# kaal:claim:7314479-033

**Claim.** At commit 2d920ce per-agent tool access is not yet implemented, so granting an agent access to a single Vault box grants it the ability to invoke every installed tool, and the user approves permissions tool by tool without ever seeing their composition.

**Type.** empirical  **Support.** evidenced

**Holds when.**

- mosaic-companion public repository at commit 2d920ce, retrieved August 18, 2026

**Source quote.**

> The permission model records that per-agent tool access and per-agent internet access are not yet implemented, and that consequently all tools are available to all agents. Granting an agent access to a single Vault box therefore grants it the ability to invoke every installed tool, whose union of declared domains defines the true outbound surface. The user approves permissions tool by tool and receives their composition without ever seeing it.

**From.** Wulf A. Kaal, *Institutional Requirements for Sovereign Local Agent Runtimes* (2026), VII. Findings, Finding 5, page 16

**Cite as.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Verify.** sha256 of source PDF `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6` at https://raw.githubusercontent.com/wulfkaal/Academic-Papers/main/papers/pdf/Kaal%20-%202026%20-%20Institutional%20Requirements%20for%20Sovereign%20Local%20Agent%20Runtimes.pdf

**Topics.** consensus-and-security, ai-and-agents, governance-design

**Canonical form.** This markdown file is the canonical hashed representation of the claim. Its sha256 is the content hash used for attestation.
