← Back to Insights
Briefing · Agent Governance · August 2026 refresh

Control the Full Authority Path, Not Just the Agent

A client-ready operating model for mutable instructions, delegated identities, receiving-system authorization, and a stop path that reaches every action channel.

Conditional sign-off verdict

It is safe to say yes only when the full authority path is inspectable: which instructions the agent trusted, what authority each child inherited, which receiving system accepted the action, and whether one stop path actually closed every route.

The operating model

Observe

The agent reads or watches. Evidence needs to show what it accessed and why.

Advise

The agent drafts or recommends. A person still decides, sends, spends, or changes the record.

Act with approval

The agent prepares the action, but a named approver confirms before the system changes anything consequential.

Narrow autonomy

The agent acts inside a pre-approved boundary with monitoring, rollback, and kill-switch authority.

Owner, authority path, proof

Owner

A named operator accountable for the job, data diet, dependencies, permissions, review loop, response, and retirement.

Authority path

A record linking approved instruction versions, parent and child identities, credentials, routes, queues, targets, and suspension owners.

Proof

A receipt that binds instruction provenance, delegation, receiver policy, approval, action, revocation, and recovery evidence.

What leaders should take from it

1
Ownership now includes dependencies and descendants.

The operating owner needs the external instruction sources, child identities, tokens, routes, sessions, and targets that sit inside the agent's effective authority.

2
An approved skill is not always a stable object.

A local package can load mutable documentation or examples after review. Pin what was accepted, inventory remote sources, detect change, and make reapproval a lifecycle state.

3
Delegated authority should get narrower, not wider.

Each child needs no broader and preferably shorter-lived authority than its parent, with immutable delegation identifiers preserved in the receipt.

4
The receiving system must decide for itself.

The target validates identity, token audience, object, action, scope, freshness, current policy, and any required human approval. Upstream ownership is not receiver authorization.

5
A kill switch is a tested population and channel proof.

Disabling one orchestrator does not prove that child identities, API keys, cached tokens, queues, webhooks, and target sessions have stopped.

Where the evidence stops

The reviewed evidence proves attack mechanics, real malicious registry entries, and implementable identity and authorization primitives. It does not establish enterprise install prevalence, a coordinated swarm loss class, a universal legal design mandate, or causal governance ROI. Treat the added controls as proof obligations, not promised risk reduction.

First moves before hiring anyone

01
Expand the operating card into an authority-path record.

Add approved skill versions, remote instruction sources, parent and child identities, credentials, routes, queues, targets, evidence custody, and the authority that may suspend each link.

02
Treat skill approval as a lifecycle state.

Distribute accepted skills from a versioned source, pin exact artifacts, inventory remote fetches, detect changes, and require review before changed instructions regain trust.

03
Make receiver authorization independent.

At every consequential action, the target validates the agent, token audience, object, action, scope, freshness, policy, and any approval. Reject missing delegation context.

04
Design revocation across the graph.

Cover the parent, descendants, tokens, API keys, routes, queued work, target sessions, new delegation, evidence preservation, and the incident authority who can invoke the stop.

05
Run one authorized four-assertion drill.

In an isolated environment, with written rules from every affected owner and approved synthetic data, prove separately that instruction drift is detected, a pre-authorized negative test is rejected, revocation reaches every tested channel, and the receipt reconstructs the full path.

Where to start

Start with one consequential agent and one authorized failure drill. If any assertion fails, repair that control plane before widening authority, population, or receiving-system scope.

Claim ledger

31/31
Checked
citation clusters traced to primary or strongest reachable sources
0
Fabricated
no invented source clusters found
12
Corrected
wording narrowed after source review
4
Demoted
useful signals kept out of the headline
ConfirmedEU AI Act: high-risk systems require logs, oversight, documentation, accountability, incident procedures, and deployer obligations.eur-lex
CorrectedNIST AI 600-1: useful role, inventory, testing, monitoring, incident, and deactivation guidance, but voluntary rather than binding.nist.gov
ConfirmedFINRA 2026 GenAI guidance: existing supervision, recordkeeping, monitoring, model-version, prompt/output, human-review, and agent guardrail expectations apply.finra.org
ConfirmedSR 11-7: older model-risk pattern supports inventory, validation, governance, audit, documentation, and effective challenge.federalreserve.gov
ConfirmedISO/IEC 42001: AI management-system framing supports traceability, transparency, risk management, and continuous governance.iso.org
ConfirmedDelegated execution research: standard traces may not identify delegation scope; delegation context needs to bind at execution time.arxiv.org
ConfirmedAuditable Agents research: accountability needs recoverable actions, lifecycle coverage, policy checks, responsibility attribution, and evidence integrity.arxiv.org
ConfirmedOverlaying Governance research: current IAM/OAuth patterns are too static for recursive delegation and dynamic scopes.arxiv.org
DemotedGoverned AI-Assisted Engineering: oversight tiers and velocity-preservation claims are analytic modeling, not measured enterprise acceleration.arxiv.org
CorrectedGartner agentic AI forecast: cancellation and 2028 forecast points verified; exact vendor-count details treated as secondary-reported.gartner.com
DemotedIBM CIO/CTO figures: governance-gap, incident, and deployment-multiple figures are vendor-survey signals through accessible reporting.itpro.com
DemotedCSA/Aembit identity survey: useful directional signal on AI-vs-human activity, but vendor-sponsored and reached through secondary reporting.itpro.com
ConfirmedSEC AI-washing settlements: Delphia and Global Predictions settled charges tied to misleading AI claims.sec.gov
ConfirmedAir Canada chatbot case: reporting shows the company was responsible for misleading chatbot refund information.guardian
DemotedReplit incident: strong reported failure case, but not an official postmortem or regulatory finding.businessinsider
CorrectedEchoLeak / CVE-2025-32711: Microsoft 365 Copilot vulnerability confirmed; no verified in-the-wild victim harm found.arxiv.org
CorrectedAnthropic skill guidance: review less-trusted dependencies and external-source instructions, but scanning has material exclusions and is no safety guarantee.anthropic
ConfirmedBroadcom ClawHub report: Koi Security found 341 malicious skills in the cited audit set, most attributed to ClawHavoc.broadcom
CorrectedAIR skill experiment: a vendor demonstration changed external documentation after marketplace acceptance and scanner clearance; reach and outcome are self-reported.air.security
CorrectedSkill-poisoning preprint: 1,070 generated attack samples support plausibility, not registry prevalence; bypass includes malicious generation without execution.arxiv.org
CorrectedAgent-skill governance preprint: controlled local variants from real benign skills support simulated attack plausibility, not live victim impact.arxiv.org
CorrectedMicrosoft Entra Agent ID: blueprint and class controls exist, while agent-user accounts, API keys, and some exchange steps need separate treatment.microsoft
ConfirmedMCP HTTP authorization: the receiving server validates token, audience, validity, and resource, and uses a separate token upstream.mcp
ConfirmedAWS source identity: delegation context can persist through role chaining and support downstream policy, with documented service-action limits.aws
ConfirmedGitHub supply-chain controls: full commit-SHA enforcement and immutable releases offer useful analogues, not agent-skill requirements.github
ConfirmedNIST zero trust: location or ownership confers no implicit trust; descendant-agent application is this report's analogy.nist.gov
CorrectedNIST CAISI: 57% one-try average and 80% across 25 retries in simulated tasks; neither is a production incident rate.nist.gov
CorrectedUK AISI competition: 1.8 million prompts and more than 62,000 simulated policy violations; the 10-to-100-query result belongs to a separate curated benchmark.aisi.gov.uk
CorrectedNIST NCCoE concept: exploratory draft project framing, not a descendant-graph or cascade-revocation mandate.nist.gov
ConfirmedSEC Regulation S-P: covered institutions need incident response and service-provider oversight, but not categorically a written provider contract.sec.gov
CorrectedNYDFS Part 500: binding third-party and access duties; later downstream-provider and offboarding details are guidance that creates no new requirements.nydfs
What would change this conclusion

Related work

Verified research · 31/31 citation clusters checked · 0 fabricated · 12 corrected · 4 demoted