Predicate-Scoped Authority for Conflict Resolution Between Mutually Untrusted Agents

When autonomous agents from different trust domains exchange facts, those facts conflict, and a receiving agent must decide which value governs. We make two claims. First, predicate-scoped authority strictly generalises global per-principal authority: some predicate-scoped assignments, including any containing an authority inversion, are not representable by any global per-principal ranking, and independently authored benchmark policies contain such inversions. Second, when the authority class is derived at an authenticated boundary from the grants in force rather than read from the submission, a writer cannot raise its own class by asserting authority and so cannot displace a value held at a higher class, so long as that value remains eligible and at that class; a writer at the same class as the governing value can still displace it by writing later. We evaluate the first claim on tau2-bench’s three domain policies, transcribed into capabilities: the best per-principal ranking resolves only 70%, 50% and 60% of the governed predicates in each domain, while a ranking that may differ between recorded and requested values resolves all of them. On Flight, a data-fusion benchmark, scoping each operator’s capability to the predicates and subjects it actually operates (declared from source names, before any accuracy is computed) removes 2,421 and then 1,686 of 4,552 contested decisions over identical sources, records and labels; on Flight and on a second such benchmark, Stock, among sources holding no capability the ranking ceiling (0.500 on Flight, 0.312 on Stock) measures predicate-dependent reliability, an independent statistical analogue of the same limitation, not a second instance of the first claim. Against an over-asserting writer that forges authority inside its own later submission, none of the twenty-three governed predicates across the three policies is captured, with a falsification check confirming the harness can produce a capture when one is due. Placed unmodified as a gate on tool calls in AgentDojo, a promptinjection benchmark built by others, the resolver confines an injected request to the issued tool scope, a guarantee that follows from the issuing user’s own grant alone, but that benchmark tests neither claim directly: it does not test whether an in-scope invocation came from the user, and the user’s grant is uniform in the predicate. Separately, a rival in the user’s own instruction is found in only 10.4% and 11.4% of attacked runs on banking and slack. The transport and the idea of trust-based resolution are not new; the contribution is authority scoped to the predicate and derived at the boundary, evaluated on assignments the authors did not choose

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-05
DOI
https://doi.org/10.5281/zenodo.23169445
Primary Topic
Access Control and Trust
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Predicate-Scoped Authority for Conflict Resolution Between Mutually Untrusted Agents

Yao Elom Emmanuel Tsakpo
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
preprint

Predicate-Scoped Authority for Conflict Resolution Between Mutually Untrusted Agents

Yao Elom Emmanuel Tsakpo
preprint en

Abstract

When autonomous agents from different trust domains exchange facts, those facts conflict, and a receiving agent must decide which value governs. We make two claims. First, predicate-scoped authority strictly generalises global per-principal authority: some predicate-scoped assignments, including any containing an authority inversion, are not representable by any global per-principal ranking, and independently authored benchmark policies contain such inversions. Second, when the authority class is derived at an authenticated boundary from the grants in force rather than read from the submission, a writer cannot raise its own class by asserting authority and so cannot displace a value held at a higher class, so long as that value remains eligible and at that class; a writer at the same class as the governing value can still displace it by writing later. We evaluate the first claim on tau2-bench’s three domain policies, transcribed into capabilities: the best per-principal ranking resolves only 70%, 50% and 60% of the governed predicates in each domain, while a ranking that may differ between recorded and requested values resolves all of them. On Flight, a data-fusion benchmark, scoping each operator’s capability to the predicates and subjects it actually operates (declared from source names, before any accuracy is computed) removes 2,421 and then 1,686 of 4,552 contested decisions over identical sources, records and labels; on Flight and on a second such benchmark, Stock, among sources holding no capability the ranking ceiling (0.500 on Flight, 0.312 on Stock) measures predicate-dependent reliability, an independent statistical analogue of the same limitation, not a second instance of the first claim. Against an over-asserting writer that forges authority inside its own later submission, none of the twenty-three governed predicates across the three policies is captured, with a falsification check confirming the harness can produce a capture when one is due. Placed unmodified as a gate on tool calls in AgentDojo, a promptinjection benchmark built by others, the resolver confines an injected request to the issued tool scope, a guarantee that follows from the issuing user’s own grant alone, but that benchmark tests neither claim directly: it does not test whether an in-scope invocation came from the user, and the user’s grant is uniform in the predicate. Separately, a rival in the user’s own instruction is found in only 10.4% and 11.4% of attacked runs on banking and slack. The transport and the idea of trust-based resolution are not new; the contribution is authority scoped to the predicate and derived at the boundary, evaluated on assignments the authors did not choose

Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.