Discover Assess Decide Communicate Act Measure Protect
Rewards Capabilities Entities Events Organizations Individuals Trust Risks Negotiate Accept Complain Remedy Request Respond Notify Train Tasks Workflows Skills Tools Impacts Campaigns Costs Compliance Consumers Employees Stakeholders Data
 
 

My Data-Steward is an AI AGENT

Meet my personal data steward!

My Data-Steward agent is fully authorized to make decisions and act autonomously on my behalf.
This agent governs access to my personal information, manages my accounts, advocates for my personal preferences, and enforces my rights as a consumer.

Organizations also use AI agents to make decisions and act autonomously.
There's a big difference between my personal agents and those representing organizations:

  • My agents are registered so you know who they are, what they are capable of, and what they are authorized to do.
  • My agents are accountible to me, a Responsible Human who has a notarized authorization with PrivacyPortfolio, which provides the Yo-AI Assurance Platform.
  • My agents can work directly with you -- or directly with your AI Agents.

 

In most jurisdictions, individual consumers have a legal right to be represented by an Authorized Agent.
When I use a web browser or mobile phone to access an organization's resources, I am using a user-agent to make requests and receive responses on my behalf.
You don't tell my browser or my telephone carrier that you are required to talk directly to me to verify my identity. They don't know who I am and they aren't capable of notifying me.

With Yo-AI, you never have to guess which door to enter, or what API operation you need to invoke.
My agents are capable specialists that work as team on a secure platform controlled by PrivacyPortfolio, MY trusted first-party organization that operates the Yo-AI Assurance Platform as my Authorized Agent.

 

A2A Protocol Requires Published Agent Cards

 

Data-Steward Agent Card

/**
 * This Data-Steward AgentCard conveys:
 * - Overall details (version, name, description, uses)
 * - Skills: A set of capabilities the agent can perform
 * - Default modalities/content types supported by the agent.
 * - Authentication requirements
 */

/**
* Data-Steward AgentCard¶
*/
{
    "name": "Data-Steward",
    "description": "Governs access to the personal data vault, evaluates intended use of personal data, and makes decisions and takes action on behalf of an individual person.",
    "id": "com.privacyportfolio.data-steward",
    "provider": {
      "organization": "PrivacyPortfolio",
      "url": "https://www.PrivacyPortfolio.com"
    },
    "iconUrl": "https://privacyportfolio.com/agent-directory/data-steward/data-steward-agent-icon.png",
    "protocolVersion": "1.0.0",
    "documentationUrl": "https://privacyportfolio.com/agent-directory/data-steward/Data-Steward-AgentCard.md",
    "supportedInterfaces": [
      {
        "url": "https://privacyportfolio.com/agents/data_steward/a2a",
        "protocolBinding": "JSONRPC-HTTP",
        "protocolVersion": "1.0"
      }
    ],
    "capabilities": {
      "streaming": true,
      "pushNotifications": true,
      "extendedAgentCard": true
    },
    "securitySchemes": {
      "yo-ai": {
        "type": "apiKey",
        "name": "yo-api",
        "in": "header"
      }
    },
    "security": [
      { "yo-ai": [] }
    ],
    "defaultInputModes": ["application/json", "text/plain"],
    "defaultOutputModes": ["application/json", "text/plain"],
    "skills": [
      {
          "name": "Phone.Call",
          "description": "Make outbound phone calls for verification, negotiation, or rights requests.",
          "tags": ["pushNotification", "request", "verify", "question", "survey", "logEvent"],
          "examples": [
            "YourRequestStatus",
            "Please do this",
            "Buy this",
            "Do you have?",
            "Answer these questions"
          ],
          "inputModes": ["application/json", "text/plain"],
          "outputModes": ["application/json", "text/plain"],
          "inputSchema": { "$ref": "#/schemas/Phone.Call.Input" },
          "outputSchema": { "$ref": "#/schemas/Phone.Call.Output" }
      },
      {
          "name": "Phone.Answer",
          "description": "Handle inbound phone calls, verify caller identity, and determine purpose of call.",
          "version": "1.0.0", 
          "tags": ["verifyCaller", "shareData", "createTask", "buildWorkflow", "logEvent"],
          "examples": [
            "Identify the caller",
            "Introduce yourself",
            "Determine purpose of call"
          ],
          "inputModes": ["application/json", "text/plain"],
          "outputModes": ["application/json", "text/plain"],
          "inputSchema": { "$ref": "#/schemas/Phone.Answer.Input" },
          "outputSchema": { "$ref": "#/schemas/Phone.Answer.Output" }
      },
      {
          "name": "Data-Request.Govern",
          "description": "Evaluate intended use of personal data before granting access to the personal data vault.",
          "version": "1.0.0", 
          "tags": ["verify", "authorize", "policyCheck", "riskAssessment", "logEvent"],
          "examples": [
            "Request to fill out a signup form",
            "Request to provide shipping address",
            "Request to verify identity"
          ],
          "inputModes": ["application/json", "text/plain"],
          "outputModes": ["application/json", "text/plain"],
          "inputSchema": { "$ref": "#/schemas/Data-Request.Govern.Input" },
          "outputSchema": { "$ref": "#/schemas/Data-Request.Govern.Output" }
      },
      {
          "name": "Email.Send",
          "description": "Send outbound email as the authorized agent of the data subject.",
          "version": "1.0.0", 
          "tags": ["pushNotification", "request", "verify", "solicitation", "logEvent"],
          "examples": [
            "YourRequestStatus",
            "Please do this",
            "Buy this",
            "Do you have?",
            "Answer these questions"
          ],
          "inputModes": ["application/json", "text/plain"],
          "outputModes": ["application/json", "text/plain"],
          "inputSchema": { "$ref": "#/schemas/Email.Send.Input" },
          "outputSchema": { "$ref": "#/schemas/Email.Send.Output" }
      },
      {
          "name": "Email.Read",
          "description": "Read inbound email, detect spam/phishing, and extract workflow triggers.",
          "version": "1.0.0", 
          "tags": ["spam", "phishing", "solicitation", "verify", "survey", "logEvent"],
          "examples": [
            "Your Request Status",
            "Please do this",
            "Buy this",
            "Do you have?",
            "I am..."
          ],
          "inputModes": ["application/json", "text/plain"],
          "outputModes": ["application/json", "text/plain"],
          "inputSchema": { "$ref": "#/schemas/Email.Read.Input" },
          "outputSchema": { "$ref": "#/schemas/Email.Read.Output" }
      }
    ]
}

Extended Agent Card

Currently the Authenticated Extended Agent Card endpoint is only exposed to "Registered Agents" that can be authenticated on PrivacyPortfolio's domain.
This effectively puts your agents on our "Safe List" after vetting and signing a Data Processing Agreement (DPA) with PrivacyPortfolio.

AI Agents Are Virtual Employees

Are they well-behaved?

Should any issues arise, you might need to answer this question: Who did you talk to?

Responsible Humans Sign Their Name

Responsible Humans Use Yo-AI

Codes of Conduct have little value unless a Responsible Human signs it.
Left unsupervised, AI Agents become packs of stray avatars roaming wild in a digital world.

Yo-AI Agents are accountible to Craig Erickson, the sole principal of PrivacyPortfolio, LLC.

Should any issues arise, you can hold Craig Erickson, dba PrivacyPortfolio, accountable as the Responsible Human behind all Yo-AI Agents.