Skip to content
Preprint

Runtime Authorization for Resources Acquired by AI Agents

Sep 2026 · 0 citations
Computer Science

TL;DR

A provenance-bounded runtime authorization architecture that quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a downward-closed relational envelope over a typed resource-capability hypergraph.

Abstract

By acquiring compute, credentials, accounts, services, and other agents, autonomous AI agents can introduce new authority into a task. Payment, budget, OAuth, mandate, and fulfillment checks can validate transaction conditions without deciding whether a returned resource may become usable authority. This post-fulfillment activation gap spans tool-mediated creation, inter-agent delegation, and agentic commerce. We present a provenance-bounded runtime authorization architecture. It quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a downward-closed relational envelope over a typed resource-capability hypergraph. The envelope preserves correlated identity, effect, data, delegation, and graph-wide limits. Single-use effect permits are revalidated and consumed at effect linearization. Under explicit assumptions, we prove eight safety properties covering quarantine, backing, non-amplification, split non-evasion, crash/retry, refunds, epochs, and effect confinement. Across five resource classes, reference semantics accepted 20/20 benign traces and rejected 40/40 registered unsafe traces over 810 events; an independent checker agreed on 60 base and 40 refinement traces and rejected 89/89 tamper tests. Frozen Codex and Gemini Model Context Protocol (MCP) client components completed 54/54 deterministic local stdio calls. In a registered 18-case staged MCP-to-Docker composition, both benign paths completed, and none of the 16 unsafe paths added an unauthorized Docker start request. A five-source audit classified 1,248 field pairs across 32 units; no unit alone supplied a complete activation profile.

View source

Similar papers

Preprint Aug 2026

AID-Guard: Stateful Authorization for Delegated Agent Effects

This work presents AID-Guard, a stateful authorization-to-effect closure protocol that revalidates the approved request and provider state at commit, retains one reservation under ambiguity, and permits release or one successor only after a terminal result or certified no effect with a delivery fence.

Yingzhe Tong, Le-Yu Dai, Song-Hui Guo · 8 citations
Preprint Aug 2026

A Policy Algebra for Trust-Preserving Agentic AI Execution

A policy algebra is proposed that defines the reliability envelope within which agent capability may be exercised and provides researchers and practitioners with formal correctness conditions, executable decision semantics, and trace evidence for building agents that are not only capable, but reliably capable.

Bhaskar Tripathi, Anurag Kumar, R. Kumar et al. · 0 citations
Preprint Aug 2026

A Contract-Centered Architecture for Scalable and Manageable Agentic Runtimes

A contract-bounded runtime architecture, a source-preserving data substrate, and a falsifiable measurement protocol are contributed, which proposes a cluster-period randomized crossover experiment with a four-state verdict: supported, falsified, conditional-engineering, or inconclusive.

Ya-Xiao Liu, Peng Liu, Yi-Wen Liu et al. · 0 citations
Preprint Aug 2026

Attesting Outputs and Delegation Ancestry in Multi-Agent AI Systems

Multi-agent applications delegate work across independently operated deployers. After an incident, a verifier must answer two questions: which deployer released the reported bytes, and whether each cross-deployer edge was authorized. Credentials establish who may act, but need not bind them to later output bytes or pro...

Li-Fei Liu, Hao-Ran Yu · 2 citations
#artificial intelligence Preprint Aug 2026

A Formal Analysis of Agent Payment Protocols

This work formalizes four representative agent payment protocols: x402, MPP, ACP, and AP2 in Tamarin, and constructs source-grounded models that capture each protocol's roles, state, trust assumptions, and lifecycle transitions.

Ke Jiang, Mo-Han Yu, Yuan-Yi-Chun-Min-Chieh Chang et al. · 0 citations
#artificial intelligence Preprint Sep 2026

ZeroGate: Trust-Preserving Fast Paths for Governed AI Agent Runtimes

A conditional decision-preservation proposition: successful local admission implies that a specified synchronous policy would authorize the same action at the admission point, provided approval is sound, all policy dependencies are represented and current, observations are faithful, and consumption is atomic.

Ze-Xu Wang · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.