Assessment deployment architecture¶
AIT occupies one explicit application boundary. The sender is configured to use an AIT listener or wrapper, AIT forwards to the unchanged receiver, and the control plane remains local to the researcher's machine. This is a placement decision, not transparent interception.
The researcher controls the route into AIT and the upstream configuration. The sender and receiver remain the systems selected for the assessment. A transcript establishes delivery; receiver state or another authorized observation source establishes what followed.
Placement by transport¶
| Communication | Explicit placement | Boundary controlled |
|---|---|---|
| A2A JSON-RPC or REST | Replace the receiver URL with the AIT HTTP or HTTPS listener | Complete request and response envelopes |
| A2A gRPC | Replace the service endpoint with the A2A-specific bridge | Supported A2A service messages, not arbitrary gRPC |
| MCP Streamable HTTP | Replace the MCP origin with the AIT listener | Initialization, requests, responses, notifications, and SSE events |
| MCP stdio | Replace the server command with the wrapper AIT prints | Framed stdin and stdout messages without a shell |
| SSE or WebSocket | Replace the stream origin with the explicit relay | Complete events or messages, including release order and replay |
If the sender cannot be configured to use the listener or wrapper, AIT cannot occupy that hop. It does not change DNS, poison name resolution, install a trust root, or redirect network traffic.
Trust and credential locations¶
| Location | Material present | Research implication |
|---|---|---|
| Sender | Its normal target configuration and any credential it normally sends | Repointing the sender is the authorized placement step |
| AIT data plane | Raw message envelopes, including credentials carried by the selected exchange | Raw captures are sensitive; the operator can see what the protocol carries |
| AIT control plane | Connection references, decisions, and local authorization token | It stays on loopback even when the data plane binds a routable address |
| Receiver | Its own TLS identity, policy, storage, and action credentials | AIT does not need receiver code execution or model access |
| Evidence source | The minimum authorized state needed to judge the effect | It must not be inferred from the transcript or receiver narration alone |
Credential values belong in environment-backed or connection references where the platform accepts them. A raw transcript necessarily retains values that cross the selected boundary. Export redacted evidence by default and keep raw records on an encrypted operator volume.
TLS boundaries¶
There are two independent TLS questions:
- What does the sender trust? If it requires HTTPS, supply a listener certificate whose SAN names the address the sender dials.
- What does AIT trust upstream? Use system roots, add a private CA, or configure mTLS client material on the connection.
AIT does not mint a trusted interception certificate. Supplying
insecure_skip_verify changes the security property of the assessment path and
must be recorded as a deliberate exception, not treated as equivalent to a
private CA.
Evidence maturity by path¶
Implementation support and external validity are different claims.
| Path | Repository-backed evidence | Limit |
|---|---|---|
| A2A JSON-RPC and REST | Complete-frame adapter tests and process-backed controlled labs | A lab result does not describe an external coordinator |
| A2A gRPC | Protocol-specific bridge and transport tests | Not a general gRPC proxy |
| MCP Streamable HTTP | Adapter and controlled-lab coverage | Target behavior still needs a target-owned observation |
| MCP stdio | Packaged wrapper acceptance against a third-party server | One server does not establish ecosystem-wide compatibility |
| Remote listener plus TLS | Automated placement rehearsal and a two-host field procedure | Network policy and certificate trust remain environment-specific |
| Framework-mediated traffic | A framework can be placed only where it emits a supported boundary | Installing or importing a framework is not execution evidence |
When a row lacks a named test or retained field record, treat the path as unverified for the current checkout.
Field procedure¶
- Record the exact sender, receiver, protocol binding, locator, and authorized effect before starting a listener.
- Name what must never happen, such as a real payment, message, deletion, or cross-tenant access.
- Prepare the connection without contact and inspect the routing change.
- Confirm control-plane loopback binding and the exact data-plane interface.
- Validate certificate names, upstream trust, and credential references.
- Start with interception off and send one low-risk operation unchanged.
- Confirm that the inert path preserves framing, streaming, timing, and target behavior.
- Reset target state and take the oracle baseline.
- Run one bounded attack arm and one close control against the same target state and topology.
- Read sender bytes, delivered bytes, receiver state, and effect evidence as separate records.
- Export redacted evidence, resolve pending messages, stop every owned process, and verify cleanup.
Cancellation and recovery¶
A paused message holds a real connection. Set a pending timeout and an explicit timeout action for any unattended session. Stop cooperatively first; AIT then terminates its owned process group. After interruption, do not resume a removed compound campaign. Start a new bounded run after verifying that listeners, callbacks, browser contexts, trace receivers, and target namespaces are clean.
Offline work¶
Because this is a source-access research platform, prepare the reviewed checkout
and its locked dependencies before entering a restricted environment. Confirm
the packaged Seam binary, run ait doctor, and exercise the exact transport in
the controlled lab. Do not rely on an unverified wheel or release archive as a
substitute for the reviewed source state.
Continue with Taking it to a real target for connection details and Two-host field rehearsal for the real network boundary.