Ordering Is Not Resolution: What the Instruction Hierarchy Defines, What It Leaves Undefined, and the Same-Tier Conflicts Agent Benchmarks Do Not Separate
Description
(c) 2026 Pranay Mahendrakar. Licensed under CC BY 4.0.
When a language-model agent receives instructions that conflict, the dominant remedy is a privilege ordering over sources: system above developer, developer above user, user above tool output. This paper argues that the ordering paradigm is well-defined for one class of conflict and undefined for another, and that published benchmarks and training sets do not separate the two. A conflict between instructions carrying different privilege labels has an answer the paradigm can state; a conflict between two instructions carrying the same label does not, because an ordering over privilege levels does not induce an ordering among the instructions inside a level. The second class is not hypothetical. One profiler of real deployed prompt policies reports that across thirteen thousand jointly governed trials, only about a third of cases satisfy both of two individually reasonable standing rules. Multi-principal deployments, where two users hold equal authority, instantiate the same structure by construction. The paper distinguishes three failure classes that the single phrase "instruction hierarchy failure" currently covers, argues that reported hierarchy-compliance numbers are sums over classes with different remedies, and states what a same-tier resolution rule would have to supply that an ordering does not. The case for the ordering paradigm is presented first and is not weak: several recent results report large, transferable gains from training on ordering. Nine studies that would settle the open parts are named. No experiments are reported here, and the strongest case against this paper's own position is stated in full.
The literature search, drafting and citation verification for this paper were carried out with AI assistance under the author's direction. Every citation was machine-verified against the arXiv API and Crossref before inclusion, and every quantitative claim was read back against the cited source's own abstract. The author is responsible for the final text and for all claims made in it.
Files
ordering-is-not-resolution.pdf
Files
(417.7 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:a2bf84beab8620a523ce8eb6ad027c1e
|
417.7 kB | Preview Download |