<?xml version='1.0' encoding='utf-8'?>
<!DOCTYPE rfc [
  <!ENTITY nbsp    "&#160;">
  <!ENTITY zwsp   "&#8203;">
  <!ENTITY nbhy   "&#8209;">
  <!ENTITY wj     "&#8288;">
]>
<?xml-stylesheet type="text/xsl" href="rfc2629.xslt" ?>
<!-- generated by https://github.com/cabo/kramdown-rfc version 1.7.43 (Ruby 3.4.9) -->
<rfc xmlns:xi="http://www.w3.org/2001/XInclude" ipr="trust200902" docName="draft-rosenberg-vcon-redaction-00" category="info" consensus="true" submissionType="IETF" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <!-- xml2rfc v2v3 conversion 3.34.1 -->
  <front>
    <title abbrev="VCON Redaction">Use Cases and Requirements for Redaction in VCON</title>
    <seriesInfo name="Internet-Draft" value="draft-rosenberg-vcon-redaction-00"/>
    <author fullname="Jonathan Rosenberg">
      <organization>jdrosen.net</organization>
      <address>
        <email>jdrosen@jdrosen.net</email>
      </address>
    </author>
    <date year="2026" month="September" day="29"/>
    <area>Applications and Real-Time</area>
    <workgroup>Virtualized Conversations</workgroup>
    <keyword>VCON</keyword>
    <keyword>AI</keyword>
    <keyword>redaction</keyword>
    <abstract>
      <?line 48?>

<t>The Virtualized Conversations (VCON) specification defines a standardized object format for representing multimedia conversations between users and AI agents. Recent work has expanded VCON to enable it to been used to capture sessions with AI Agents as well, including tool calls, reasoning steps, model configuration and more. This has also expanded the set of use cases and requirements for redaction of sensitive information from a VCON. This document outlines use cases and requirements for redaction in VCONs. This document is meant for discusssion purposes. All of this document was written by the author and not by an LLM.</t>
    </abstract>
    <note removeInRFC="true">
      <name>About This Document</name>
      <t>
        The latest revision of this draft can be found at <eref target="https://jdrosen.github.io/vcon-redaction/draft-rosenberg-vcon-redaction.html"/>.
        Status information for this document may be found at <eref target="https://datatracker.ietf.org/doc/draft-rosenberg-vcon-redaction/"/>.
      </t>
      <t>
        Discussion of this document takes place on the
        Virtualized Conversations Working Group mailing list (<eref target="mailto:vcon@ietf.org"/>),
        which is archived at <eref target="https://mailarchive.ietf.org/arch/browse/vcon/"/>.
        Subscribe at <eref target="https://www.ietf.org/mailman/listinfo/vcon/"/>.
      </t>
      <t>Source for this draft and an issue tracker can be found at
        <eref target="https://github.com/jdrosen/vcon-redaction"/>.</t>
    </note>
  </front>
  <middle>
    <?line 53?>

<section anchor="intro">
      <name>Introduction</name>
      <t>The Virtualized Conversations (VCON) specification <xref target="VCON"/> defines a standardized object format for representing multimedia conversations between users and AI agents. Recent work <xref target="VAC">HOWE</xref> <xref target="RESTRUCTURE"/> has expanded VCON to enable it to be used to capture sessions with AI Agents as well, including tool calls, reasoning steps, model configuration and more. This has also expanded the set of use cases and requirements for redaction of sensitive information from a VCON. This document outlines use cases and requirements for redaction in VCONs. This document is meant for discusssion purposes. No AI was used in the creation of this document.</t>
    </section>
    <section anchor="redaction-support-in-vcon">
      <name>Redaction Support in VCON</name>
      <t>The VCON specification itself provides support for redaction in a singular fashion. It allows a VCON to reference a prior instance of a VCON which was unredacted. This is accomplished through the "redacted" object defined in Section 4.1.8 of <xref target="VCON"/>.</t>
      <t>Beyond this, the specification says that specific methods for redaction of text, audio, and video are out of scope for the document.</t>
      <t>This document considers what those methods could be.</t>
      <section anchor="redaction-properties">
        <name>Redaction Properties</name>
        <t>There are several different properties of redaction systems. These properties largely define what information still remains after the redaction has ocurred.</t>
        <section anchor="signaled-or-unsignaled">
          <name>Signaled or Unsignaled</name>
          <t>Firstly, redaction can be signaled or unsignaled. In signaled redaction, there is some kind of indication - meant for processing by software - which indicates that redaction has occurred. In unsignaled, there is no such indication meant for processing by software. The distinction of "meant for processing by software" is important in this definition. It means that there is something like a field in a JSON document, a flag or tag or other piece of information which conveys the fact that redaction has occurred. In the current VCON specification, the redacted field is the property which provides a way for redaction to be signaled.</t>
        </section>
        <section anchor="positioning-and-participant-indications">
          <name>Positioning and Participant Indications</name>
          <t>Redaction operations can provide a positioning indication. A positioning indication is information that remains post-redaction that indicates where the redaction occurred. For audio and video streams, this is the start and stop timestamps where the redaction ocurrred. For textual streams, it is the exact text which was redacted in the chat sequence. For events, like a tool call, it is the exact position in the event - the tool call input or output for example - which was removed.</t>
          <t>Redaction operations can provide a participant indication. A participant indication is relevant only for conversational elements - audio, video or chat - and it indicates the participant that was redacted.</t>
          <t>By definition, if a VCON has positioning or participant indications, the VCON has signaled redaction.</t>
          <t>What are the use cases where we want to redact sensitive information but retain positional and/or participant indicators? in something like a contact center call, we want to remove PCI, but wish to retain positional and participant indicators for troubleshooting purposes. It is very common in contact centers for managers to review calls after the fact, and use the conversation to adjust many aspects of how both human and AI agents support customers. Another use case is for PII redaction, where we want to anonymize the conversation but don't need to hide the fact that redaction has ocurred. In such cases, we would want positional indicators, but not participant indicators.</t>
        </section>
        <section anchor="detectable-and-undetectable-redaction">
          <name>Detectable and Undetectable Redaction</name>
          <t>In the case of audiovisual content, redaction can be characterized as detectable or undetectable, which indicates whether a human being (or perhaps a model which is processing the content as a human might) - through observation of that content - would be able to determine that redaction has occurred.  For example, if a user speaks their social security number, and it is "beeped" over within the recording itself, then a human could determine that redaction has occurred by listening to the audio, and noting the beep as a clear indicator that there has been information redaction. In video content, there might be rapid fadeout to black. In image content, there might be a black box pasted over an image.</t>
          <t>To make audiovisual redaction undetectable, it needs to be substituted with something which sounds or looks appropriate to a human observer. This is generall quite difficult to do. For example, if a user speaks their social security number to an agent, one could use a text-to-speech model to generate an alternative, fake social security number, using the voice of the user. In other words, apply a "deepfake" technology to alter the content in such a way that it is generally undetectable.</t>
          <t>There are different use cases for how much information we want to remove, and how much we want to retain in the document. For highly sensitive redactions, such as when a witness needs to be protected and their presence utterly removed from a conversation - it is desirable to make the redaction undetectable, with no remaining positional or participant indications.</t>
        </section>
        <section anchor="information-tagging-vs-redaction">
          <name>Information Tagging vs. Redaction</name>
          <t>A close cousin to redaction is information tagging. In information tagging, sensitive information - such as PII - are tagged explicitly in the document or object. By tagging it, downstream consumers of the document can hide the information - or not - depending on the user that is viewing it. This relies on trust between the transmitter of the document, and the recipient. Namely, it requires that the transmitter trust the recipient to perform the information hiding appropriately based on the user that is viewing it.</t>
          <t>A common use case for this is in the contact center. A normal human contact center agent reviewing a call may not have permissions to see the name and address of the user in the transcript of the call, should they view that transcript. However, someone from the security and compliance team, might have such permission.</t>
        </section>
      </section>
    </section>
    <section anchor="redaction-methodologies-for-vcon-audio-and-video-dialogs">
      <name>Redaction Methodologies for VCON Audio and Video Dialogs</name>
      <t>This section discusses the techniques which can be applied to a VCON to achieve different types of redaction. Redaction methodologies for audio and video are more complex than those for text, due to the obvious difficulities in manipluation of the content.</t>
      <section anchor="full-dialog-object-removal">
        <name>Full Dialog Object Removal</name>
        <t>The simplest way to redact audiovisual information in a VCON is to remove the dialog object containing that information entirely from the VCON. In this approach, there is no trace whatsoever that this dialog existed in the VCON. This removal changes the index for any other dialogs in the VCON, which might require updating of references to that dialog from other objects, such as an analysis or participant.</t>
        <t>Full object removal only makes sense if the VCON was structured as a sequence of dialogs, each representing a temporal segment of the conversation. For example, if each turn of a conversation was represented in a singular dialog. If a user spoke their social security number in a specific turn, the dialog representing that turn could be removed from the VCON.</t>
        <t>Full object removal may result in a "hole" in the sequence of dialogs where no audiovisual information is present, making it potentially detectable. Whether it is detectable or not depends on how the dialogs were structured and on the nature of the conversation being captured. If the VCON had a set of dialogs, each representing a one-minute interval of audio mixed from all participants, then removing of one of the dialogs results in a VCON in which redaction is easily detectable - there will be a notable silence in the audio. However, if the VCON had a series of dialogs, each representing the audio contribution of a single speaker for a one-minute portion of time (or perhaps a single turn), then it might be detectable, or might not. If it was a conversation between a user and an AI agent, and the user's utterance is removed, the conversation would clearly sound like it was missing something. For example -</t>
        <artwork><![CDATA[
AI Agent: What is your social security number?
AI Agent: Got it, thanks
]]></artwork>
        <t>A user listening to this audio sequence would know something was missing, making the redaction detectable.</t>
        <t>However, in a less structured meeting, where it is possible there was no direct response to a user's utterance of redacted information, it may not be detectable.</t>
        <t>Full dialog object removal does not have positional or participant indications, making this approach problematic for cases where positional and participant indications are desirable.</t>
      </section>
      <section anchor="dialog-object-content-removal">
        <name>Dialog Object Content Removal</name>
        <t>In this approach, the content of the Dialog object - present either in the body element or the url and content_hash - is removed from the VCON, but the Dialog object itself and its meta-data (including parties, start and duration), remain. We call this a Dialog object "shell".</t>
        <t>Like full dialog object removal, this approach makes sense of the VCON was structured as a sequence of dialogs, each representing a temporal segment of the conversation. For example, if each turn of a conversation was represented in a singular dialog. If a user spoke their social security number in a specific turn, the dialog representing that turn could be converted to just a shell.</t>
        <t>Unlike full dialog object removal, there is no change in the index of the dialog that was redacted, eliminating the need to potentially update references elsewhere in the VCON.</t>
        <t>Also unlike full dialog object removal, content removal can be accompanied by positional indicators (if the start and duration elements are preserved) and participant indicators (if the parties element is preserved). This makes this approach useful for many applications. However, it has a hard requirement that the VCON be structured in a way facilitating removal of content from a single dialog. For calls between a consumer and an AI agent, it would require per speaker, per-turn dialog elements. Even then, redaction of an entire turn might cause loss of information which is desirable for downstream troubleshooting and management purposes. Consider this conversation -</t>
        <artwork><![CDATA[
AI Agent: How can I help you today?
User: Yeah, so my name is Jonathan Rosenberg and my account number
is 12345. I ordered a widget 2000 like a month back and it still
hasn't shown up. The website is showing it shipped but it has
said that for a while and there is no Fedex tracking number.
What's going on?
]]></artwork>
        <t>In this case, the user turn contains PII information (the user's name and account number), but it also contains critical information - the intent of the caller and context of the removal. If the dialog content is removed, the audio is lost. Now, this might be acceptable if there was an accompanying transcript in an analysis object. The entire audio turn could be redacted, and then just the two PII elements from the transcript. The alternative is to perform content substitution, noted below.</t>
      </section>
      <section anchor="dialog-object-content-substitution">
        <name>Dialog Object Content Substitution</name>
        <t>In this approach, the content of the dialog object is replaced with something else. For audio, this might be a "beep" sound. For video, it might be a recorded video of a black screen. More interestingly, the content can be substituted for one in which the "beep" or video overlay only occur in a portion of the content. For example, consider a Dialog containing recorded audio covering 20 minutes of a call. At timestamp 3:41 the user said their social security number and it took 3 seconds to speak it. During the interval 3:41 to 3:44, the audio is replaced by an audible "beep".</t>
        <t>Content substitution is detectable. However, in the current VCON specification, there is no explicit indication that the substitution has happened. There is no positional or participant indicators either.</t>
        <t>This is a gap in the specification.</t>
      </section>
    </section>
    <section anchor="redaction-of-text">
      <name>Redaction of Text</name>
      <t>Text content can be present in dialog objects, containing emails or chat messages. It can also be present in events, such as a tool call request, a tool call response, or even in reasoning outputs. It can be present the Analysis object, inside of a transcript or summary of a dialog element.</t>
      <t>There are several ways to perform redaction of text within VCON.</t>
      <section anchor="well-known-character-substitution">
        <name>Well-Known Character Substitution</name>
        <t>The simplest technique is to just substitute the sensitive information with some kind of alternative well-known characters - "XXX" being quite common. Sometimes, the word "REDACTED" is used as well.</t>
        <t>Well Known Character substitution is effective and easy to implement. It is detectable.</t>
        <t>It's main drawback is that, as a positional indicator, it can lead to false positives. Consider the following interesting conversation -</t>
        <artwork><![CDATA[
AI Agent: What is your three letter confirmation code?
User: Yes, it is XXX.
AI Agent: Thanks, let me look it up.
]]></artwork>
        <t>Here is the interesting question - was the user's confirmation code actually XXX, or was it something else, and there was a redaction operation which substituted the real confirmation code?</t>
        <t>This perhaps seems contrived, but it is even more complex in cases where the redaction occurred over text that was the result of speech recognition. Consider this example -</t>
        <artwork><![CDATA[
AI Agent: What is your three letter confirmation code?
User: Hang on, umm, OK. Its XXX, then YKZ.
AI Agent: Thanks, let me look it up.
]]></artwork>
        <t>In this case, is the user's confirmation code XXXYKZ, or has some kind of partial redaction taken place? There is no way to know.</t>
        <t>This is perhaps improved by using a word like REDACTED, but again can lead to confusion if the participants in a conversation actually use that word! Consider this conversation -</t>
        <artwork><![CDATA[
User 1: Did you try reading the document?
User 2: Yes I did, but the account number was redacted.
]]></artwork>
        <t>In this conversation - did user 2 speak the account number, but then it was subsequently redacted? Or did they say the word "redacted"?</t>
        <t>There is another problem that the word "redacted" is in English, making it difficult to parse in VCON represented conversations in a different language.</t>
        <t>All of these problems stem from the fact that character substitution is not actually part of the schema of the VCON at all - its a hint. As a hint, is ambiguous in some cases. If we want software to be able to know that redaction has ocurred, we want to do better.</t>
      </section>
      <section anchor="information-substitution">
        <name>Information Substitution</name>
        <t>An alternative solution is to replace a piece of information - like a social security number or name - with an alternative that is incorrect, but plausible. For example, using the name "John Smith" or a social security number like "183-13-3948". To perform this substitution, software requires knowlede about the type of information element, and needs some kind of algorithm to perform substitution.</t>
        <t>This approach is similar to well-known character substitution. However, when done well, it can produce redaction which is undetectable. In some use cases, that is highly desirable. In others, it may be very bad. Using a contact center call as an example, consider a user that chats with a contact center agent to get a refund. The account number is recorded into the VCON for the call at the end, and then replaced using information substitution. The user calls back the next day. A human contact center agent reviews the transcript of the prior chat session, and observes the account number in the prior transcript. Not knowing that this is actually NOT the correct account number, the agent uses the wrong account number and applies the refund to the wrong account.</t>
      </section>
    </section>
    <section anchor="requirements-for-vcon-extensions">
      <name>Requirements for VCON Extensions</name>
      <t>Based on the discussion in this document, there are a number of gaps in the VCON specification which would be good to address. Two stand out.</t>
      <section anchor="explicit-positional-and-participant-redaction-indicators">
        <name>Explicit Positional and Participant Redaction Indicators</name>
        <t>In cases where audiovisual dialog content has undergone substitution (e.g., the "beep" sound in an audio track), it would be desireable to have a property within the dialog object that explicity indicates the points in time (start and duration) that contain these beeps. That would address the limitation that, without this, there is no clear positional or participant indicators. THose indicators are highly useful for troubleshooting purposes.</t>
      </section>
      <section anchor="explicit-text-redaction-element">
        <name>Explicit Text Redaction Element</name>
        <t>Instead of using XXX or the word REDACTED or similar, it would be good to standardize a way for any text string - present anywhere in the body of the VCON - to have a standardized way of indicating that some kind of redaction has ocurred. A good way to do this is by adding the idea of a redaction manifest, which allows a string anywhere in the document to be replaced by a reference to a standardized object which supports a mix of text and redacted information. Consider a simple VCON showing a single event - a tool call - which closes an account (using the event concept defined in <xref target="RESTRUCTURE"/>).</t>
        <artwork><![CDATA[
{
  "events" : [
    {
      "type" : "tool-call",
      "tool_name" : "close_account_by_id",
      "input-params" : [
        {
          "input-name" : "account_id",
          "input-value" : "293827344"
        }
      ]
    }
  ]
}
]]></artwork>
        <t>You can see that this contains a sensitive account ID. Here is a version that is now redacted.</t>
        <artwork><![CDATA[
{
  "events" : [
    {
      "type" : "tool-call",
      "tool_name" : "close_account_by_id",
      "input-params" : [
        {
          "input-name" : "account_id",
          "input-value" : "__REDACTED_REF_001"
        }
      ]
    }
  ],
  "redactions" : [
    "name" : "__REDACTED_REF_001",
    "type" : "account_number"
  ]
}
]]></artwork>
        <t>You can see that, we've added a redactions element into the JSON which contains the list of redacted fields, including specification of their types.</t>
      </section>
      <section anchor="explicit-information-identication-element">
        <name>Explicit Information Identication Element</name>
        <t>There is no way in VCOn to take a piece of information - like a first name or social security number - and then explicitly tag it as a piece of sensitive information, without removing it from the document per se.</t>
        <t>This can be done along much the same lines as the text redaction element noted above.</t>
      </section>
    </section>
    <section anchor="ai-authorship-considerations">
      <name>AI Authorship Considerations</name>
      <t>All of the text in this document was written by hand, without AI assistance. AI was used to analyze options for redacting text strings in a JSON document without needing to modify the schema of the document.</t>
    </section>
    <section anchor="security">
      <name>Security Considerations</name>
      <t>This document is entirely about security - focused on information privacy through redaction.</t>
    </section>
    <section anchor="iana">
      <name>IANA Considerations</name>
      <t>This document has no IANA actions.</t>
    </section>
  </middle>
  <back>
    <references anchor="sec-informative-references">
      <name>Informative References</name>
      <reference anchor="VCON">
        <front>
          <title>The JSON format for vCon - Conversation Data Container</title>
          <author fullname="Daniel Petrie" initials="D." surname="Petrie">
            <organization>SIPez LLC</organization>
          </author>
          <date day="7" month="September" year="2026"/>
          <abstract>
            <t>   vCon is a standardized framework for the exchange of conversational
   data.  Conversations, which may involve one or more participants,
   occur across a wide variety of modes and application platforms.  This
   document defines a JSON format for representing conversational data,
   encompassing metadata, conversation media, related documents, and
   analysis.  The goal of this standard is to provide an abstracted,
   platform-independent data format for conversations, regardless of the
   mode or application platform.  By doing so, it facilitates the
   integration and seamless exchange of conversational data across
   application platforms, enterprises, and trust boundaries.

            </t>
          </abstract>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-ietf-vcon-vcon-core-04"/>
      </reference>
      <reference anchor="BIRK">
        <front>
          <title>Verifiable Agent Conversation Records</title>
          <author fullname="Henk Birkholz" initials="H." surname="Birkholz">
         </author>
          <author fullname="Tobias Heldt" initials="T." surname="Heldt">
         </author>
          <author fullname="Orie Steele" initials="O." surname="Steele">
         </author>
          <date day="31" month="August" year="2026"/>
          <abstract>
            <t>   Autonomous agents based on large language models increasingly perform
   consequential tasks on behalf of humans and other agents.
   Demonstrating that recorded agent behavior truthfully represents
   actual behavior is essential for accountability, compliance, and
   human oversight.  This document defines a data format for verifiable
   agent conversation records using CDDL, with representations in both
   JSON and CBOR.  The format captures session metadata, message
   exchanges, tool invocations, reasoning traces, and system events in a
   structured, extensible CDDL definition for verifiable agent
   conversation records.  COSE is used as the signing method to allow
   for native interoperability in SCITT Transparency Services and the
   CDDL definition allows for seemless integration in Evidence as
   specified in RFC 9334.  The specification supports cross-vendor
   interoperability by defining a common representation that
   accommodates translation from multiple existing agent implementations
   with distinct data structure layouts that are typically represented
   in JSON.

            </t>
          </abstract>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-birkholz-verifiable-agent-conversations-01"/>
      </reference>
      <reference anchor="HOWE">
        <front>
          <title>vCon Agent Session</title>
          <author fullname="Thomas McCarthy-Howe" initials="T." surname="McCarthy-Howe">
            <organization>VCONIC</organization>
          </author>
          <date day="20" month="May" year="2026"/>
          <abstract>
            <t>   This document defines an "agent_session" extension for Virtualized
   Conversations (vCon) that profiles the use of vCon parties, dialog,
   analysis, and attachments to carry the record of an autonomous AI
   agent's internal session - its prompts, tool invocations, tool
   results, reasoning, and file or artifact provenance - alongside the
   human-facing conversation that the agent participated in or acted
   upon.

   The extension is a Compatible vCon extension.  It introduces no new
   top-level fields and does not alter the semantics of existing ones.
   Instead, it specifies (a) how an autonomous agent is represented as a
   vCon party, (b) how agent message turns are placed in the dialog
   array, (c) how the internal agent trace (tool calls, results,
   reasoning, system events) is carried as a structured analysis entry
   whose body conforms to the Verifiable Agent Conversations (VAC) CDDL
   schema [I-D.draft-birkholz-verifiable-agent-conversations], and (d)
   how files and artifacts modified by the agent are carried as
   attachments.

   By projecting agent-session data into the vCon model, implementations
   inherit vCon's party/identity model, the lawful basis framework
   [I-D.draft-howe-vcon-lawful-basis], the lifecycle and redaction
   machinery [I-D.draft-howe-vcon-lifecycle], and JWS-based signing,
   without re-specifying any of those concerns.

            </t>
          </abstract>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-howe-vcon-agent-session-00"/>
      </reference>
      <reference anchor="VAC">
        <front>
          <title>Verifiable Agent Conversation Records</title>
          <author fullname="Henk Birkholz" initials="H." surname="Birkholz">
         </author>
          <author fullname="Tobias Heldt" initials="T." surname="Heldt">
         </author>
          <author fullname="Orie Steele" initials="O." surname="Steele">
         </author>
          <date day="31" month="August" year="2026"/>
          <abstract>
            <t>   Autonomous agents based on large language models increasingly perform
   consequential tasks on behalf of humans and other agents.
   Demonstrating that recorded agent behavior truthfully represents
   actual behavior is essential for accountability, compliance, and
   human oversight.  This document defines a data format for verifiable
   agent conversation records using CDDL, with representations in both
   JSON and CBOR.  The format captures session metadata, message
   exchanges, tool invocations, reasoning traces, and system events in a
   structured, extensible CDDL definition for verifiable agent
   conversation records.  COSE is used as the signing method to allow
   for native interoperability in SCITT Transparency Services and the
   CDDL definition allows for seemless integration in Evidence as
   specified in RFC 9334.  The specification supports cross-vendor
   interoperability by defining a common representation that
   accommodates translation from multiple existing agent implementations
   with distinct data structure layouts that are typically represented
   in JSON.

            </t>
          </abstract>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-birkholz-verifiable-agent-conversations-01"/>
      </reference>
      <reference anchor="RESTRUCTURE">
        <front>
          <title>Virtualized Conversations (VCON) Restructure to Facilitate AI Agent Use Cases</title>
          <author fullname="Jonathan Rosenberg" initials="J." surname="Rosenberg">
            <organization>jdrosen.net</organization>
          </author>
          <date day="11" month="September" year="2026"/>
          <abstract>
            <t>   The Virtualized Conversations (VCON) specification provides a
   structured format for storing recordings of conversations, including
   phone calls, email threads and multi-party chats.  VCONs also store
   metadata like call transcripts and mid-call events, like a call hold
   or addition of a party.  Its structure is well suited for 2-party and
   basic multiparty phone calls.  However, there is a need for the VCON
   format to also act as a record of AI Agent conversations, which are
   just another type of conversation.  This document proposes changes to
   the object model in VCON to make it a more suitable format for
   handling AI Agent conversations, as well as more complex conferencing
   use cases.

            </t>
          </abstract>
        </front>
        <seriesInfo name="Internet-Draft" value="draft-rosenberg-vcon-restructure-00"/>
      </reference>
    </references>
    <?line 287?>

<section numbered="false" anchor="acknowledgments">
      <name>Acknowledgments</name>
      <t>TODO.</t>
    </section>
  </back>
  <!-- ##markdown-source:
H4sIAAAAAAAAA+1cbY8buZH+rl/Bkz9kDUjy6+E2AxycWb9kJ5usF/Y4m1yw
MCg1JTFuNXXN7tEoi81vv6eqSDbZ0nh8CQ4HHA4wbKvVJIv1+lSxqPl8Puls
V5sLNf3gjXqpvfFKN5V6Z/6zt63Zmabzau1aPKj0qrOuUbZRf3z59vvpRC+X
rbnBUPo4vDCdrHRnNq49XuDdtZtMKrdq9A6LVK1ed/PWedMsTbuZ36xcM2/j
wPnjxxPfL3fWe3zqjnuMuHp9/UapB0rX3mEl21Rmb/BX001namoq27nW6po+
XF1+g39A6vTq3fWb6aTpd1jkYlKBmosJVsKqvvcXqmt7MwHdzya6NRqzXu73
tQXRWDXuXtfza7sz08nBtZ82rev3tE/bdr2u7d9MpV665sa0XgZNJ5/MEW9W
FxM1Z+7Qv5dX9Hfa3uTGND0oUeoL5lNK9j/9EevbZqN+S2Po+U7bGs+Jdb+x
plsvXLuh57pdbfF823V7f/HoEb1Gj+yNWcTXHtGDR8vWHbx5RBM8ooEb2237
JYb+tWLJPCqlQq/UYKHvstnDqwsZu7BuNOjR5yW92Ha7ejqZ6L7bupaYhkWU
Wvd1LYoy/Z1rdLfVjXoXp5jyK9iFbuzfmE0XKpLRmI6/NYE54flvsu+xWuPa
HQbeQAYTUszhk2KZQdvmrxZCObFMiOa/Vq419No3V+++y19b2vbT1tV/m0N2
dm31sjZzvYF2YkQmTxr67dsfX+dDt+5gZHIZAMsjtWdiLl/+g4u8e/3++t2H
l9cf3hVrncjBwwZWXU+bmkzm87nSSzyCcCaT661Rdyqm+ooY9VD5vVmBFLEZ
VZm1bchxKN/BfHRb8Ui3/KtZdUoYzU6kNXusDcpJo3d93cHEKqtVsQ+1NN3B
mEb1Hs/YHi+vFG/YL2CaK/xHkVmqrfbK3O7xBlZjJ9Q5ZRpikLIdfViGeSr6
sNJ72rIKnPbqAO2luS95boXZDqauZ/Baq7qviMbOuRrj6trPQLz2rqGnvjN7
PNi5ytRE+9pu+lZYQdTuoCwLdb21nikk1zWQ2W2JgE65NdGFuaPHbcceN1kL
vUu+y5K2qqS5+GLduh24TlsPC8LV9jSFcn1Xs1C+eJXg1/14Jvx/Z3QjEqys
X/We+af2fbuHYmHAZV0TkV0x7kD8bG3XQQTLI29c7J0JaVxHT2Hhv//9HxZB
C3e2qmro5AN11XStq3qh7OcHlj7+8g8p51/o4U//azr6F7L7n0DF5Uv8ndnn
T1+kvv+vvP/jyvu9IzaStjKvMRNtcwWORfoLvSZdfZDBoff9fu/aLlIQdJSk
Weqh7byp12rfuhtbYUM+jDvZBzQUcuoRvdVa+y2FS3XVQRI14nZgGGlEa9am
Nc0KZoVZLaaxDek2HoDm8N5ha1db2Vwjq5gq8Ah/9GrldsA+fsvCBcTYbHn3
0/juNFqI2A+z570RWp8vniy+prXExMCYb8zRNRXzaybKUrDA66PHYxhafA7h
wCNUZ3SmM7fdDA6jsm7GwieuOaAcQ9rBWrVye8MDaaVMPKUGEPDDUFjpgVbG
ctCpuOzK9XUFM8OoB7lQf2gxd9tZ41meWFSz7cED6Bp6tGbWdyTN8B5RNGzA
H2FmO9ZG+JL8NYh1Y+pj4KfQlFuF7yycaUtIhsDoujOyv2FuMktsrsUTJvuB
em83ja7Jm7XqA3YrnyaTN7b1XX2cZYNXcLjwKj4b0acR0LNm+CoNYlFi++Cq
dzujgEcr2i7+iZKdZ1aGza7IScHXwMF7t+4OxLx50MUwygRNGO8rbIwoGQjL
KGgcLGeYhgbetzRLgYwfLj3p1/S+UVNaze7IRulFdgukVyQ320WrpFnCTgom
4V1MV9tPZJ1ra+pKTPt372GUUTdn9F2tNySFTv5xNIvaWyNWnGuGsI/DEJsR
dB+cu5eL7MzoIzZx6pZmmXJB5oFSmT5o7TGsnDyXhj85jixWglVSJNHLH5xn
ThEryIR/0LCBld0TP6+S/GBig+HRiiHEkqqGNcnDZXMNsgf0uOMbll7GvcAm
MSsM6eYZ8WKEUS8PLMjS6AaWviEAQ24p80rAzkbv2OeJY2Xf12G7/JLv3F4R
jsCj3f6uBTB/WoC8HzDOMLHt4rTmlqWOFzLnngQYoxc7WYRLig8yJXwXwuYs
6mQCB6dzR4bGyXgk7Jf+n4bhyz354ZbcMf2P9AHjEU4GWxfSdu6GVeJLpJxp
yEjKZ78hwltTmxt67Jpa1DKHamAivhfIMI/xRKRGbxKf5iwk2xWuyRQrsobk
jKZgd8ycAbiYYi6ZYK6U5GLOUh+CZBp06nqxzI+0tA76MuAh0aED/jB9Loy5
A2ste1L+DsqfKANjsO1H54lzrX9B4j9xZWBtR8sQwIWjEgUqqCBpqx9eXs14
0QOwhTw/s/gdK0tMBxgBEPZb5xiJD3jtitUVAj6Cmt1O9LSkS6bY6QaIHB94
/RtrDoKGs6hKHlTgBXGWLSfTHRqoq7/2vqO5kKyQ6+w41CN7V0s4a7Xt8VWZ
ACRoB7DZgYEtZUiNePYoQNoC0fjD1VUeaE+kqhvXHHdIVU6JI/ZWrvlVpxoj
OcKWjOjzgWGICxxFWZdEgIyEeNlMSINQRJyUtZ0XGsNi+PxXpgOPOIchpnxA
3pAeJAcwmcTARKwgtEp2eWM9+TwSJQfHE9QCa6UahWk5ddMUjNPcDGSGz7MT
tAHWsgR0ENnSkFp9Rfpv2q3eU1yTpCiM9DkwCNwnwmjhOMnObrbdQ/aNAp7d
EgnhTZY56C6NmwcmYydMMiRGBLc7AoKfDePiwMW5Bk9DiSeFcv2JvZXFB7ey
FDIMRllEbal/zpJz82q6NGbPmB5axAlk8PCtWbmWc0bJUtgvNWmXgpK/iFZC
UMgnsF/JQEPan1B8I9ZMT4kY4eWqNroddCmHUzQ3F3Fybza4R1JkceZJa2Qc
C4Y43eq9Ba7ReKeXnLrWq0880O5gr3cO1PImrPwWKu8puDLbdBhIiYaDX/hk
Cu0d2FKqoxUz9REp9UvA0a6naTmTHzytqJ93GO9JrWvnIGO9JzjWWugy+4Ug
GtE30w45HVwQJSm1Qq7cGc5V7Kqvee+VW/wTqiT+SJzcDNHWBMUgn6YZkcw7
N8dEBvSLKWGE0NMZHlpDhRquus4gE7DuLqXtk9XdOCtYOMS/lmUn3pRK7vBM
4A0iv1bTCipF005BzWrbuNptjkx1HR1+tEUbHKBgWQGAXc6+YyG/RZ4GDunf
EI7Jl1NM2ElukqH2cWwUO0jvFt9zjAw2mRJaltgWagmahuie9Az7l52wiyOj
hT41cFuFvkF5aC/kNjlBJylLnQvM7TuwB7MHqBYrM0W0mQf+IAGwbXRfrP0l
jh05YVLtxgXgzXF8CC5346IYTK4yRl7rzYYmuOECWwokl/AelNFDFb1tBiB0
LgWQGcT2T5/P7sBO88RfCtZzwWIYAkaZWzo4ssixx1JjYMyVk4UCUAxLgIcz
vHJoBNdzbaIngBD1e6hawFpSOC+pwcwUhudKjsIYYTbJOoIuAyAB78iSwTcA
J3OdoqEDMN+lEibD+hZp7I5qte2YlFnUGIoSFpkpqeT3emeosGC7WJQbkuBi
MlmqGE0yQsilLZ3sDlvmZHFwdmDtUlNd7p49siYIHEwYS2pD4hZjYlTgREos
+FSoTpGugLfs6gJ2ZLok9dnBZZAIthqqsqegGGqy2Jk3IjM6x2LO6apqyRoz
DxaJYUatWrvv4reCpwF6ya/iwZG3GFib3l6ob92BalEzDhvkidlkpTwbPCmt
LdU9Lgl20LdZiG5MNyv1QDyZXFHX/AOXyMiF2uDfOE+5TKnvHznuvoL7dhsf
qm4+lAZDpTVkUuyMLZJRH4sYgufIb1uBrkNZU6+2FnvLvCydhJb1tcwDhFJe
Tuc4OyeDpbK2sMPcKj5YlELgOiTbMMveRLziljcW7iTFTsuVOwgNKmL3dZ/B
uxRRxGWpNz30Q3ii3krl9B15VV1LYdhbIsF3EnZS1pYjiNweuGbEnLE+S6/Y
PmWRUJ5lxRUP241LinSW0ZIhJSWRmvtVKGmxtYHtZZWNjgOlPukd6Vq0b4oB
srS5tT6rOWSF/Fa2TIC92QQloKP7W5EPUimJ3zKRz2eIwF00NTgX1e8rzcCR
tSDUvb3IC1QFgnh/MrOwJYuNnKTp+uitHwUeSI6lFjgZaedqAgU4z3HBEFZK
2TqVAtIZaiUoNpZbiMawsZky4Gt5pERIiaqKjHo2EiuSJqV4e4rTeCYs10h1
vwjOUpkIi5hqdIogxEDeGdhzErjvxnoyRSzT07qzXO2KLYlmEGmxnl5CiaQd
5zlN7hSTEUblVadbV1P5tQkO7YStIU2Gkt5pNz6gGxg2ZCgxAtiDLNUyusuw
nfoxpIYR4eRJJfl5CbQcOgm3DWygMzc6F8g0oUmRCjiXDuzOCDfknuFIr2LJ
ZIWgipWpu1eP4PfnyMeQQ2DvHaWddcqlYT+3CcmB5Zm++5DdMfuDTVEIiXE/
7Ewk4nMXFGvQBcIy2tuCn1IppDIGnWRwJgUm8jd4k0UZRMuUZsHMnmFDG85W
PsOJNBV7wdYu++ifxQhqI9kNJMzuJ2cc1WmiM7eI2GU9IIwm1X4YuAYdSSli
jnSp3sTPsVcWqJWCoR5LXkBXMEQGCE0qHQ1Yi779lRdkzvHbpkrq7FSfpK7A
aTQlCZQ6SsEuEMExns5+Y5JZuBc1R+z6+9//PomnyRfqxwCwjq6/y0O8yF7/
resY2lJg/eR5LsAx3uGoGEDhhkWVzFpo/9TAsLIceCA6GXCZZxS52aBBxNma
4FZmkztjOp5I3IZYOfIQbzmNEV3VHPQqBBv2TPCQ5PMZmZzIIkERdrXJ6zAc
jtiwUI/o+MqYHf1f5YzP8OSXJEgZU7IATlkeViNqVlIIz0rF95depf2NEtyY
48mxaAlnXoYMOsGaszAiJdrBq7wqdj6P3lkZK55XHMLSVcdYrlfhYLdv64Bl
ecKPW+23lI368zFG6pSnS4bjdymGUVNAp+fAFFp9NTRMME+oHjoc3VShN+Lh
LOSwiBYC08OmR8tM/dbU9RSM+z3Z3/pOqc9GosuRhvt/pPHlSEPI6ySN4Fo9
ZiMhQAYfmvp+KQyQV+BqVEYBrEVUPD0HAt9ri1iiUySKxfgcbDB8NTlyNbU3
wR1l6Blek/pt+vvJjuaVkHbIqLihA1mKVGLPVvKh8evRAWXU8uGojNwA872F
hT383GFNnC0YTzLfCMF4gpAXiJKXig81wUbjgc1RksJYB8qwQSf9SPi7LTqB
hroD28uygGOsW3xarVcWeZyIKUH8deJjKHmFgB/1+I1rw5HRELdjzeY0dlOw
Za2MWcs+1lVpA/gwZ82N2VNg9UK9vpEqTJMfeZDpxdRNNF7gxUpTeaN2UlE4
7Q8oSnTc9DSUm8ZnatzvxYdkzMjhiO1l6JkRUZV1wDFUgIRY+64UjG5PiAHa
X+nji8kHCP9C/dnoLdUp1O4oRRHMeNrdK7QcWYF70CK+YYJ3nzx99vxf4VIQ
D0ARuUAAy2oDfPz08ePH8VxyBzlu1ZIK9uG8gxtpJtAZOiHDlg8NzFBaQQ5m
6ak2TgULfBGyA7+1+z3ZTd8FbZt4bSvRLwGOYHE418rdxhtDjoLyZQ7JQvqC
D24BGzZOKnQvBBbFaEmheZZVtMSncRIvhcZctF9lkHAoLBWsejiLhHPLXppq
BVcLcyrTo3lwcHmEJj0PWs1GcZu+CeaS0pSgwKmUPkKmgu/wFEpKpUJ3CLFu
OFpZrcxeMgJxHgGAUY4eHNiR3elQHyNDzjP4UFolaQYbkWXHWWj00kFmjUQI
LkodHPM5ubwEI/JCGy2QnVqEMkwsX0YWpNMcRoGAcqRGpnaHUBU6j6DeZ6O+
EEaV0YA5v6/16vQQieJL1qtyIgE5C5xKriAvcrFsViQ4OpwMmlhKY0Ag52Lg
EBziQv3BtSH/NNRgtaGycE557DjLDrzImCjjTAklvR8IioTwYVsNz811GD5e
FG+eZ2xZ+a1EMbHpb8BnWYEs7SkmjdRXj+dPHyvJCn0APrCIhbrshtYd9ezi
+ZPBaIN7+Ay2Cb6oc+6TekbfukaOZDgscG3+Vd9G6JCyeFnG0b/PR0aVBC7N
0/Sc7Ei4B3V7eUYly6pGHlS/qD0sObp43JE34KToWyxIoRo59N400m46zHFv
ekOYQrKC2MrJMHuj96kilFO4KKvWENw1XBdGkgMb6WBMOmxTGpKf5erBl0h8
6g6C6D0ipDSerPgQ07vRbLG3KhUbsz4pAgPQntnooSSYXDeg0TTL0KMtLVXD
ktlqxIDL0g2SHEnbRWvzQwXoZb/b6fYoX5XIY3GutfXALbqDhzvpyY1tAwGv
wrn9CKw9/66hAPsyNmiMfFtR+U6nAcGZskce3EMo+p07iUs+LrWg5q6Z2t/n
n5iO1ChCPV/TP/3pT9NQcpMzcTknWqj35C7JtsXG6DRZTd+9fnX58vr1K+7/
5I7w0FpPvVj4R423OrY0s17TKciNRGnIlAv9vHs5z70alRkx8RUhBUov6Yrc
gWGMlRO1mejTOSTPvprUozaaU441VDMm+jcjHEdgkDrIpUsyeet7wF1RB+q2
8PhYjA/2+OZAFMzKVWbAe6ldEYxfZJNdc3VoRjPAqrivgV4EKhNo9G3wEskV
BhLZfgS2EErIsNAJEcAP1DeJiIG12bhoBIG7IjLOMgwnRbr2tDcxNmJkgUvQ
kK7P7V58VawdemN2PtQjGRkFcEb6QeZenEdR/1pWqSkLXamzhrtP2ARTFipv
cuWcGuKl84LC2ya2KJdIPiv4/dNy/lYzrJ0peJiZevsd6bUXtjPQ+vN3//Hf
EX6Ji+09YsYymJ8FzI2TuU/gmFJ04nTIwBrFcfNFEYzCIRw5jSzYRBnCZFsu
MCHUSj+KFh/BOUf0EyJavdG2KYyRiO75qkmeIIcSvECZwvaS5konoub7Q9W/
fEEuRvJQTy6AdCpJv1o6T9FVhBXxJF8kp56yjSKhqmw1VMvKbGLU61pKqGwL
wSyChp4GUHM6W1qliQVpMiouYnXcdiLrvFBvW56OD769PmZeOd1HeRGjFqGC
0FQZyp4DFhmNCef/rwFOrd/mJ0JFdxQE5E28x1NUucq7Xyy74Xi6hiH00hCW
7sGFSx9EFZXvQFvKLobezNWdIYSKwUkfSG8i2vWrLeBJUSDUfDWI+3O4PGIp
xFzG/7Ip6d3Sbno60Q4tveJuOKGL/Ufpnob0C8UOH67L391JWvT+VjSSnEbI
evLunRIPXBatYFi7TlvnQ242VYp65+5BzGPOfwfmpkM7ypHnghfKtjMVW0ds
gySgZfREyokVez4PGCUSQx8azzn9ndtiMztMzKnKnUQwidMnXz+bP3k2f/br
519PAYPzvhfrR1ljEkBqqCHe14aC2tIFK6VWiDE/ApwL/ZXc8zXCSBsH0ra7
HNfla0fXl0pyRJvd0f1xGnIOV5Xjh4SCO9Aqyu3CZcQuNvhX/SqPaqlYVXTZ
cV8y0Z4a62ZJYKEDbjibSG2APh28QHG5L3ypkXV8CC77TMt6aAg4ly4O/UWE
/sM1y5NJpDGIuxs7Rg9rTqOvTx0pp2wh34Q9usFw4801IUjka5q8VpFyPdHC
4ppYwf/rmJGGYiXhR6lFAy1U+kh9Tvc2OPlR8SN6GblbGG6UcK+QkBhaT/25
8BEyNRma11O+h2cjXRqK+ekqYnB337+9Dok9m+dJKOHVNqH7UhY/tI4kXZLA
JTJuMIo4iWQUW3yKIfFK5+h2KUvp9W1HuQhfU/omb0QLLU7pnkx25zBmzWTN
OrmlNeWwRa/L6HpkuDMTi1cb56Q1ShrIIOWDk8vLlB9K7vU6ZuQ/lKd7+U2r
ITm+Shk2R/Mcc+aNFKP63laLlbYbsusiVH1lFpvFLC/fyNlzqNZJRY7qog+z
6vgyHDCaGGP42FNn182GxvSy3sUKE4sQx/F1HWcDsJKD/DNneCq142uZ30sX
Ot/T1JG+2LBHk9LZTjcUOqShVZxxuOI6HB5xE/uXlDew2reOkUYqeJCmBAeX
nYfceQemlD2XOgYpv5Z4QCIG8tCV3Nam8UDN8VSVEVKEsFwoEIdfyimqYHZl
Prv9R6c1nI/4jktYw6kuvikOt/hcNwct80zuxX18mju7Whq9RBHQ7rjTcink
BkxfueRaqFJWJTQMP6+lHDLMQ319ay7SiA2mu9ZhZ+P9pDZdAUtFTS67l83d
A+d+biBmlnxNiC+e2NtUYJGb7qftBVkyp0M1JXiRcIaRjq/ihb284hSv5HG3
dCq1k7/8asA4MhAGQvX5/Mp38cMFDxeSd/w8UWoqpa+pulB/4Z9g+Zn/xhcE
VejxlGiYEw3TWfoOjz4SoOIXmKSPgZyPy+NHWw2v8jXDOQxJ77JV8pWy19KU
cbJspuy1G1338t7TXz/7+um/PXv+fJre+iX876dJ/PTT5BfJgCZ/RnZFeEaa
fGP0SmctOqtbRe5evQI8ivkKoROfqqbsNw75lcL/I1z9+DF6FvznzcfHj598
lr0013S4zzDQM00rn5lRKBgYEomTcDvN5TYWG2UtvyIZVXwKkN2lGE6vI1Tj
C9vp6rXIWSKD74pGIL467fPf3yiju7g/20o788iF56nSFf26VRyVnPm4bCFp
Kl946PgO0j3J0pp+C0CSGHfnccV8wJ7Z1Qa6mm7Dtbe0yNkK7RAfU3Oh7YbU
N7lNPhg3Me8IFW5OGxDu+WdXwqGQJ3rlp0B07CW/zXPRKC85c0OidMNNS/zD
KPxjM3SqmxxnvG8+5Oky3xjAjX+7ZqsJl8e90Yk/gJ/81sai+PEQviGl6yPi
pNuLRmX35MnLDvHSn/lFgLQG5XGhaW7nKrs+nkn/s5+8eEA/yiGiLPeqfn4Q
hfzL+JcxqCAYW8MlxUz6MAfZqz6g3VyfgOhv9IqokfuO+U1l+tmey+8vTymw
4MnJ6lvpuOMRwfrizwBR/sJCXIUUmJuX/OTnC9FTU/37lGvdU5r17au3NPC/
AGz9e3rMTgAA

-->

</rfc>
