AGT stewardship and continuity: request for an official path forward #3929
Replies: 3 comments 1 reply
|
I hold no operative authority on this repository. My access level is write, I am not in One correction to the diagnosis. Reviews submitted between 12 August and 11 September: MohammadHaroonAbuomar 99, me 87, liamcrumm 68, Prayag (@prayagupa) 34, Carlos Hernandez (@carloshvp) 16. Review capacity is not the constraint. Merge authority is. All 90 merges in that window came from two accounts (liamcrumm 56, MohammadHaroonAbuomar 34) and 75 of the 90 were Dependabot. I reviewed 87 PRs and merged none, because every PR needs a code-owner approval and I am not a code owner. The backlog also splits less one-sidedly than the totals suggest. Of 132 open human non-draft PRs, 56 are REVIEW_REQUIRED and 44 genuinely sit with the author. The remaining 31 read CHANGES_REQUESTED but have commits pushed after the last review, so the sticky label hides them. 87 are waiting on us, not 135. The item I would add is in GOVERNANCE.md. Succession Planning moves maintainers inactive for 3+ months to Emeritus and removes merge privileges. Last commits on main: Elton Carr, II (@eltoncarr-ms) 3 May, Prashan Sapkota (@prashansapkota) 12 May, Nishar Miya (@miyannishar) 27 May, Jack Batzner (@jackbatzner) 16 June, Kevin Knapp (@Knapp-Kevin) 30 July. Three are already past that line, which puts Core Maintainers below the minimum of three, and the vacancy clause then says no architecture or governance decisions may be made until three is restored. Between them the five submitted 3 reviews in the last 30 days. So the stewardship question cannot be decided under the current document until the roster is repaired. I propose doing that first: confirm the two people actually merging as maintainers, then nominate from contributors who already clear the GOVERNANCE.md bar of 5 merged PRs and 2 months. Carlos Hernandez (@carloshvp) has 17 merged. I founded agentrust-io. I support this discussion and I recuse from any vote on option 4. The merge distribution is checkable: |
|
Carlos Hernandez (@carloshvp), thanks a lot for starting this thread. First, I want to apologize for not dedicating time recently. All current maintainers were busy working on model mis-alignment and other frontier risks. The issue we're trying to fix was low-quality reviews and contributions that were mostly just AI agents without much oversight. It was very clear we needed a change with many breaking things and a lot of prototypes that don't work. We over compensated and I'll personally own fixing that moving forward. The immediate next step I'm taking is dedicating energy to close or merge all outstanding changes. Imran Siddique (@imran-siddique), there are currently 3 maintainers from Microsoft. I'll update the docs to reflect current state. We need to refresh the process for inducting new maintainers and meet more regularly with our passionate community. |
|
Thanks MohammadHaroonAbuomar , liamcrumm , Prayag (@prayagupa) and everyone who has been working through the backlog. The operational recovery since this discussion started is significant: we went from 161 open PRs on September 10 to 30 today. I think it is worth separating that progress from the longer-term stewardship question, though. The original concern was not only the size of the backlog, but whether contributors can understand who is accountable for the project and how continuity works when maintainers become unavailable. As of October 1, there are still a few concrete inconsistencies:
The public-comment date I proposed, September 24, has now passed. Rather than reopening the different transfer options immediately, I think the most useful next step would be to establish the current operating model before the October 10 target:
If Microsoft is actively restoring maintainer capacity and intends to continue stewardship, that is a perfectly valid outcome. Documenting it clearly would resolve much of the uncertainty that motivated this discussion in the first place. I am also still happy to contribute more formally where useful. I now have sustained contributions across runtime governance, action-bound approval, documentation/ADR maintenance, and related areas, so I would be interested in helping with an appropriate maintainer scope if the project is reopening that process. |
Uh oh!
There was an error while loading. Please reload this page.
Request for an official AGT stewardship and continuity plan
Purpose
AGT continues to attract substantial community work. The current maintainer capacity does not appear sufficient to process that work within predictable timeframes.
I am opening this discussion to ask Microsoft, the repository administrators, the listed maintainers, and the community to agree on an official stewardship path for the project.
Current situation
As of 10 September 2026:
The total PR count fell from 173 on 6 September to 161 on 10 September, largely because the Dependabot backlog fell from 44 to 26. During the same period, the human-authored backlog grew from 129 to 135, and the number of PRs older than 30 days grew from 52 to 64.
The project is processing automated dependency updates faster than community contributions. Contributors need timely decisions so they can respond to feedback, redirect their work, or invest elsewhere.
Governance records need clarification
The repository presents conflicting descriptions of maintainer authority:
GOVERNANCE.mdsays maintainers are responsible for technical direction, releases, and community health. It also identifies the code owners as maintainers.MAINTAINERS.md, last updated in May, lists a Project Lead and five Core Maintainers..github/CODEOWNERSgrants repository-wide approval authority to two accounts that do not appear inMAINTAINERS.md.These records do not tell contributors who currently leads the project, which listed maintainers remain active, or who has accepted responsibility for reviewing and merging work.
The documentation backlog shows the operational effect. The ADR index says maintainers last reviewed it on 11 June. A repository audit found implemented and superseded decisions with incorrect statuses. Two correction PRs remain open and require review:
GitHub also lists v4.1.0 from 9 June as the latest release.
Questions requiring public clarification
I would appreciate responses to the following:
Imran Siddique (@imran-siddique), could you confirm whether you still hold any Project Lead or maintainer authority?
MohammadHaroonAbuomar and liamcrumm, could you clarify your current roles and whether you have authority to nominate maintainers or initiate a stewardship transition?
I also invite the Core Maintainers named in
MAINTAINERS.mdto confirm their roles and availability.Possible stewardship paths
I see four options for discussion:
1. Renewed Microsoft stewardship
Microsoft names an active Project Lead, confirms the maintainer roster, and assigns enough review, issue-triage, security-response, and release capacity.
2. Delegated community maintenance
Microsoft retains the repository while granting qualified community maintainers package-level review and merge authority.
This could distribute work across the Python, TypeScript, .NET, Go, Rust, documentation, compliance, and infrastructure areas without requiring an immediate organizational transfer.
3. Transition to the OWASP GenAI Security Project
Microsoft supports an orderly donation or transfer to the OWASP GenAI Security Project. AGT would remain a separately governed implementation project and could serve as an official reference runtime for the Agent Control Standard.
This path already has a technical foundation. The ACS repository contains an AGT-based Guardian proof of concept and conformance harness.
AGT and ACS should retain separate repositories and governance. ACS would define the vendor-neutral standard, while AGT would provide an implementation and conformance testbed.
This path would require agreement from:
4. Transition to AgenTrust
Microsoft supports an orderly donation or transfer to
agentrust-io, where AGT could join an existing open-source ecosystem focused on agent identity, confidential communication, attestation, delegation, and portable governance evidence.This path could provide maintainers already working on adjacent governance infrastructure. It would require a formal AGT charter, multi-organization leadership, transparent maintainer admission, and separation between AGT and the existing AgenTrust projects.
I maintain several repositories under
agentrust-io, so I disclose that affiliation. I am presenting AgenTrust as one possible steward, alongside OWASP, rather than as a predetermined destination.Common evaluation criteria
The community should evaluate each option against the same criteria:
Any transition would require Microsoft to address:
The existing Technical Charter already describes a foundation-transition path and requires public comment for charter amendments.
Proposed next steps
I propose:
Contributors and users can help by stating:
Any recovery plan should preserve AGT's existing security and quality standards while giving contributors timely decisions.
Supporting analysis
I have attached a dated report covering the pull-request and issue backlogs, governance records, ADR maintenance, and release continuity.
agt-governance-capacity-snapshot-2026-09-06.pdf
The report reflects the repository state on 6 September. The updated figures in this Discussion reflect the state on 10 September.
All reactions