Authorization Revocation for Long-Running AI Agents: Root-Scoped Quiescence under Delegation and Asynchronous Execution
A root-scoped quiescence protocol revokes authorization for long-running AI agents across delegation, queues, and late effects.
The paper defines root-scoped authorization quiescence for long-running AI agents whose credentials, delegated tasks, queues, callbacks, and provider-side operations outlive the initiating process. The protocol linearizes a root cut, fences old-root expansion and protected sinks, represents authority as antichains of minimal sufficient root sets, and composes provider certificates over registered old-root paths. Under stated assumptions, the authors prove post-cut non-expansion, compositional soundness, independent-support preservation, and crash/replay stability. A late-effect suite matched 17 of 17 outcomes, and a separate checker verified 17 of 17 traces while rejecting 44 of 44 rehashed regressions; cancellation-only runs still accepted already scheduled late effects.
- Cancellation and credential revocation leave scheduled late effects on long-running agents.
- Root-scoped quiescence fences old-root expansion and accounts for every cut-relevant acceptance.
- Proofs cover non-expansion, compositional soundness, and crash/replay stability.
- A checker verified 17 of 17 traces and rejected 44 of 44 semantic regressions.
Full article218 words · extracted from arxiv.org · click to collapse
Long-running AI agents outlive initiating processes through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations. Cancellation, process exit, and credential revocation neither close every pre-cut carrier nor distinguish independently authorized shared work. We define root-scoped authorization quiescence: for each manifested sink, a certificate accounts for every cut-relevant acceptance under the retired root-epoch atom that precedes its local fence and excludes protected acceptance under that atom after the fence, while permitting exact rebind to a current, independently sufficient support. The root-scoped quiescence protocol linearizes a root cut, fences old-root expansion and protected sinks, represents alternative and conjunctive authority as antichains of minimal sufficient root sets, and composes provider-frontier certificates into a cutset over registered old-root paths. Exact channel-token accounting reconciles transfers; missing or conflicting evidence remains indeterminate. Under stated assumptions, we prove post-cut issuer non-expansion, support-sound projection, compositional soundness under exact channel conservation, independent-support preservation, merge-order independence, and crash/replay stability. A provider-free late-effect test suite matches 17/17 registered outcomes. Two cancellation-only and one cut-only execution accept the same class of already scheduled late effect; two cut-plus-fence executions, one restart, and one stale-process execution reject it. A separately implemented checker verifies 17/17 traces and rejects 44/44 consistently rehashed semantic regressions. The certificate establishes root-relative authorization quiescence within its bound manifest and configuration, not global idleness, rollback, or business completion.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.21284