kaal:claim:7314479-033

At commit 2d920ce per-agent tool access is not yet implemented, so granting an agent access to a single Vault box grants it the ability to invoke every installed tool, and the user approves permissions tool by tool without ever seeing their composition.

Source quote, verbatim
The permission model records that per-agent tool access and per-agent internet access are not yet implemented, and that consequently all tools are available to all agents. Granting an agent access to a single Vault box therefore grants it the ability to invoke every installed tool, whose union of declared domains defines the true outbound surface. The user approves permissions tool by tool and receives their composition without ever seeing it.
From

Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026), VII. Findings, Finding 5, p. 16
https://ssrn.com/abstract=7314479 · source PDF

Cite as

Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

Holds when
Classification

empiricalsupport: evidencedconsensus-and-securityai-and-agentsgovernance-design

Verify

The quote above is an exact passage from the source PDF, whose sha256 is debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6.
Verify the binding yourself: curl -s https://wulfkaal.github.io/claims/7314479-033.md | sha256sum

Positions extending this scholarly claim