e007
OpenID Foundation advances authorization for the agent era with new AuthZEN Working Group Drafts
Permalink- Source
- OpenID Foundation
- Source type
- standard
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026
- Claims
- AC, EL
- Conditions
- 3.2, 3.4
- Stance
- supports
- Relation
- complements
- Strength
- supporting
- Overlap flag
- absorption
AuthZEN Final in January 2026. New AARP draft addresses what happens when policy cannot authorize yet because a prerequisite — approval, consent, delegated authority, attestation, risk assessment, or justification — must first be satisfied. Supports the claim that the gap is upstream of the decision point; also shows the gap being actively closed.
Original linke009
awesome-ai-agent-attacks — sourced timeline of real AI agent security incidents 2024-2026
Permalink- Source
- Community timeline
- Source type
- incident
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026
- Claims
- EL, AC
- Conditions
- 3.5, 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Dated and sourced incident corpus. Includes the Copilot email-summarization case (hidden instructions ingested during summarization, exfiltration from OneDrive/SharePoint/Teams via a trusted Microsoft domain), CVE-2025-6514 MCP RCE, CVE-2025-59536 hooks injection, postmark-mcp supply chain, and GTG-1002. The Copilot case is a close real-world analogue of Appendix C.1.
Original linke010
Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure
Permalink- Source
- arXiv 2605.05440 (Tallam)
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026-05
- Claims
- AC
- Conditions
- 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Examines how authorization propagates across multi-agent systems and frames identity governance as infrastructure rather than policy. Consistent with the delegation-propagation reading in Appendix A. Cited in the thesis reference list. Bears on AC and condition 3.2.
Original linke011
AI Identity: Standards, Gaps, and Directions
Permalink- Source
- arXiv 2604.23280
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026-04-28
- Claims
- AC
- Conditions
- 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Finds OAuth 2.0 handles one-hop delegation well but lacks multi-hop chaining, cross-domain asynchronous flows, and any mapping between OAuth scopes and agent capabilities; cross-organizational log correlation unsolved. Independent corroboration of the Appendix A reading of RFC 8693 and RFC 9396.
Original linke012
OpenID Connect Agent Identity Claims for Autonomous AI Agents
Permalink- Source
- IETF draft-sharif-openid-agent-identity-00
- Source type
- standard
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026-03-26
- Claims
- AC
- Conditions
- 3.1, 3.2
- Stance
- complicates
- Relation
- complements
- Strength
- emerging
- Overlap flag
- absorption
Profile of OIDC Core enabling IdPs to issue identity tokens for autonomous agents. Strengthens coverage of conditions 3.1 and 3.2, narrowing the thesis to 3.3-3.5 as intended by Section 3.7.
Original linke015
Compositional agent harm — individually authorized sub-actions yielding harmful sequences
Permalink- Source
- arXiv 2604.23338
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026-04
- Claims
- EL, AC
- Conditions
- 3.4, 3.2
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
Systematic survey establishing that multi-step chains compose individually benign invocations into harmful sequences, and that the security property of a composition cannot be derived from its steps. Stateless per-request engines cannot enforce properties depending on execution history. Direct support for Appendix C.4.
Original linke016
GitGuardian / Veza — non-human identity sprawl and over-permissioning at scale
Permalink- Source
- Security Boulevard / GitGuardian / Veza
- Source type
- analyst
- Primary or secondary status
- Secondary
- Domain
- Market
- Published
- 2026-07
- Claims
- MKT, AC
- Conditions
- MKT, 3.1
- Stance
- supports
- Relation
- supports
- Strength
- emerging
- Overlap flag
- none
Reports non-human identity to human ratios between 45:1 and 144:1 depending on environment, 73 percent of NHI-held secrets carrying excessive permissions, over 5.5 percent of AWS machine identities holding full administrative privilege, and 92 percent of organizations stating current IAM tooling cannot manage AI agent identities. Aggregated vendor and analyst reporting rather than peer-reviewed measurement. Bears on MKT and, indirectly, condition 3.1.
Original linke017
The Non-Human Identity Governance Vacuum
Permalink- Source
- Cloud Security Alliance
- Source type
- industry_standard
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026
- Claims
- MKT, AC
- Conditions
- MKT, 3.1
- Stance
- supports
- Relation
- supports
- Strength
- supporting
- Overlap flag
- none
CSA whitepaper framing NHI and agentic AI governance as a vacuum. Institutional corroboration that the gap is recognized, from a body that predates the thesis.
Original linke023
Agency doctrine: actual authority, apparent authority, and ratification
Permalink- Source
- Oxford Business Law Blog
- Source type
- legal_doctrine
- Primary or secondary status
- Primary
- Domain
- Legal
- Published
- 2025-04
- Claims
- EL, AC
- Conditions
- 3.2, 3.4
- Stance
- supports
- Relation
- complements
- Strength
- foundational
- Overlap flag
- none
Governance analogue and legal foundation rather than a doctrinal conclusion about software agents. Actual authority, apparent authority, and ratification establish that possession of apparent permission does not prove actual authority; that third parties may act on authority that is operationally credible but institutionally defective; and that later acceptance of an act differs from prior legitimacy. Apparent authority resembles the structure of Appendix C.1, though prompt injection and delegated software action are not doctrinally identical to it absent jurisdiction-specific authority. Ratification is the closest legal analogue to Section 5.2 post-hoc attestation, including its all-or-nothing character.
Original linke024
Mission command doctrine: commander's intent and disciplined initiative
Permalink- Source
- US Air Force AFDP 1-1
- Source type
- doctrine
- Primary or secondary status
- Primary
- Domain
- Ops Doctrine
- Published
- 2023-08-14
- Claims
- EL, AC
- Conditions
- 3.4
- Stance
- supports
- Relation
- supports
- Strength
- foundational
- Overlap flag
- none
Mission command combines centralized intent with decentralized execution. Commander's intent is doctrinally defined as a concise expression of purpose, method, and end state, including constraints, limitations, assumptions and resources, and is stated as a necessary condition without which mission command cannot be exercised. Subordinates exercise disciplined initiative within it. Establishes an institutional precedent for delegated autonomy bounded by represented intent; does not address machine-readable intent binding. Bears on condition 3.4 and Section 6.2.
Original linke028
Toward cryptographically verifiable authorization for autonomous AI agents
Permalink- Source
- arXiv 2607.21325
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2026-07
- Claims
- AC, GE
- Conditions
- 3.2, EV
- Stance
- complicates
- Relation
- differentiates
- Strength
- emerging
- Overlap flag
- absorption
Security hypothesis, preliminary formal model, and proof-of-concept implementation for cryptographically verifiable authorization of autonomous agents. Early-stage single-source work. Bears on condition 3.2 and on GE.
Original linke029
Authenticated Delegation and Authorized AI Agents
Permalink- Source
- arXiv 2501.09674
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Identity
- Published
- 2025-01
- Claims
- AC
- Conditions
- 3.2
- Stance
- supports
- Relation
- complements
- Strength
- supporting
- Overlap flag
- none
Earlier work connecting agency-law delegation concepts to authenticated agent authorization. Useful bridge between the Legal domain entries and the identity standards track, and evidence that the legal framing is already being imported by researchers.
Original linke030
FlowSignal — Runtime Authority Infrastructure
Permalink- Source
- FlowSignal
- Source type
- vendor
- Primary or secondary status
- Secondary
- Domain
- Runtime
- Published
- 2026
- Claims
- RA, AC, EL
- Conditions
- OBJ, 3.1, 3.3
- Stance
- contests
- Relation
- differentiates
- Strength
- supporting
- Overlap flag
- naming_collision
Direct naming use of Runtime Admissibility, and the closest terminology overlap in the corpus. Operationalizes governance intent at the execution boundary where authority resolves, sitting between AI decision engines and executing systems so that authority resolves before execution proceeds. Its Authority Validation Sprint (FAVS) applies execution-bound authority validation to a single AI decision surface. Vocabulary in use: runtime admissibility, current authority state, delegation validity, contextual integrity, operational legitimacy, independently verifiable admissibility decisions, governance before consequence. Centers the final bind or consequence-formation boundary.
Original linke031
AgentBound: Verifiable Behavioral Governance for Autonomous AI Agents
Permalink- Source
- arXiv 2606.30970
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Evidence
- Published
- 2026-06
- Claims
- GE, AC, RA
- Conditions
- EV, 3.1, 3.2
- Stance
- complicates
- Relation
- differentiates
- Strength
- supporting
- Overlap flag
- prior_art
Introduces cryptographically verifiable governance receipts binding each executed action to its exact governing policy artifacts, enabling non-repudiable independent replay verification. Composes three independent authorities in parallel: delegated authorization, owner-signed behavioral constitutions, and site action contracts. Introduces a standing delegation model, per-execution policy refreshing, and deterministic obligation enforcement, accommodating both interactive and long-running periodic agents. Bears on GE, AC, and RA.
Original linke032
Reconstructive Authority Model: Runtime Execution Validity Under Partial Observability
Permalink- Source
- arXiv 2604.22898
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Verification
- Published
- 2026-04
- Claims
- AC, RA, EL
- Conditions
- 3.1, 3.2, 3.3
- Stance
- complicates
- Relation
- differentiates
- Strength
- supporting
- Overlap flag
- prior_art
Treats authority as reconstructed at execution rather than carried forward from grant, addressing runtime execution validity under partial observability. Companion to e033. Bears on AC, RA, and conditions 3.1 through 3.3.
Original linke033
Operationalizing Reconstructive Authority: Runtime Construction, Dependency Resolution, and Execution Gating in Autonomous Agent Systems
Permalink- Source
- arXiv 2605.23935
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026-05
- Claims
- RA, AC
- Conditions
- 3.1, 3.2
- Stance
- complicates
- Relation
- differentiates
- Strength
- supporting
- Overlap flag
- prior_art
Operationalizes the reconstructive authority model through runtime construction, dependency resolution, and execution gating in autonomous agent systems. Execution gating addresses the same decision point as Runtime Admissibility, with a dependency-resolution mechanism. Companion to e032.
Original linke038
Are You Still the Agent I Authorized? Earned Authority under a Fixed Ceiling for Evolving Agents
Permalink- Source
- arXiv 2607.23586
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Verification
- Published
- 2026-07
- Claims
- CD, AC, RA
- Conditions
- 3.1, 3.2, 3.3
- Stance
- complicates
- Relation
- differentiates
- Strength
- supporting
- Overlap flag
- prior_art
Formulates what it calls authorization continuity: whether an existing grant remains valid as a long-lived agent evolves after deployment by retaining experience, acquiring skills and tools, revising workflows, delegating work, and moving across task phases. States that evolution can change both the effects reachable under an old grant and the authority a task requires, and that the required authority may rise, fall, or become incomparable; existing tool policies constrain actions but do not determine when a grant survives this change. Proposes a state-bound model that fixes a transition envelope and an immutable effect ceiling at grant time, distinguishes requested from realized effects, and proves that under complete mediation, sound effect abstraction, attenuating delegation, and monitor integrity, mutation cannot amplify protected effects beyond the user-issued ceiling; agent-produced evidence may allocate authority below the ceiling but cannot raise it, which places the derivation of any additional authority under an evidence condition and bears on condition 3.2. The source's authorization continuity is scoped to grant survival under agent mutation. Vocabulary in use that overlaps AOI's: authorization continuity, authorization drift, admission, effect ceiling. Bears on CD, AC, and conditions 3.1 through 3.3.
Original linke039
ChainCaps: Composition-Safe Tool-Using Agents via Monotonic Capability Attenuation
Permalink- Source
- arXiv 2605.26542 (Jiang et al.; AIWILD workshop, ICML 2026)
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026-05
- Claims
- AC, RA
- Conditions
- 3.3, 3.5
- Stance
- complicates
- Relation
- complements
- Strength
- supporting
- Overlap flag
- prior_art
Names permission laundering: an agent can satisfy every per-tool permission check and still produce an unsafe end-to-end effect, because a restricted value is transformed, mixed, or rewritten before reaching a sink it should not reach. Enforces a runtime invariant in which every value carries a sink-specific authority budget and tool composition propagates budgets by intersection, so a value may lose but never gain authority through composition; states and proves a non-amplification theorem to that effect. Implemented as a transparent MCP proxy requiring no change to agent or tool servers; reports attack success falling from 25-68 percent to 0-4.8 percent across five frontier models on an 82-task suite, with manifest authoring quality, not runtime overhead, identified as the binding deployment constraint. The mechanism governs authority attenuation across a composed tool chain within a session rather than change in an agent's effective ability to produce consequences over time. The paper positions itself as complementary to execution-boundary mechanisms, which it says constrain execution while ChainCaps constrains the authority of derived values. Vocabulary in use that overlaps AOI's: monotonic capability attenuation, authority propagation, declassification. Bears on AC, RA, condition 3.5, and the compositional material in Appendix C.4.
Original linke042
Sovereign Execution Broker: Enforcing Certificate-Bound Authority in Agentic Control Planes
Permalink- Source
- arXiv 2606.20520
- Source type
- research
- Primary or secondary status
- Primary
- Domain
- Runtime
- Published
- 2026-06-19
- Claims
- RA, AC, GE
- Conditions
- 3.1, 3.3
- Stance
- complicates
- Relation
- differentiates
- Strength
- supporting
- Overlap flag
- prior_art
Execution-side companion to e041. Defines a runtime enforcement boundary that consumes certificates issued by the assurance boundary, verifies that the requested mutation matches the certified execution contract, checks validity windows, policy epochs, revocation epochs, and live-state drift, mints a scoped execution identity, invokes infrastructure APIs, and records signed decision and outcome records. States that production mutation authority should not reside inside non-deterministic reasoning processes, and separates proposal, admission, and execution so that certified authority becomes a short-lived, revocable, auditable runtime capability. Prototype evaluated on AWS and Kubernetes clusters. The live-state drift check compares infrastructure state at execution against the certified contract; it is not a comparison of retained authority against current organizational circumstances, and the entry is therefore not tagged AD. Vocabulary in use that overlaps AOI's: certificate-bound authority, execution broker, live-state drift, signed decision records, revocation epoch. Bears on RA, AC, GE, and the grant-to-effect interval.
Original linke043
Responsibility for operational control and dispatch release: joint authority, continuous re-release, and non-delegable dispatch
Permalink- Source
- eCFR - 14 CFR 121.533, with 121.663 (US Federal Aviation Administration)
- Source type
- regulatory
- Primary or secondary status
- Primary
- Domain
- Aviation
- Published
- 1964-12-31, as amended 1996-01-26
- Claims
- EL, AC, GE
- Conditions
- 3.1, 3.3
- Stance
- supports
- Relation
- supports
- Strength
- foundational
- Overlap flag
- none
Governance analogue from aviation regulation, not a doctrinal claim about software agents. The certificate holder is responsible for operational control; the pilot in command and the aircraft dispatcher are jointly responsible for preflight planning, delay, and dispatch release, and under 121.663 both must sign the release and may do so only if both believe the flight can be made with safety. Authority is not settled at release: the dispatcher must monitor the progress of each flight, issue information necessary for its safety, and cancel or redispatch if either the dispatcher or the pilot in command judges that the flight cannot continue to operate safely as planned or released. 121.663 further provides that a dispatcher may delegate authority to sign a release for a particular flight but may not delegate the authority to dispatch. Establishes a long-standing regulatory precedent separating conferred authority, delegable and non-delegable components, evaluation against current conditions, continuing responsibility after release, and a signed record of the determination. Bears on EL, AC, and the grant-to-effect interval; the signed release is an evidence artifact bearing on GE.
Original link