Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure
A new academic paper submitted to arXiv addresses a critical security challenge in multi-agent artificial intelligence systems known as authorization propagation. The author, Krti Tallam, argues that current security discussions overly focus on prompt injection, neglecting the distinct problem of maintaining authorization invariants as non-human agents retrieve data, delegate tasks, and synthesize results across dynamic boundaries. The study formalizes this issue as a workflow-level property, identifying three specific sub-problems: transitive delegation, aggregation inference, and temporal validity. It asserts that classical access-control models like RBAC, ABAC, or ReBAC are insufficient for these complex interactions. The paper derives seven structural requirements for robust authorization architectures and highlights emerging solutions such as invocation-bound capability tokens and task-scoped authorization envelopes. Crucially, it posits that identity governance must be treated as fundamental infrastructure, enforced continuously at every interaction boundary before orchestration logic scales. Preliminary evidence from a production enterprise AI platform indicates that ordinary system behavior, rather than just adversarial attacks, already triggers the predicted authorization failures, underscoring the urgent need for integrated architectural solutions in agentic AI development.
Wire timeline
Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure
A new academic paper submitted to arXiv addresses a critical security challenge in multi-agent artificial intelligence systems known as authorization propagation. The author, Krti Tallam, argues that current security discussions overly focus on prompt injection, neglecting the distinct problem of maintaining authorization invariants as non-human agents retrieve data, delegate tasks, and synthesize results across dynamic boundaries. The study formalizes this issue as a workflow-level property, identifying three specific sub-problems: transitive delegation, aggregation inference, and temporal validity. It asserts that classical access-control models like RBAC, ABAC, or ReBAC are insufficient for these complex interactions. The paper derives seven structural requirements for robust authorization architectures and highlights emerging solutions such as invocation-bound capability tokens and task-scoped authorization envelopes. Crucially, it posits that identity governance must be treated as fundamental infrastructure, enforced continuously at every interaction boundary before orchestration logic scales. Preliminary evidence from a production enterprise AI platform indicates that ordinary system behavior, rather than just adversarial attacks, already triggers the predicted authorization failures, underscoring the urgent need for integrated architectural solutions in agentic AI development.
cs.AI updates on arXiv.org