Predicate-Scoped Authority for Conflict Resolution Between Mutually Untrusted Agents
When autonomous agents from different trust domains exchange facts, those facts conflict, and a receiving agent must decide which value governs. We make two claims. First, predicate-scoped authority strictly generalises global per-principal authority: some predicate-scoped assignments, including any containing an authority inversion, are not representable by any global per-principal ranking, and independently authored benchmark policies contain such inversions. Second, when the authority class is derived at an authenticated boundary from the grants in force rather than read from the submission, a writer cannot raise its own class by asserting authority and so cannot displace a value held at a higher class, so long as that value remains eligible and at that class; a writer at the same class as the governing value can still displace it by writing later. We evaluate the first claim on tau2-bench’s three domain policies, transcribed into capabilities: the best per-principal ranking resolves only 70%, 50% and 60% of the governed predicates in each domain, while a ranking that may differ between recorded and requested values resolves all of them. On Flight, a data-fusion benchmark, scoping each operator’s capability to the predicates and subjects it actually operates (declared from source names, before any accuracy is computed) removes 2,421 and then 1,686 of 4,552 contested decisions over identical sources, records and labels; on Flight and on a second such benchmark, Stock, among sources holding no capability the ranking ceiling (0.500 on Flight, 0.312 on Stock) measures predicate-dependent reliability, an independent statistical analogue of the same limitation, not a second instance of the first claim. Against an over-asserting writer that forges authority inside its own later submission, none of the twenty-three governed predicates across the three policies is captured, with a falsification check confirming the harness can produce a capture when one is due. Placed unmodified as a gate on tool calls in AgentDojo, a promptinjection benchmark built by others, the resolver confines an injected request to the issued tool scope, a guarantee that follows from the issuing user’s own grant alone, but that benchmark tests neither claim directly: it does not test whether an in-scope invocation came from the user, and the user’s grant is uniform in the predicate. Separately, a rival in the user’s own instruction is found in only 10.4% and 11.4% of attacked runs on banking and slack. The transport and the idea of trust-based resolution are not new; the contribution is authority scoped to the predicate and derived at the boundary, evaluated on assignments the authors did not choose
Authors
- Yao Elom Emmanuel Tsakpo (ORCID: https://orcid.org/0009-0000-6523-9694)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-05
- DOI
- https://doi.org/10.5281/zenodo.23169445
- Primary Topic
- Access Control and Trust
- Type
- preprint