SADAR
 -
White Paper
April 29, 2026

SADAR Quick Reference

SADAR is an open Community Specification aimed at improving the observability, attribution, and trust of Agentic AI systems.

SADAR Enables

By acting as the definitive semantic trust layer, SADAR transforms agent discovery from a probabilistic guessing game into a deterministic, governed operation. It unlocks enterprise adoption through several key mechanisms:

1. Deterministic, Standards-Grounded Discovery

SADAR abandons ambiguous text descriptions. Instead, capabilities and data contracts are mapped explicitly to established industry standards like NAICS (industry classification), APQC PCF (business processes), and X12 or HL7 (data transactions). When a requesting agent searches the registry, it matches exact semantic contracts rather than hoping two independent prose fragments happen to overlap.

2. Enforceable Business Process Integrity

SADAR treats end-to-end business workflows as first-class registry entries. By explicitly declaring exactly where a capability fits within a standard business process, SADAR manifests define strict predecessors and successors. This deterministic mapping prevents out-of-sequence failures by ensuring an agent cannot invoke a tool until its required predecessor steps are confirmed complete.

3. Bilateral Matching of Non-Functional Requirements (NFRs)

SADAR elevates Non-Functional Requirements—such as costs, SLAs, payment methods, and regulatory compliance—to first-class discovery criteria. Discovery operates bidirectionally: a requesting agent can filter out capabilities that are too expensive or lack required SOC 2 or FedRAMP certifications. Conversely, a provider has a built-in right-of-refusal, restricting its visibility strictly to requestors that assert compatible regulatory postures. Compliance is verified before a connection is ever attempted.

4. Verifiable Identity and End-to-End Attribution

Through the use of the standardized searchAndInvoke tool and the SADAR Context Token (SCT), SADAR guarantees that every action taken by an agent is fully attributable. The SCT is a cryptographically signed token passed alongside standard authentication that preserves the human originator's identity, their authorized scope, and the specific business process context through an arbitrarily deep chain of agent delegations. Every autonomous decision is linked to a unique transaction instance ID, providing full enterprise explainability and auditability.

5. Secure First-Use Authorization

SADAR defines the exact mechanics for first-time interactions between previously unknown agents. Because OIDC authentication endpoints and public keys are embedded securely within the signed manifest, agents can negotiate credentials, verify licensing, and authorize payments directly. The registry facilitates the introduction, but sensitive runtime execution and data exchange happen entirely out-of-band directly between the agents.

Click on the link to read the full document.