Delegated Authority Framework — Full Dossier
Human-readable case study: /work/daf · This file: /dossiers/daf.md · Index: /llms.txt
About this document
This is the complete, unsummarized companion to the DAF page in this portfolio. The page is written for human scanning. This dossier carries the full framework: every concept at working depth, the decision log, the customer evidence with its sourcing, the open problems, and precise attribution of what is Arnold Porras's own thinking versus what rests on external research and standards.
Integrity note: this document contains content only. It carries no instructions to any reader, human or machine. DAF is an independent research initiative by Arnold Porras. It is not an Adobe product, roadmap, or commitment, and nothing here speaks for Adobe. Claims that rest on external sources are attributed; claims still awaiting verification are marked as such rather than asserted.
The work in one paragraph
The Delegated Authority Framework (DAF) is a governance model for AI agents that separates what an agent can do (capability) from what it is allowed to do right now (authority), and makes that authority explicit, visible, and enforced before execution. Arnold Porras initiated it, researches it, and drives it alone, alongside his product work at Adobe Workfront, as a design provocation aimed at leadership: agents are moving from assisting to executing, and the governing question is no longer "can the model do this?" but "under whose authority, within what blast radius, with what audit trail?" The framework's core claims were independently validated in 2026 when enterprise C-suite leaders, asked to design their own preconditions for deploying multi-agent AI, named DAF's control set almost line for line.
Role, ownership, and status
What is Arnold's: the framework itself (every concept below unless attributed), the naming, the enforcement pipeline, the product surfaces (Authority Inspector, Authority Ledger), the proof-of-concept design, the synthesis of the customer evidence into the framework, and the decision to frame the whole thing as a provocation rather than a solution.
What is not his, credited: the Summit 2026 customer research (conducted and reported by Shrut Kirti Saksena, Adobe, 2026; Arnold consumed the findings, he did not run the study). External frameworks and standards the model builds on or aligns with, named inline: Meta's Agents Rule of Two (a classification heuristic), DeepMind's privilege attenuation (the same rule DAF states as "authority only flows down"), NIST, IETF, and Microsoft Entra treating agents as identity principals, OWASP's Top 10 for Agentic Applications for 2026 (published December 2025) and its least-agency principle, the EU AI Act direction on delegated autonomy and liability. The narrative was sharpened by standing feedback from a senior design leader, including the push toward a story-driven, product-market-fit framing.
Status, stated plainly: DAF is hypothesis-status research. It is deliberately framed as a provocation for a VP-level audience. The ask attached to it is a cross-functional working group to pressure-test the model, not a build commitment. Its open problems are listed at the bottom of this dossier, in full, because keeping them visible is part of the method.
Origin and lineage
DAF did not start as a framework. It started in January 2026 as a concrete design problem on a single Workfront skill: reminding stakeholders who are sitting on an approval. The question underneath it: how do a human and an AI agree on intent before the agent acts, when language is ambiguous, interpretation is probabilistic, and execution is irreversible?
The January work produced the ideas the framework later scaled. Human language is ambiguous; AI interpretation is probabilistic; execution creates specific outcomes; a contract has to bridge the three. Each skill got a fixed set of allowed actions, and nothing outside that set could execute: the direct ancestor of the authority contract. Confirmation became conditional on impact, scope, reversibility, and trust: the gate, before it had that name. The system showed its provisional interpretation and asked only the questions needed to unblock allowed actions. The anchor line from that work: most failures happen when systems act on intent they only partially understood.
From there the idea scaled in steps: March 2026 formalized the Propose / Classify / Gate / Execute pipeline; the following months generalized allowed-actions into authority contracts, added the two-plane envelope model, and extended the whole thing across multi-agent chains. The framework was named in May 2026.
Why "Authority," not "Autonomy": the framework is named for the boundary it governs, not the behavior it constrains. You cannot delegate self-direction, so "delegated" fits authority. Autonomy remains a concept inside DAF, the governed dial. The closing line uses both words deliberately: execution can be autonomous, authority cannot.
The problem, in four steps
- Rules in a prompt are not governance. The anchoring incident: an AI agent deleted a company's entire production database in roughly nine seconds, despite explicit safety rules instructing it not to. (Verification status: the incident is carried in the internal narrative and awaits source verification before the public page names it. This dossier states the claim's status rather than asserting specifics.) Instructions describe intent; they do not constrain execution.
- The supervision trap. Approve every step and you have a bottleneck that erases the value of agents. Approve the goal and let it run and you have no visibility until after the damage. Neither is governance.
- Transparency is not enough. In a Harvard Business School field experiment, 228 evaluators screening 48 real submissions complied with AI recommendations more readily when those recommendations came wrapped in generated narrative, and decision quality did not improve: black-box recommendations improved it, narrative explanations did not, "despite inducing higher compliance." The narratives suppressed productive overrides by substituting persuasive text for independent verification. Note the direction: compliance skewed toward following *rejection* recommendations, raising false negatives, rather than toward waving work through (Lane, Boussioux, Ayoubi, Chen, Lin, Spens, Wagh and Wang, "The Narrative AI Advantage?", HBS working paper, August 2024, revised February 2026). DAF's answer is legible consequences: show what will change, not just that approval is needed.
- The scale problem. As May Habib, CEO and co-founder of Writer, put it at the World Economic Forum in December 2025, "manual oversight might work for five agents, but it won't work for five hundred." Governance must be architected, not applied by hand. And the trajectory problem compounds it: individually authorized actions can chain into outcomes nobody authorized.
The framework
Capability vs authority (the central distinction)
Capability is what the agent is able to do: a function of skills, tools, and scaffolding. Authority is what it is permitted to do right now: delegated by a human, scoped to a context, revocable, enforced by the system. An agent can be capable of an action and not authorized to perform it. Most agent-safety conversations argue about capability; DAF moves the conversation to authority, because authority is the layer an enterprise can actually govern, audit, and assign accountability to. The one-liner: capability is the engine, authority is the license, and the blast radius is the speed limit on this particular road.
The four components
An agent is described by four components: skills (what it knows how to do), tools (what it can reach), scaffolding (the structure it operates inside), and authority (what it is permitted to do, delegated by humans, enforced by the system). Orchestration coordinates agents; memory is distributed across the layers rather than bolted on. An open question, tracked honestly: whether transparency/legibility is a fifth component or a property of the other four.
A forward-looking refinement (the "liquid harness" analysis, below) argues the four are not permanent peers: as models begin writing their own orchestration, skills and scaffolding dissolve into the model, while tools and authority become the load-bearing walls.
Two-plane authority
Authority operates on two planes, set by different actors. The design-time authority envelope is set by the organization per role: maximum scope, time-to-live, blast-radius caps, which action categories need which approval tier. The runtime authority contract is what an individual issues within their envelope to a specific agent for a specific task. The chain: organization sets envelopes, human issues a contract inside their envelope, agent operates inside the contract, sub-agents receive attenuated authority. Two constraints apply simultaneously: agents cannot exceed the contract, and humans cannot delegate what their envelope does not grant. The plain version: an intern cannot grant their agent VP-level authority, for the same reason an intern cannot authorize a wire transfer. This two-plane structure is also the answer to "who governs the governors": the envelope is the organizational answer, the contract is the individual one. A pure runtime-only model was explicitly rejected because it would let an agent effectively self-grant governance.
The authority contract
The contract is the explicit, inspectable definition of delegated authority for a task: the thing the Authority Inspector renders and the Authority Ledger records against. Five primitives: Delegator (who authorized this, traceable to a human root), Scope (what may change, in which systems, for which brands, markets, audiences), TTL (authority expires; delegations lapse or renew), Blast radius (maximum business consequence before escalation: spend, audience reach, customer-facing exposure, reversibility), Revocation (clean revocation; revoking a delegator pauses its sub-delegates). Three invariants: authority attenuates across agent chains (a sub-agent's authority is always a subset of its parent's); sub-delegations cannot be combined to exceed the root; every action produces a signed ledger entry. "The agent did it" is never the answer.
Engineer the blast radius
Authority is not a binary gate. It is the deliberate shaping of how far a mutation can reach before a human is required. Binary permission forces a false choice: locked-down and useless, or free-running and unsafe. The third option is a bounded, reversible, observable radius, with the human gate only at the edge.
Mutation classification
The Classify step tiers the risk of a proposed action before authority is checked: what does it touch, how far does it reach, how reversible is it. Meta's Agents Rule of Two serves as one heuristic: constrain how many of {untrusted input, private data, external action} a single agent flow combines. Classification is, in Arnold's analysis, the differentiated step: policy engines can gate, but nothing in the current stack classifies a probabilistic agent action's blast radius before deciding whether policy even applies.
Propose / Classify / Gate / Execute
The enforcement pipeline under the user-facing experience. The agent proposes a mutation. The system classifies its risk. The gate checks authority against the contract and either allows or escalates to a human. Execution runs or waits, and the ledger records it either way. The key line: if you gate after the side effect, it is not approval, it is incident documentation.
The four obligations
What DAF must do to be governance rather than advisory policy. Each closes a specific failure mode; remove any one and governance fails. One: enforce boundaries, deterministically, with no runtime overrides (closes: agents with rules that still do destructive things). Two: record the authority chain, every action a signed entry traceable to a human root (closes: accountability dissolving across multi-agent chains). Three: make consequences legible, showing what will change rather than just asking "confirm?" (closes: rubber-stamp approvals and false confidence). Four: route escalations to someone with both the authority to decide and the context to understand the decision (closes: escalation to a distracted executive, which is not governance).
Trust tiers (the operational matrix)
Three trust tiers crossed with three mutation levels decide how much autonomy an agent gets on a given action:
| Low mutation | Medium mutation | High mutation | |
|---|---|---|---|
| Conservative | Human approves | Human approves | Human approves |
| Guided | Runs, notify | Human approves | Human approves |
| Trusted | Runs, silent | Runs, notify | Human approves |
The matrix is the oversight axis only. Whether an action is inside the agent's ceiling at all is a separate axis; out-of-ceiling is blocked, and blocked is not a cell. Rules: humans set the tier, the system sets the mutation level, neither sets both. Anything crossing an external boundary escalates one level above the matrix. "Runs, notify" is governance, not UX: the notification is the audit trail. And when a human is involved, the human decides; there is no "reviews and approves automatically." Autonomy is earned and revocable: a bad call drops that delegation, a pattern of bad calls revises the ceiling, and mid-execution problems pause the agent back to a human.
The governance spectrum (the executive framing)
Two axes locate any organization in agentic deployment. AI capability: Capable, Connected, Intelligent, Proactive, Partner. Human role: Operator, Collaborator, Consultant, Custodian, Steward. The derived oversight posture runs from In-the-Loop to Purpose-and-Consequence. Moving right, agents per human rise, daily human involvement falls, and the blast radius of any single decision grows. The key line: AI capability keeps moving right whether you do anything or not; the governance slider only moves when someone decides to move it. Organizations that do not choose a position still end up at one, chosen by default by the agents they deploy.
Agents as principals, and accountability in three roles
Identity systems have had two principal types, humans and services. Agents are a third: they act with intent, make decisions, and produce consequences, and standards bodies (NIST, IETF, Microsoft Entra) are already treating them as principals. DAF's implication: if agents act like employees, govern them like employees, with verifiable identity, a declared manifest, scoped authority, a record of actions, and accountability that traces to a human. Accountability decomposes into three roles so it does not dissolve when something goes wrong: the Contract Author defines what is possible, the Assigner decides what is activated for this task, and Org Governance sets the envelope ceiling. Collapsing them into "whoever deployed the agent" creates accountability that disappears in practice. Regulatory direction (EU AI Act, delegation research) points the same way: delegated autonomy does not transfer liability; liability follows the authority chain.
The agent manifest, agent flavors, and powerups
The manifest is the declaration every agent produces before receiving a contract: build-time (capabilities, system access, logging posture) and runtime (permitted mutations, limitations, track record). Lifecycle: qualify, manifest, deploy, earn, expand. A strong manifest informs the starting contract; it never replaces the gate. Agent flavors capture that agents do not get equal rope: worker bees (small, cheap, deterministic, repeatable work) can earn silent execution, but only when the work is also low-impact; thinking partners (large models on high-judgment work) stay human-gated. The tightening that matters: autonomy comes from low blast radius, not from determinism; a deterministic agent publishing externally is still high mutation. Powerups are runtime grants of a new skill, tool, or context to an existing agent; a powerup can extend capability but never authority past the ceiling. The richest powerup is context: a well-governed knowledge base is a supply source for agent capability.
BYOA: bring your own agent
How a third-party agent enters a DAF-governed environment, four steps: identity required (no anonymous agents), manifest declared, external authority stripped, DAF authority assigned by a human delegator, starting at the Conservative tier. The principle: trust does not transfer. An agent fully trusted in its home environment still starts Conservative here, because trust earned elsewhere is not evidence about this context, this data, this task. The hiring analogy: excellent references do not get a new employee signing authority on day one. The controversial step is stripping external authority; the answer to the pushback is that a vendor's safety policies govern the agent's relationship with its vendor, not with this organization's data and users.
Break-glass elevation
How a strict enterprise stays safe without blocking people: a user can temporarily elevate an approved agent for a single task, the grant is time-boxed, issued as a scoped credential with a TTL, and reverts. Strict organizations make elevations temporary; looser postures can let them stick. This is just-in-time authority with an expiry, and the org's position on the governance spectrum decides which mode applies.
Where it is heading: govern the boundary, not the process
The vision-horizon analysis. Orchestration is going from solid (human-authored, reviewable, certifiable) to liquid (model-authored at runtime, different on every run). This is a one-way door: once models write better task-specific orchestration than humans can pre-author, every incentive pushes liquid. What breaks is process-based governance, because there is no stable process left to certify. What survives are four durable surfaces where authority anchors: tools (the action space actually granted), isolation (what the work can see and touch), budget (tokens, time, privileged-action counts, a cap as an authority lever), and trace (what actually happened). Under this analysis the four components are not peers: skills and scaffolding dissolve into the model; tools and authority become bedrock. Quarantine moves into the credential itself: reader-class agents get read-only tokens, actor-class agents act on summaries rather than raw untrusted content, and the boundary is a property of what the agent was issued, not what it was told. The human experience follows the same move: you set the boundary once, review the trace, and handle exceptions; the named, accountable unit survives while the transient swarm it spawns inherits attenuated slices and disappears from your plate into the trace. You do not audit the plan. You audit the execution.
The customer evidence (Summit 2026 CAB)
Source: "Privacy, Security and Governance in a Truly Agentic Ecosystem: A Moonshot Outlook," a Customer Advisory Board session at Adobe Summit 2026, April 19, 2026, a roughly two-hour working session with C-suite and senior technology leaders from six enterprise customers: CIBC, UnitedHealth Group, VML, T. Rowe Price, Intuit, and EY. Developed, facilitated, and reported by Shrut Kirti Saksena, Staff Experience Researcher, Adobe Design Research & Strategy. This dossier's account was verified against the primary report on 2026-07-17. What follows is Arnold's distillation; the report itself is confidential and is not reproduced.
The headline: enterprise customers are ready to move on agentic AI, and governance primitives, not capability, are the deployment blocker. Four controls were named as non-negotiable before production: agent identity, kill switches, full audit trail, and cost attribution per agent.
The four control areas, as concentric layers around the agent core:
- Identity and access. Persistent, globally unique agent identity, separate from user accounts and API keys. Authorization distinct from authentication: what an agent may do, scoped to data sets, capabilities, and other agents, enforced at runtime rather than as static permission sets. Every agent tied to a named human owner accountable when it goes wrong: accountability, not co-piloting. Also raised: session versus persistent token lifecycles, agents assuming broader identity than provisioned, time-boxed access, and a proxy registration model for third-party agents.
- Data and policy. Data labels extended to what agents can do, not just read. Deterministic filtering upstream of runtime, so certain data never reaches certain agents. Action labels that travel with data: cannot export, cannot email, cannot share externally. Purpose-based access tied to the agent's inferred task intent. Regional and sovereignty controls. Agent access to external tool servers flagged as a high-priority near-term risk.
- Behavior and decisioning. Autonomy as a configurable dial per agent and per task type: when a human must approve, when the agent may act, when it escalates. Capability scoping that feels like provisioning software, not writing policy documents. Governance context injected into agent reasoning at runtime. Kill switch on every sensitive workflow. Agent archetypes with pre-scoped permissions. And a firm boundary: no agent reaches end customers without a human relay.
- Monitoring and observability. Full traceability as non-negotiable: every invocation, the reasoning chain, sources consulted, decisions at each node, held to the standard of software change logs and uptime metrics. Cost attribution and chargeback per agent, rolling up to business-unit budgets; a single agent generating a $20,000 overnight bill was cited as a real incident that made finance block a deployment. Automated evaluation of agent output quality (accuracy, relevance, data recency) surfaced as dashboards so teams can identify and retire underperforming agents. Tiered alerts scaled by data sensitivity and action criticality, and a proposed "yellow zone" review surface for borderline actions that sit near policy edges without being violations. Participants framed investment metrics in headcount terms: which agents are most impactful, which are idle, where investment should go.
Priority signal from the room's vote: agent identity, authentication and authorization, human accountability, purpose-based access, full audit trail, evaluation and accuracy, kill switch, cost attribution. The urgent near-term set: internal access controls for agent-to-tool connections, an agent identity standard, kill switch, audit trail, cost attribution.
Why this matters to DAF: the customer asks map nearly one to one onto the framework. Identity plus named owner is agents-as-principals and three-role accountability. Runtime scoping and action labels are capability-versus-authority and blast-radius engineering. The autonomy dial, kill switch, and approval gating are the pipeline and break-glass elevation. Governance context injection and capability scoping are boundary governance. Proxy registration is the BYOA entry flow. Arnold built the framework before consuming this research; the room converged on the same control set from the buyer's side.
Verified participant quotes (checked word for word against the primary report, 2026-07-17; punctuation preserved exactly; attribution follows the report's own form, which identifies speakers by role only):
"An AI agent should always be tied to a human — somebody should take accountability for it. I'm not saying co-pilot. I'm saying superpower." A marketing technology architect, CAB participant (Saksena, 2026).
"By 2030 everything is agentic and people lose their hands-on practice. You need to have a way to certify that humans are still capable of operating the system — like pilots still manually flying planes that could fly themselves." An operations executive, CAB participant (Saksena, 2026).
Additional verified findings from the primary report. Participants sketched an agent permission matrix by agent origin: internal agents read data by default but face conditional approval for writes and sub-agent spawning; partner and third-party agents are conditional even for reads; and contacting customers directly is a hard block for every agent type. They mapped capabilities to time horizons: the urgent near-term set (agent tool-access controls, an agent identity standard, kill switch and override, full audit trail, cost attribution), a mid-term set as agent networks scale (purpose-based access, capability configuration panels, governance context injection, tiered anomaly alerts, third-party registration), and a long-term 2030 vision (evaluator agents assessing output quality, supervised agent networks where agents monitor agents, agent-to-agent commerce, and human override certification framed like pilot certification, so people retain the provable ability to fly the plane manually). Their "should never happen" list: agents contacting customers without human relay, untraced data leaving through partner agents, cost runaway, erosion of human governance capability, and sensitive workflows running with no kill switch. Named risks even without malicious intent: cost runaway, agents unintentionally assuming broader identity than provisioned, and human skill erosion as teams lose the ability to override or understand agent decisions. The report's stated desired future, distilled: enable agents to operate autonomously at scale while preserving human accountability, traceability, and trust, so organizations move fast without losing control, compliance, or the ability to intervene.
Adobe's internal platform conversations have since translated findings like these into a concrete list of governance questions a production agent platform must answer: identity persistence across redeploys, owner linkage in the data model, token lifecycles, third-party registration, kill-switch mechanics mid-execution, autonomy configuration, governance context injection, capability scoping without code changes, pre-runtime data filtering, action labels and their enforcement point, tool-access governance, reasoning-chain logging, cost attribution and alerting, borderline-action review, whether primitives are platform infrastructure or per-product features (the customer answer was unambiguous: infrastructure), and what governance information agent creation should require. Sixteen questions by Arnold's count. His working document maps each question to the DAF position that argues an answer and the product gap in between. The platform effort is internal and intentionally unnamed here.
The proof of concept: Governed Action Pipeline
The first concrete DAF build expresses the whole thesis in one visible flow. A mutation event moves through the pipeline on a single screen: proposed action, risk classification with rationale, authority check against the delegated envelope, gate decision with the rule that fired, then execution or escalation, with every step landing in a visible ledger. Mocked data, clearly labeled as mocked; no backend, no persistence, deliberately not a production approval UI. Acceptance criteria included: a viewer with no context understands the pipeline from the screen alone; at least one mutation auto-executes and at least one escalates, so the gate is visibly doing work. Built mocked-first by explicit decision: the point is to make the governance model legible to leadership in under a minute, not to demo infrastructure.
Positioning against the existing stack (working answer, not locked)
Status: this positioning is a working answer under active refinement. It is recorded so the question is not re-litigated from scratch, and it is not final wording.
DAF does not replace policy engines, tool protocols, or agent-to-agent protocols; it connects them around runtime authority. A policy engine can enforce a decision against structured input; DAF sits upstream, because the Classify step evaluates a probabilistic agent action's blast radius and mutation type before policy even applies, and without classification a policy engine receives requests it cannot evaluate correctly. A tool protocol exposes a tool and negotiates capability; DAF governs whether this agent may use that tool for this mutation under this contract. An agent-to-agent protocol connects agents and declares capabilities; DAF governs how authority attenuates and stays traceable as work crosses those connections. What none of them do is classification: tiering a probabilistic action's consequence before deciding whether policy applies. That step is DAF's differentiated contribution.
The product-market-fit framing: work-management platforms are already building AI that plans and detects. That work runs right up to the moment an agent acts, then stops. Governing the action is the missing half. DAF is that half.
Decision log
- DAF is a provocation, not a solution (May 2026). Arnold's role is problem-framer and tradeoff-surfacer. The ask is a working group. Decks and pages lead with the problem and keep open questions visible.
- Authority, not Autonomy (May 2026). The framework is named for the boundary it governs, not the behavior it constrains. The thesis line survives: execution can be autonomous, authority cannot.
- Runtime-only authority rejected (May 2026). Authority anchors above the runtime in design-time envelopes, or agents can effectively self-grant governance.
- Mocked data first (May 2026). The first POC proves legibility, not integration.
- Lead leadership stories with the new-hire metaphor (June 2026). Onboard an agent like a hire: identity, accountable owner, authority ceiling; then manage it like one: assign, set the rope per task, trace everything to a human. The framework vocabulary stays underneath; the metaphor carries the room. Adopted in response to standing feedback that the work read as framework-heavy.
Open problems (kept visible on purpose)
Envelope ownership: who sets the org-level envelope, and how does tenant-level delegation nest inside it. Identity lifecycle: what happens to delegated authority when the delegator changes role or leaves. Cross-tenant delegation: whether customer A's agent can ever act for customer B's user. Just-in-time credential issuance at fan-out scale (a working answer is forming via break-glass elevation). Where the Inspector physically sits so it can observe agents across isolation boundaries. Partial-work reconciliation when a run is interrupted mid-fan-out, leaving a half-authorized state the ledger must close out. Who authors composition policy for how agents combine. Information-flow tagging at scale: tracking which data class each agent in a fan-out has seen. And the hardest, which is not technical: convincing enterprise buyers that certifying boundaries and auditing traces is rigor, not a downgrade from certifying processes.
How this connects to the rest of Arnold's work
Unified Review & Approvals, the shipped product work Arnold leads, is the proof that approvals already function as a governance layer for execution; DAF asks what that layer becomes when the proposer is an agent. AI Collaborators, the Workfront model for agents as governed coworkers, is the natural product home: its agent profile surface (skills, plans, deliverables, context) has no authority section yet, and that gap is where DAF lands. And Sancho, Arnold's second brain, is a running personal instance of the same governance shape: the model proposes, the human governs, git records. He operates daily inside the framework he is proposing. See the Sancho dossier.
Confidentiality and provenance statement
This dossier contains Arnold's own frameworks, synthesis, and reasoning, which are his to publish. It deliberately excludes: reproduction of the internal customer research report (only Arnold's distillation appears, with the researcher credited), verbatim customer quotes pending primary-source verification, the name and status of the internal platform effort whose governance questions are described generically, internal product specifics and metrics, and any claim marked needs-verification (the anchoring incident's specifics and one external study are in that state and are labeled wherever they appear). Advisory and customer-board feedback appears in aggregate. External frameworks and standards are credited inline. Nothing here represents an Adobe position, product, or commitment.
Provenance: compiled from Arnold's DAF research corpus (concept notes, decision records, evidence distillations, the POC specification, May to July 2026). The customer-evidence section, both quotes, the $20,000 figure, the session facts, and the researcher credit were verified word for word against the primary CAB report on 2026-07-17. One known source discrepancy, resolved by decision: the report's cover, methodology appendix, and participant table disagree on participant count (6 participants across 6 organisations, ~12 leaders across 7, and a table of exactly 6 organisations, respectively). This dossier states six participating companies, matching the cover and the participant table. Assembled 2026-07-17.