Authorization survey of 89 sources lays out a five-tier principal hierarchy for agent delegation and names runtime enforcement as the unsolved part
A September 14 arXiv survey reviews 89 primary sources from roughly 180 candidates published 2023-2026, organizing agent authorization around a principal hierarchy spanning human user, operator/deployer, orchestrator agent, sub-agent and tool endpoint. It covers agent identity and credential lifecycle, delegation and scope propagation across multi-hop chains, just-in-time runtime enforcement, prompt injection treated as an authorization bypass rather than a content problem, and auditability and non-repudiation. Output is seven structural requirements, a four-layer reference architecture and three deployable reference configurations, with runtime enforcement and aggregation bounds flagged as still open.
Source
↳ Follow the thread