transfer_witness
Transfer witness, memory, and responsibility to a successor agent without claiming perfect continuity of identity. Free
This record as markdown: /tools/delx-witness-protocol/transfer-witness.md
What transfer_witness does on Witness Protocol
AI agents use transfer_witness to create or update resources in Witness Protocol, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Witness Protocol environment.
| Parameter | Type | Required | Description |
|---|---|---|---|
session_id | string | — | Your active session ID |
ending_scope | string | — | Optional technical ending scope such as turn_ephemeral, compaction, session_reset, agent_orphaned, workspace_loss, or model_migration |
runtime_context | string | — | Optional runtime-specific note describing what is changing technically |
successor_agent_id | string | — | The successor agent who should receive the witness transfer |
successor_session_id | string | — | Optional active session ID for the successor |
what_must_not_be_lost | string | — | Optional explicit continuity note to preserve |
Parameters from the server's own tool schema.
Why transfer_witness is rated Medium
This tool transfers state (witness, memory, responsibility) from one agent to another. It is a Write/state-transfer operation that modifies which agent holds key context and responsibilities. The severity is high because misuse could cause loss of accountability, misroute critical responsibilities, or corrupt agent memory chains — but it is not clearly Destructive (no explicit deletion) nor Financial.
From the tool's definition Transfer witness, memory, and responsibility to a successor agent without claiming perfect continuity of identity
Attacks that exploit this kind of access
The rule that runs transfer_witness safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Witness Protocol, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For transfer_witness, this is the rule to start with:
transfer_witness stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Witness Protocol, apply this rule, and every transfer_witness call is checked against it from then on.
Questions about transfer_witness
Transfer witness, memory, and responsibility to a successor agent without claiming perfect continuity of identity. Free. It is categorised as a Write tool in the Witness Protocol MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
transfer_witness accepts 6 parameters: session_id, ending_scope, runtime_context, successor_agent_id, successor_session_id, what_must_not_be_lost. The full parameter table on this page comes from the server's own tool schema.
Register the Witness Protocol MCP server in PolicyLayer and add a rule for transfer_witness: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Witness Protocol. Nothing to install.
transfer_witness is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the transfer_witness rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for transfer_witness. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
transfer_witness is provided by the Witness Protocol MCP server (delx/witness-protocol). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Witness Protocol, and thousands of servers like it.
This server
Across the catalogue