All research systems
WarrantActive

How can agents verify delegated authority across organizational boundaries?

Question → hypothesis/design → architecture → evaluation → results → limitations → next questions

Motivation

A local policy decision does not by itself establish authority to a different organization.

Hypothesis

Scoped signed grants with explicit issuer trust and fresh proof of possession can make delegation independently checkable.

Architecture

  • Ed25519-signed, scoped and expiring grants
  • Issuer-key resolution and optional revocation checks
  • Fresh holder possession proof at verification

Evaluation methodology

Implementation and threat-model review are documented in the repository. No cross-organization deployment benchmark is claimed here.

Results

Evaluation in progress

Limitations

  • A grant alone is a bearer credential without fresh possession proof
  • Issuer trust and revocation policy remain explicit deployment responsibilities

Current status

An implemented delegation component in Agent Rails; production adoption is not established here.

Roadmap

  • Evaluate delegation and revocation failure cases across trust boundaries

Next questions

  • How should availability and revocation freshness trade off?