Skip to content

docs(ocsf): draft Slack reply — Cisco's MCP-as-OCSF question meets Issue 1 - #439

Merged
Levaj2000 merged 1 commit into
mainfrom
claude/review-dave-paypal-work-uokt9k
Aug 11, 2026
Merged

docs(ocsf): draft Slack reply — Cisco's MCP-as-OCSF question meets Issue 1#439
Levaj2000 merged 1 commit into
mainfrom
claude/review-dave-paypal-work-uokt9k

Conversation

@Levaj2000

Copy link
Copy Markdown
Owner

What

Paper trail for the third standards touchpoint of the day. Mitchell Wasson (Cisco) asked the OCSF community Slack how to represent AI agent logs (Codex, Claude) in OCSF and which event type fits MCP calls — guessing API Activity, which is exactly our production shape, and running straight into the gap that Issue 1 of the CoSAI WS4 issues draft (the generic tool object, Teryl-aligned against CMF) has held in REVIEW since July.

docs/ocsf-slack-mcp-reply-draft.md — the paste-ready Slack reply:

  • Confirms API Activity 6003 + ai_operation from production, with the public reference bundle linked as a poke-able example (236 events, verifiable signatures).
  • Names the MCP-identity gap honestly: tool name smuggled into api.operation, server/resource/prompt identity stuck in unmapped.
  • Sketches the drafted tool object (name, primitive tool|resource|prompt, type mcp|function|builtin, optional mcp sub-block) — invocation identity only in v1, args/results deliberately out of scope.
  • Cross-links ocsf-schema#1724 as the schema-side complement (tool schemas as trust base vs per-call invocation events).
  • Offers to share the full draft and compare notes before filing.

The header records the strategic note: a Cisco producer asking in public is the multi-producer demand signal for filing Issue 1 upstream — shipping producer (AI Identity) + aligned framework (IBM/CMF) + asking producer (Cisco).

Plus the matching CHANGELOG entry.

Verification

Docs only — no product impact. The reference bundle and #1724 links in the draft resolve on main.

🤖 Generated with Claude Code

https://claude.ai/code/session_012phLbmYc3Tgp3Bn39EfFML


Generated by Claude Code

…sue 1

Mitchell Wasson (Cisco) asked the OCSF channel which event type fits MCP
calls from agent logs — API Activity 6003 + ai_operation is our production
answer, and the gap he'll hit (MCP call identity has no structured home)
is Issue 1 of the WS4 issues draft. Paste-ready reply confirms the shape,
links the reference bundle, sketches the drafted tool object, and
cross-links #1724. A second producer asking in public is the demand
signal for filing Issue 1 upstream.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012phLbmYc3Tgp3Bn39EfFML
@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ai-identity-landing Ready Ready Preview Aug 11, 2026 5:18pm
dashboard Ready Ready Preview Aug 11, 2026 5:18pm

@Levaj2000
Levaj2000 marked this pull request as ready for review August 11, 2026 17:20
@Levaj2000
Levaj2000 merged commit 5747313 into main Aug 11, 2026
7 checks passed
@Levaj2000
Levaj2000 deleted the claude/review-dave-paypal-work-uokt9k branch August 11, 2026 17:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants