dynamic-capability-scoping-for-enterprise-ai-agents-a-synthetic-dataset-and-three-source-permission-architecture-c03d6541·1 events·first seen Aliases: Dynamic Capability Scoping for Enterprise AI Agents: A Synthetic Dataset and Three-Source Permission Architecture
A new arXiv preprint proposes a dynamic least-privilege architecture for enterprise AI agents, replacing static credential sets with a three-source system combining role-based ceilings, task-context classifiers, and policy-derived combination prohibitions. The authors release a synthetic dataset of 600 enterprise task prompts labeled with minimum required permissions across a 15-permission taxonomy, validated with high inter-rater agreement (Cohen's κ = 0.967 post-review). The architecture supports both enforced and observe-only deployment modes, with the latter generating behavioral signals for misalignment research. The work addresses the over-privilege problem in agentic deployments, where persistent broad credentials expand attack surface regardless of model reasoning quality.