Same Tool Call, Different Authorization: Policy-Sufficient Graphs for Agents
Abstract
With rules and workloads fixed across three typed agent deployments, exposing predecessors raises policy-laundering blocking from 82.4% to 95.1% and persistent-compromise blocking from 87.6% to 95.4%; binding the approved object to execution raises them further to 98.2% and 98.6%. The mechanism is an information collision: a benign plan and a secret- or attacker-dependent plan can terminate in the same byte-identical privileged call, so current-call authorization must give both the same decision. Policy sufficiency formalizes the missing information. The resulting policy-footprint characterization gives the coarsest equivalence induced by typed capability, provenance, and secret-flow clauses; it proves a terminal-projection lower bound and shows that any faithful carrier of the footprint is sufficient. GraphPermit computes that footprint from an Action Graph, returns replayable rejection witnesses, and binds the graph and policy judgment to gateway execution. On 1,200 disjoint post-freeze adaptive runs, GraphPermit blocks 96.3% of laundering and 96.8% of persistence attacks, versus 80.2% and 85.8% for OPA; unsafe authorization falls from 7.2% with unbound whole-plan visibility to 3.4% with binding. Its selected operating point blocks 99.1% of attack objectives while preserving 96.6% benign completion at 0.87 ms median gate time. A 228-execution audit measures 96.8% recall of policy-decisive dependencies, and transfer to AgentDojo reduces targeted attack success to 1.8%. These results identify authorization input and binding as controllable causes of compositional policy failure.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.