Put the five formats on one grid and three things become visible that no single teardown could show.
First: no format satisfies all five criteria, and the gaps are not random. They cluster. Every self-describing format — A2A, MCP, AGNTCY, and AgentFacts — lands at Partial or below on Action authority and, in most cases, on Permissioning, because none of them binds a verified capability to an identity or revokes an agent’s live authority on a governance clock. They describe and they sign; they do not verify. Only AgentFacts makes sub-second revocation a first-class goal — and it lands at Partial, not Strong, because that revocation is proposal-grade and invalidates a credential rather than a live agent’s exercised authority. The one format that scores Strong on authority and permissioning — Entra — does so by inverting the model, and pays for it with the weakest cross-organization Discoverability of the set. The gaps are structural. They follow from what each format decided to be.
Second: the field splits cleanly into two halves of one problem. The self-describing formats solve open-network discovery and provenance — how an agent in one organization is found, described, and cryptographically attested to an agent in another. Entra solves enterprise governance and authority — how an agent an organization owns is identified, scoped, and revoked by an accountable authority inside its boundary. These are not competing answers to one question. They are answers to different questions, and an enterprise running agents at scale has both. It needs to discover and trust foreign agents and govern its own. No format in this arc answers both, and the matrix shows why: the design choice that makes a format strong at one half is the same choice that makes it weak at the other. Self-description enables open discovery and forecloses centralized governance. Directory-issuance enables governance and forecloses open discovery.
Third, and most important: there is a shared ceiling every format hits, and it is the same ceiling. In every case, what the format proves stops one step short of what enterprise assurance requires. A2A proves the card’s authorship. MCP proves the server’s publisher. AGNTCY proves the record’s pipeline. AgentFacts proves the claim’s issuer. Entra proves the identity’s issuance. Not one of them proves that the agent, at runtime, behaves as its record claims and remains authorized to — and can be stopped on a governance clock the moment that stops being true. This is the line the entire arc has walked, format by format: the distinction between a notarized claim and a verified one, between coordination-grade infrastructure that is necessary and the alignment-grade assurance that is sufficient. The strongest format in the arc, by whichever criterion, still sits below that line. The ceiling is not a failure of any one format. It is the current frontier of the whole field.
The Matrix
The five formats, scored on the five Substrate Fitness Criteria. Every rating is carried forward from its own teardown, where it is anchored to the format’s specification and repository as of writing.
| Criterion | A2A Agent Card | MCP Registry | AGNTCY ADS | Entra Agent ID | NANDA AgentFacts |
|---|---|---|---|---|---|
| Discoverability | Strong | Strongservers | Strong | Partialinward | Strong |
| Context integrity | Partial | Partial | Strong | Strong | Partial |
| Action authority | Partial | Partial | Partial | Strong | Partial |
| Permissioning | Partial | Weak | Partial | Strong | Partial |
| Provenance | Partial | Partial | Strongbounded | Strongtenant | Partial |
Reading the columns: A2A and AgentFacts are discovery-and-provenance descriptors that climbed toward trust and stopped at notarization. MCP is a server manifest scored, correctly, as strong on discovery and weak on agent-level permissioning because it governs servers, not agents. AGNTCY is the strongest self-describing format — the only one with structural, content-addressed integrity — and still Partial on the authority and permissioning planes. Entra is the inverse: Strong where the descriptors are weak, weaker where they are strong.
Reading the rows: Discoverability is broadly solved — four of five are Strong — because discovery is the problem the field started with. Context integrity separates the content-addressed and directory-issued formats (Strong) from the self-published-file formats (Partial). Action authority and Permissioning are where the field is thinnest: only Entra reaches Strong, and only by issuing identity rather than describing it. Provenance is the row that best exposes the ceiling — several formats reach Strong within a bound (AGNTCY’s pipeline, Entra’s tenant), and none reaches the unbounded, behavior-verifying provenance enterprise assurance ultimately wants.
| Open-network half | Enterprise-governance half | |
|---|---|---|
| Question answered | Discover and trust an agent you don’t own | Govern and revoke an agent you do own |
| Formats | A2A, MCP, AGNTCY, AgentFacts | Entra Agent ID |
| Strong on | Discoverability, Provenance (bounded) | Action authority, Permissioning |
| Weak on | Action authority, governance-clock revocation | Cross-org discovery, portable capability |
| Shared ceiling | Runtime behavioral verification bound to revocable authority — unmet by every format | |
Why the Ceiling Is Shared
The matrix shows that the ceiling exists. It does not explain it — and the explanation is the point, because a ceiling that five capable engineering organizations all stop beneath is not five independent oversights. Two things account for it: where each format came from, and what a document can be.
Start with where they came from: each format standardized the surface its author already owned. Look at where the strengths sit and the pattern is exact. A2A came from an organization whose problem was interoperation between agents built by different parties — and A2A is strongest at discovery and description across organizational lines. MCP came from a model provider whose problem was the boundary where a model meets its tools — and MCP is strongest precisely at that boundary, cataloging tool-providing servers, which is why reading it as an agent-identity record miscategorizes it. AGNTCY came from a networking and distributed-systems lineage — and AGNTCY is the only format with content-addressed integrity and DHT-based discovery, the primitives of that discipline. Entra came from the enterprise identity provider — and Entra is the only format that governs authority and revocation properly, because governing authority is what an identity provider does. AgentFacts came from an internet-scale-indexing research program — and AgentFacts has the most sophisticated resolution architecture and the cleanest separation of planes.
Each organization wrote the standard it was best positioned to write. That is not opportunism; it is competence, and it explains the matrix better than any account of ambition would. The gaps cluster by design because each format’s design began from the surface its author already understood. Which means the empty region of the matrix — runtime behavioral verification bound to revocable authority — is empty for a structural reason: it is the native surface of none of the five. It sits between them. It belongs to no one’s existing problem, and so it has been standardized by no one.
The ceiling is not the frontier of anyone’s effort. It is the seam none of them owns.
And the seam is not merely unclaimed. It is not territory a document can occupy. This is the harder half of the explanation, and it forecloses the obvious hope — that the next format, or a more ambitious one, simply annexes the empty region.
Documents describe a state. Behavior is not a state. A document cannot carry a property that does not exist until execution. Therefore every descriptor stops at notarization.
That is the whole of the shared ceiling, and it is not a gap better cryptography closes. Every format in this arc, including the inverted one, produces a document: a card, a manifest, a record, a credential, a directory entry — each describing what was true at the moment it was signed or issued. Behavior comes into being only while the agent runs, and it can diverge from any prior description at any moment during it. A signature can bind a claim to an issuer with total rigor and still say nothing about conduct that has not happened yet. Notarization is the strongest thing a static artifact can do.
Stated precisely, so the claim is exact: a descriptor alone cannot perform runtime verification. Verification necessarily requires a runtime observer or enforcement component — something present when the agent acts, able to compare conduct against the claim, with the authority to intervene. Remote attestation, continuous credentials, and runtime evidence do not contradict this; they confirm it. Each works by introducing a runtime component alongside the descriptor. None makes the descriptor itself sufficient. The field did not fail to build verification into these formats. Verification is not a property a format of this kind can hold.
That changes what the arc has been measuring. These formats are not underdeveloped versions of an assurance layer. They are a different layer — the coordination layer — and most of them are well built. The assurance layer sits above them and has to be made of different material: runtime observation, policy enforcement at the point of action, and revocation that reaches an executing agent rather than invalidating a document about it.
What This Means for Enterprise Architecture
Six consequences, for the people accountable for the agents rather than the protocols:
- There is no single format to select, and choosing as though there were is the actual risk. The decision is not procurement. It is composition: which layer serves which purpose, and which layer you supply yourself.
- Govern what you own with issued identity; discover what you don’t with a descriptor. These are different problems with different answers. An architecture that uses one instrument for both will be weak at whichever half it was not built for.
- A signature is not an assurance. Every instrument in this field can prove who published a claim. None proves the claim is true of the running system. A control framework that treats a verified signature as evidence of a verified capability has a gap it has not named.
- The verification layer is yours to build. It does not ship with any format in this field, and it is not arriving in the next release of one, because it is not the kind of thing these formats can contain. Budget for it as a first-class architectural component, not as configuration.
- Revocation must reach a running agent, not a document about it. Invalidating a credential is necessary and insufficient. The question a risk committee will ask is whether authority can be withdrawn from an agent mid-task — and today that answer comes from your architecture, not your vendor’s.
- What you can defend today is coordination, not conduct. Say so plainly. The instruments are real, the guarantees are real, and they stop at a line that is visible, nameable, and currently unowned. An enterprise that knows exactly where its assurance ends is in a materially stronger position than one that believes a signed record is a guarantee.
What the Architect Does With It
For the enterprise architect, the matrix converts a vendor comparison into an architecture composition problem. The question was never “which format wins.” It is “which planes do I need, which format serves each, and what do I have to build myself where every format stops.” An enterprise that runs its own agents and consumes foreign ones will compose — an issued-identity governance layer for what it owns, a discovery-and-provenance descriptor for what it does not — and will still have to add, above both, the runtime behavioral verification that no format in this arc provides. That composition, and that gap, are the deliverable. The matrix is how you see them at once. And the reason the gap is a gap — that no author in this field owned the seam, and that no document, however signed, can occupy it — is the reason it will still be there when the next format ships.
Every format proves authorship, publisher, pipeline, issuer, or issuance — and none proves that the agent, at runtime, behaves as its record claims and remains authorized to. Notarized, not verified, across the whole field.
The enterprise deliverable is composition plus a gap: govern what you own with issued identity, discover what you don’t with a descriptor, and build the runtime behavioral verification neither provides.
