Execution-Time Authorization for AI Agents: A Formal Framework for Deterministic Governance Boundaries
Execution-Time Authorization for AI Agents formalizes execution-time authorization (ETA) as a deterministic governance boundary for AI agents and other autonomous systems whose proposed actions may produce real-world effects. The paper defines ETA as a deterministic runtime enforcement architecture that evaluates a canonicalized proposed action against declared, versioned policy and decision state before an in-scope effect may occur; emits an action-bound verdict; and couples execution to the applicable authorization condition, producing a tamper-evident authorization artifact intended to support independent reconstruction. A conforming ETA deployment must be assessed separately for Output Integrity, Input Integrity, and Replay Integrity under the Authorization Boundary Integrity Model (ABIM); the definition is an implementation model, not a completeness test. The paper distinguishes ETA from adjacent categories often mistaken for governance enforcement, including guardrails, alignment techniques, identity and access management, observability tooling, agent orchestration, and policy engines. These systems may provide useful safety, visibility, policy-evaluation, or coordination functions, but do not by themselves constitute execution-time authorization unless they operate at a runtime boundary that is non-bypassable within a declared execution topology, never produce ALLOW on failure, and emit an authorization artifact with authenticated bound materials sufficient for verdict reconstruction under a declared replay mode. The product label is not dispositive in either direction: a guardrail-labeled product may implement authorization where its demonstrated architecture satisfies the applicable requirements. The formal model specifies the authorization function over the declared decision-time state (comprising the governed-state commitment, the material evidence set with its applicable admissibility conditions, authority and revocation state, and the temporal boundary), verdict semantics, determinism within the declared decision state, canonicalization, fail-closed behavior, non-bypassability across declared covered effect-producing paths, artifact and bound-materials sufficiency, replayability under the 5TS replay modes (State-Replay and Protocol-Replay), time-bounded evaluation without fail-open behavior, state freshness with release binding, and a first-class Input Integrity and admissibility invariant: the evaluator must identify the material evidence set and enforce the applicable admissibility conditions at decision time, because provenance establishes origin and origin alone does not establish admissibility. The verdict space is ALLOW, DENY, and ABSTAIN. ABSTAIN blocks execution unless and until authorized resolution produces a separate resulting action-bound verdict through the boundary; the original verdict does not convert. Failure, timeout, missing evidence, or ambiguity must not produce ALLOW; the governing policy determines whether the boundary emits DENY or ABSTAIN. The paper retains its structured relationship to access-control and policy-evaluation prior art, including the reference-monitor tradition, complete mediation and fail-safe defaults, XACML PDP/PEP architecture, OPA/Rego, Cedar, Zanzibar, and proof-carrying code. ETA does not claim to invent access mediation, policy decision points, or proof-carrying evidence. It defines a specific architectural composition: a runtime authorization boundary that holds a concrete action instance before the covered effect, binds the verdict to policy, decision state, and canonical action representation, fails closed absent affirmative authorization, and emits an authorization artifact suitable for independent reconstruction. State freshness and release binding address time-of-check-to-time-of-use risk: the governed state must remain valid at release, and the action released must be canonically equivalent to the action authorized, with the release gate closed until the boundary has emitted the verdict, produced the artifact, and validated the release conditions binding that verdict to the action presented for execution. The framework is aligned with the current FERZ instrument set: the Authorization Artifact Test v1.2 as threshold, ABIM v1.1 for the three integrity properties, the Five Tests Standard (5TS) v1.2.0 for the normative control vocabulary (Stop, Ownership, Replay, Escalation, Provenance), the ABIM Evidence Requirements v3.5 for the evidence-conclusion vocabulary (the evidence supports the claim, a failure witness defeats it, or the claim is not established), the Closed-World Bargain v1.1, and the Override Asymmetry v2.2. Proof-Carrying Decisions (PCDs) remain the 5TS implementation form of the authorization artifact, not a replacement for the canonical authorization-artifact vocabulary. The former conformance-test section is recast as implementation assessment procedures: findings are recorded within declared scope and do not issue aggregate ABIM determinations, 5TS conformance claims, or authorization-infrastructure conclusions. Version 3.1 (September 2026) is a correction release. It replaces the Section 1 characterization attributed to The Authorization Boundary with the access-authorization versus action-authorization formulation that paper states; replaces the closing sentence of Section 3.4, which miscited its source and described ABSTAIN as a transfer of authority, so that ABSTAIN records that no definitive verdict has been established and preserves the hold pending authorized resolution; corrects Section 5.4 so that the discriminator between observability and execution-time authorization is material consumption and execution dependency rather than timing; tightens the Section 5.5 orchestration sentence; replaces the product-timed signature-grade phrasing in Section 4.4 with the vendor-neutral formulation; updates the citation pins for the AI Governance Taxonomy (v1.7.1), The Authorization Boundary (v3.1), and The Override Asymmetry (v2.2); and records the concept and version DOIs on the title page. No formal definition, invariant, or conformance criterion is changed. It supersedes Version 3.0 (August 2026), recorded below. Version 3.0 (August 2026) revises the canonical definition so that ETA is a runtime enforcement architecture assessed separately under ABIM; scopes mediation to declared covered effect-bearing topology; conditions determinism on the declared decision state; adds the Input Integrity and admissibility invariant; adopts the reconstruction and replay-mode vocabulary; revises override semantics per the Override Asymmetry and the ABIM Evidence Requirements; recasts the conformance tests as implementation assessment procedures with the tripartite evidence-conclusion vocabulary; qualifies deployment-pattern and product-label claims; updates references to the current instrument editions; and revises the conclusion to contingent completeness: ETA supplies the runtime enforcement architecture through which a complete authorization boundary may be realized, with completeness contingent on demonstrated Output, Input, and Replay Integrity within a declared scope. It supersedes Version 2.1 (July 2026), which corrected citation alignment and canonicalization equivalence, and Version 2.0, which introduced the prior-art section and the state-freshness and release-binding extension.
Authors
- Edward Meyman
Institutions
- Ferghana Polytechnical Institute (UZ)
- Ferro (United States) (US)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-02
- DOI
- https://doi.org/10.5281/zenodo.18764561
- Citations
- 22
- Primary Topic
- Access Control and Trust
- Type
- article
- Field-Weighted Citation Impact
- 360.29