Agentic Effectuation Boundary and Execution-Finality Architecture
Authors/Creators
Description
Abstract
As autonomous AI agents increasingly receive delegated authority to execute API mutations, settle financial payments, manage critical power grids, control robotic systems, and modify enterprise infrastructure, existing security architectures reveal a critical effectuation-boundary gap. Prevailing mechanisms—such as OAuth 2.0 delegation, Rich Authorization Requests (RAR), sender-constrained DPoP keys, transaction tokens, and RATS remote attestation—focus primarily on access permissions, key possession, token propagation, and execution-environment trustworthiness. However, these building blocks do not verify whether the exact consequential operation remains authorized at the specific commit instant.
An approved operation can become unsafe between planning and execution due to parameter substitution, stale external prerequisites, delegation expansion, policy epoch advances, replay races, or unmediated alternate-path bypasses. This specification defines an execution-finality architecture that addresses this vulnerability.
Under this framework, a proposed Candidate Act remains held in a strictly Non-Effective State. A protected enforcement point generates an act-bound Execution Handle cryptographically tied to the canonical parameters, policy epochs, anti-replay nonces, and the intended consequence boundary. Mediation terminates at a mandatory Finality Sink—such as a payment adapter, industrial interlock, motion-command gate, or database commit boundary—which independently reconstructs the live act, revalidates mutable dependencies, ensures path completeness, and executes an atomic check-and-consume commit. Missing or unverifiable lineage is treated as UNKNOWN and fails closed. Across diverse domains, the architecture guarantees that autonomous computation, valid credentials, and platform attestation alone do not constitute authority for irreversible physical or systemic consequence.
FLOW CHART
[ Autonomous Model / Agent Workspace ]
│
│ Proposes exact Candidate Act
▼
┌─────────────────────────┐
│ Non-Effective State │ ◄── Strictly held from effect
└────────────┬────────────┘
│
│ Protected validation (Identity, RAR, RATS, Policy)
▼
┌─────────────────────────┐
│ Execution Handle │ ──► [ Act Digest + Nonce + Epoch + Sink ID ]
└────────────┬────────────┘
│
│ Evaluated at boundary
▼
┌─────────────────────────┐
│ FINALITY SINK │ ◄── Reconstructs live act parameters
│ (Command / Commit Gate) │
└────────────┬────────────┘
│
[ Atomic Check-and-Commit ]
│
┌───────────┴───────────┐
Pass │ │ Fail / Stale / Unknown
▼ ▼
┌──────────────┐ ┌──────────────┐
│ IRREVERSIBLE │ │ FAIL-CLOSED │
│ EFFECTUATION │ │ (BLOCK) │
└──────────────┘ └──────────────┘
Series information
References
Primary Specification
-
draft-das-agentic-effectuation-boundary-00: Das, S., "When AI Agents Hold the Keys: Threat Model and Execution-Finality Requirements for Autonomous High-Consequence Systems", Internet-Draft, Individual Submission, September 19, 2026.
Standards & RFC References
-
RFC 8705: Campbell, B., Bradley, J., Sakimura, N., and T. Lodderstedt, "OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens", RFC 8705, February 2020.
-
RFC 9110: Fielding, R., Nottingham, M., and J. Reschke, "HTTP Semantics", RFC 9110, June 2022.
-
RFC 9334: Birkholz, H., Thaler, D., Richardson, M., Smith, N., and W. Pan, "Remote ATtestation procedureS (RATS) Architecture", RFC 9334, January 2023.
-
RFC 9396: Lodderstedt, T., Richer, J., and B. Campbell, "OAuth 2.0 Rich Authorization Requests", RFC 9396, May 2023.
-
RFC 9449: Fett, D., Campbell, B., Bradley, J., Lodderstedt, T., Jones, M., and D. Waite, "OAuth 2.0 Demonstrating Proof of Possession (DPoP)", RFC 9449, September 2023.
-
RFC 9700: Lodderstedt, T., Bradley, J., Labunets, A., and D. Fett, "Best Current Practice for OAuth 2.0 Security", RFC 9700, January 2025.
-
RFC 9711: Lundblade, L., Mandyam, G., O'Donoghue, J., and C. Wallace, "The Entity Attestation Token (EAT)", RFC 9711, April 2025.
-
draft-ietf-oauth-transaction-tokens: Tulshibagwale, A., Fletcher, G., and P. Kasselman, "Transaction Tokens", Work in Progress,
draft-ietf-oauth-transaction-tokens-11, July 2026.
Public Disclosures and Repositories
-
The Internet Solved Communication. It Never Solved Authority.: Zenodo Technical Disclosure, DOI: 10.5281/zenodo.22082995.
-
Execution-Finality Architecture for Machine-Generated Acts: Reference Architecture Implementation Repository.
-
tool_use Is Not invoke(): Runnable Agentic Tool-Call Reference Implementation: Agentic Tool-Call Interfaces & MCP Reference Implementation.
Industry Platform References
-
OpenAI: Introducing the Agents API.
-
Anthropic: Introducing Claude Sonnet 5.
-
Microsoft: Design autonomous agent capabilities (Copilot Studio).
-
Google Cloud: Vertex AI release notes (Agent Engine & A2A).
-
NVIDIA: NVIDIA Isaac (Autonomous Robotics Platform).
Files
Full-Technical Disclosure -draft-das-agentic-effectuation-boundary-00.xml
Files
(69.5 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:d857aff0310e272a0b697f93165c776d
|
69.5 kB | Preview Download |