Protocol target
A versioned interface that an adapter is designed to implement. Compatibility depends on the negotiated features and the tested client/server pair.
Standards and interoperability
How Rangoon separates agent protocols, identity, policy evaluation, execution authority and operational evidence. Assess integration requirements against versioned release evidence.
Launch architecture · Active development
Product architecture illustrationThis is a launch architecture reference. Naming a standard or framework identifies an integration requirement; it does not establish a shipped adapter, certification or tested deployment. A support record identifies the specification revision, implementation version, supported operations, limitations and conformance results.
A versioned interface that an adapter is designed to implement. Compatibility depends on the negotiated features and the tested client/server pair.
A framework used to organize risks, controls and evidence. A mapping is not certification or proof that every requirement has been satisfied.
A claim tied to a published artifact, exact version and reproducible test evidence. The release matrix is the source of support truth.
MCP defines interfaces between model-facing applications and external tools or resources. A2A defines communication between independent agents. Rangoon treats these as integration protocols; permission to contact an endpoint remains distinct from approval to perform a consequential operation.
Record the MCP revision, transport, authentication configuration, tool schemas, resource access and error handling. HTTP authorization uses its specified OAuth flow; local process transports have a different credential boundary.
Record the A2A version, advertised capabilities, identity requirements, task lifecycle and artifact handling. Delegated tasks must retain the original data restrictions and action scope.

Authentication identifies a principal. Delegated resource access, policy evaluation and execution approval answer different questions. Rangoon preserves those distinctions when combining existing infrastructure with LNSAT or another authority adapter.
OpenID Connect provides an authentication layer; OAuth delegates access to protected resources; SPIFFE describes workload identities. An adapter must bind the verified identity and access scope to the requested operation.
These are policy or relationship-authorization technologies, not interchangeable protocol standards. Adapters supply typed input, preserve denial and error states, and record the policy or relationship version used.
The reference contract binds the request, target and digests to policy, any required human approval, scoped authorization and a receipt. Unknown outcomes require reconciliation. A transport token or policy allow does not independently satisfy that lifecycle.

Portable packaging and telemetry help teams operate the system, but neither establishes an execution permission. Each deployment needs an explicit isolation model, network policy, credential boundary and evidence retention policy.
Use versioned container artifacts and declared service configuration. Record image digests, secret references, persistent storage and rollback procedures. Container packaging alone is not a sufficient sandbox for unrestricted agent actions.
Use versioned observation and event schemas to correlate operations. Traces are diagnostic records, not execution receipts. Prompt text, tool arguments and sensitive payloads need explicit collection and redaction policy.
Inspect dependency inventories, artifact provenance, signatures or explicit unsigned status, test results and known limitations before adopting a release. This site does not claim published attestations or a completed supply-chain assessment.
NIST AI RMF is a voluntary risk-management reference. Rangoon’s architecture can help organize evidence for an organization’s evaluation; the following mapping is Rangoon’s interpretation, not a NIST assessment.
Assign accountable owners and review roles. Record intended use, affected systems, provider facts, data classes and action scope before enabling a workload.
Evaluate representative and adversarial cases, record failures and compatibility limits, and define approval, monitoring, incident and rollback procedures.
Agency authorization, procurement acceptance and any required control assessment belong to the responsible organization. No FedRAMP authorization, FIPS validation, NIST certification or government endorsement is claimed.
Technical evaluation
Review the product model, security boundaries and integration contracts.
