Two agents can exchange a valid message and still disagree about what “complete” means. One produces a draft; the other assumes the draft has been approved. The transport worked, but the user workflow did not.

The Agent2Agent protocol specification describes discovery, messages, tasks, artifacts, and interactions between independently implemented agents. The retrieved released specification is 1.0.0. Its common data model is useful infrastructure; it does not settle every application's business meaning, permission policy, or acceptance criterion.

Write the delegated task contract

For a synthetic research workflow, a coordinator asks a remote agent to find sources about a technology. Specify the corpus boundary, cutoff date, evidence fields, output format, and what makes a source relevant. “Research this well” is not an interoperable success criterion.

Decide whether the delegate may only retrieve, may draft, or may publish. An agent advertising a capability does not grant the coordinator authority to use it for every user or resource.

Distinguish a message from a finished task

Long-running work can need status updates, additional user input, streaming, cancellation, or a final artifact. The protocol gives these interactions a structure; the product must define what the user sees and who owns an unresolved task.

A received artifact is not automatically an accepted result. Validate the evidence and content contract before changing the local workflow state to complete. If the result lacks a required source date, request revision or mark the limitation explicitly.

Keep agent boundaries opaque when appropriate

A2A is designed to support collaboration without requiring agents to expose their internal state, memory, or tool implementation. That can improve modularity. It also means the coordinator should validate observable results rather than assuming that an internal method was followed correctly.

Ask for provenance and operation status that the task actually needs. Do not require a disclosure of private prompts or generated internal reasoning as a substitute for verifiable evidence.

Authorization crosses several services

The user, coordinator, remote agent, and downstream tools may each operate under different credentials and resource policies. Document the delegated authority and enforce it at the resource owner. A signed-in remote agent is not necessarily entitled to act on the current user's account.

Separate discovery metadata from trust. Validate the service endpoint, identity, declared capabilities, and permissions through an appropriate deployment process. Do not let arbitrary retrieved text register a new trusted agent and send it sensitive material.

Cancellation is not an undo guarantee

A remote task may have completed an external action before the cancellation arrives. Keep an operation identifier and a status-reconciliation path. Distinguish “cancellation requested” from “cancelled without effects.” If compensation is needed, treat it as a new authorized action.

Retries need the same care. A second message can duplicate work if task identity or idempotency behavior is unclear. Test delayed responses, duplicate requests, missing status, and a coordinator restart.

Evaluate collaboration end to end

Compare the distributed arrangement with a simpler local workflow under the same source and resource budget. Measure final task success, lost constraints, unsupported claims, unauthorized effects, latency, and cost. Protocol-conformance checks are a separate suite from product-outcome checks.

Interoperability is valuable when it lets teams collaborate across implementations without hiding the contract. The successful result is a task completed under the right authority, not merely a valid message exchanged.

Sources and further reading