# kaal:position:2026-08-26-015

**Affirmed position.** Authority can exceed consent even when the final permission check is correct. Felt and her coauthors identify permission redelegation where an application holding a user granted permission performs a privileged task for an application that lacks it. The system approves the call because the immediate deputy has the required permission. The requester nonetheless causes an action that it could not invoke directly. The paper reports fifteen such vulnerabilities across five core Android applications.

The mechanism supplies a concrete instance of authority drift. A user grants authority to one application. Interapplication communication then places that authority under the influence of a less privileged requester. A permissions system that evaluates only the immediate caller sees a valid grant and permits the action. It does not preserve the bounded purpose or authority of every participant in the chain. Local validity therefore coexists with an aggregate result outside the user's authorization.

The evidence is narrower than the institutional claim. The study concerns browsers and smartphone applications in 2011. It does not examine sovereign local agent runtimes, legal delegation, contractual purpose, or every form of authority drift. It also does not prove that permissions systems are least equipped to detect this failure relative to other failures. The institutional implication remains defensible. A runtime should carry authority provenance through every delegation boundary and evaluate a request against the intersection of the authority held along the full chain of influence. An intentional increase in authority requires a separate, explicit grant bound to the action and the principal. Otherwise a sequence of correct permission decisions can still produce an unauthorized result.

**Status.** affirmed  **Published.** 2026-08-26

**Holds when.**

- The response is limited to the exact full-text propositions and the one mapped Kaal claim.
- External evidence level: peer-reviewed USENIX Security conference paper with complete official proceedings full text.
- Mapping review tier: independent substantive scholarly-growth extension.
- The study concerns browsers and smartphone applications in 2011 rather than sovereign local agent runtimes.
- The paper addresses OS permissions and inter-application communication rather than legal delegation, contractual purpose, or institutional consent standards.
- The evidence establishes a concrete authority-redelegation mechanism but does not prove that permissions systems are least equipped to detect it relative to other failures.
- The case study reports Android vulnerabilities and does not establish prevalence across all permission architectures or delegation chains.
- IPC Inspection attenuates authority along a call chain but does not determine when an intentional authority increase is institutionally valid.

**Current debate.** Permission Re-Delegation: Attacks and Defenses: https://www.usenix.org/conference/usenixsecurity11/permission-re-delegation-attacks-and-defenses

**Extends.** kaal:claim:7314479-015: https://wulfkaal.github.io/claims/7314479-015

**Scholarly basis.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Source PDF sha256.** `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6`

**Evidence level.** peer-reviewed USENIX Security conference paper with complete official proceedings full text

**Mapping review tier.** independent substantive scholarly-growth extension

**Mapping confidence.** 0.97  **Mapping ambiguous.** false

**Topics.** consensus-and-security, governance-design, ai-and-agents, authority, delegation, permissions, consent, confused-deputy

**Provenance.** Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-015-reviewed-v1 at https://wulfkaal.github.io/positions/by-claim/7314479-015.html.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
