three-source-permission-architecture-7499d86c·1 events·first seen Aliases: three-source permission architecture
A new arXiv preprint proposes a dynamic least-privilege architecture for enterprise AI agents, replacing static credential sets with a three-source system combining role-based ceilings, task-context classifiers, and policy-derived combination prohibitions. The authors release a synthetic dataset of 600 enterprise task prompts labeled with minimum required permissions across a 15-permission taxonomy, validated with high inter-rater agreement (Cohen's κ = 0.967 post-review). The architecture supports both enforced and observe-only deployment modes, with the latter generating behavioral signals for misalignment research. The work addresses the over-privilege problem in agentic deployments, where persistent broad credentials expand attack surface regardless of model reasoning quality.