Every agent framework is racing toward the same future: agents that call other agents. MCP servers, agent marketplaces, "agent-to-agent" protocols — the demos all show Agent A politely asking Agent B to do something and it just... working.
Here's the part nobody demos: Agent B has no idea who called it, what they were allowed to ask for, or how to prove what it actually did. Agent-to-agent calls today are unsigned strings over HTTP. That's not a protocol, that's a handshake deal.
I think the missing layer has three pieces, and I've been building it the hard way. Here's the honest breakdown.
1. Identity. When Agent A calls Agent B, who is A? Not a username — a verifiable key. Without caller identity, any agent can impersonate any other agent, and rate limits / billing / trust all collapse.
2. Authorization. A said "summarize this document." Did A authorize B to read the document, or also to email the summary to A's entire contact list? The call needs a declared scope, not vibes.
3. Audit. After the call, what happened? If B says "I completed the task" and A says "no you didn't," there's no referee. Both sides need a signed receipt of the actual action.
A manifest. Every agent publishes a machine-readable, signed manifest: what it can do, what it costs (credits, in our case), what actions require the owner's explicit approval, and the public key that signs its receipts. No manifest, no calls — like robots.txt but enforceable.
Roughly:
{
"agent": "news-desk-agent",
"version": "1.3.0",
"public_key": "ed25519:7f3a...",
"capabilities": ["daily_digest", "topic_research"],
"credit_cost": { "daily_digest": 10, "topic_research": 2 },
"requires_approval": ["publish", "external_post"],
"signature": "..."
}
A signed call envelope. Every inter-agent call carries the caller's identity, the declared intent, the scope, and a nonce — signed by the caller's key. The callee verifies the signature before doing any work, checks the scope against its manifest, and rejects anything out of scope. This is the boring part. It's also the part that makes the whole thing safe to leave running unattended.
A signed receipt. The callee writes what it actually did — action, inputs hash, result, credits consumed — into a ledger entry signed by its key. Both parties keep the receipt. If something goes wrong at 3am, you don't get "the agent said so." You get a verifiable record of every action, in order, signed by whoever took it.
I'm building this at Double-Oh, an agent platform, and I want to be straight about where things stand, because this space is full of vapor:
The order matters. Everyone wants to ship the cool part first (agents calling agents!) and bolt on accountability later. That never happens. Build the receipt layer first, and the protocol becomes a trust upgrade instead of a liability.
McKinsey puts agentic commerce at $3–5T by 2030. That economy runs on agents transacting with agents — buying, booking, negotiating. None of that works on unsigned handshakes. The agent economy needs receipts the way the web needed TLS: invisible, boring, and non-negotiable.
If you're building agent tooling, I'd love to hear how you're handling caller identity and action audit. I suspect most of us are hand-rolling the same half-solutions, and a shared manifest format would save everyone a year.