCAA), providing the essential stable action object that such processes govern. The work formalizes critical concepts including canonical action identity, semantic pattern detection for identifying nuanced behaviors, robust approval binding mechanisms, receipt integrity, and runtime-portable projections, with optional attestation substrates.