Introduces a provenance-bounded activation mechanism that closes the post-fulfillment gap when autonomous agents acquire new authority via payments, credentials, or inter-agent delegation.
AcquireBound is a provenance-bounded runtime authorization architecture that closes the post-fulfillment activation gap by quarantining acquired resources and validating their actual capabilities before granting authority. It employs a downward-closed relational envelope over a typed resource-capability hypergraph to enforce strict lineage, epoch, and delegation limits, ensuring that transaction-side evidence (like payments or OAuth) does not implicitly authorize potentially dangerous outcomes like administrator credentials. The system utilizes single-use effect permits and atomic linearization to prevent unauthorized Docker starts, credential misuse, or unsafe inter-agent delegation across five resource classes.
Runtime Authorization for Resources Acquired by AI Agents addresses a security gap that becomes prominent when autonomous agents are allowed to act on their own: an action that acquires a resource can also create new authority, but traditional authorization checks often stop at the moment before the action is performed. The paper frames this as a post-fulfillment problem. Once an agent completes a payment, receives a credential, or is delegated authority by another agent, the resulting capability may become immediately usable even though no fresh policy decision has been made about whether that newly acquired authority should actually be activated. The material proposes a provenance-bounded activation mechanism in which newly acquired resources are not treated as automatically granted; instead, their activation is conditioned on the provenance record of how they were obtained and on runtime constraints such as scope, principal identity, transaction context, expiration, and revocation state.
The key contribution is a runtime authorization model that treats acquisition events as first-class inputs to the authorization decision. By binding each capability to its origin—such as a payment transaction, credential issuer, or delegating agent—and enforcing policy bounds at activation time, the mechanism prevents stale, overbroad, or improperly chained authorities from becoming usable. This is especially relevant in multi-agent environments, where one agent’s delegated authority may be further delegated, where credentials can be minted dynamically, and where economic or contractual actions create entitlements that must remain tightly scoped. In effect, the approach shifts the security question from “was the agent allowed to perform the acquisition?” to “is the newly acquired authority still valid, properly bounded, and consistent with the provenance that produced it?”
The work matters because autonomous agents that pay, sign, delegate, and consume resources require continuous assurance rather than point-in-time permission checks. A provenance-bounded activation mechanism gives system designers a concrete way to implement least-privilege, auditable, and revocable agent capabilities in agentic commerce, cloud APIs, delegated workflows, and federated agent ecosystems. Its broader significance is that it closes a practical gap in agent security: ensuring that the authority an agent gains through action is no more powerful, persistent, or transferable than the action and policy context that produced it.