CURRENT AUTHORITY
Every execution uses current identity, delegation and resource scope.
Authorization is re-evaluated for dispatch, handoff, retry and resume. Agent identity, the human or workload principal and delegation remain distinct records.
POLICY + GUARDRAILS + APPROVAL
Identity, authorization, policy, native guardrails, approval, budget, tool dispatch and official audit are separate control layers. High-impact actions move from proposal to evidence through explicit gates that the model cannot bypass.
The model proposes work; platform controls determine whether work can become an external effect.
CURRENT AUTHORITY
Authorization is re-evaluated for dispatch, handoff, retry and resume. Agent identity, the human or workload principal and delegation remain distinct records.
POLICY + GUARDRAILS
Provider adapters can change while platform-native authority remains stable. External content never becomes trusted platform instruction simply because it came from an internal source or another agent.
HUMAN APPROVAL
Where required, approval references the exact operation, target, arguments, purpose and validity window. A generic UI confirmation cannot authorize a different payload later.
OFFICIAL EVIDENCE
Critical task, delegation, policy decision, approval and external effect records correlate to the same execution while sensitive content stays minimized.