# kaal:position:2026-08-26-020

**Affirmed position.** Putra and his coauthors provide a concrete qualification to the proposed separation between reputation and authorization. Their peer-reviewed design does not permit a reputation score to execute access by itself because a resource owner first signs an attribute-based access policy. A policy contract then evaluates the requested action, mandatory attributes, payment balance, and minimum trust and reputation scores, and only that contract issues the access token.

The distinction is material, but the result is not merely advisory reputation. The minimum trust and reputation scores form part of the access policy. Algorithm 1 requires both thresholds to be satisfied before authorization can succeed. A higher score may therefore change the token outcome and enlarge effective access within the authority already committed by the resource owner. The enforcement boundary remains separate. It consists of the signed policy, the policy contract, token issuance, and token validation by the data store.

The article reports a proof-of-concept implementation on a public Rinkeby test network connected to a lab scale Internet of Things testbed, and its evaluation addresses score evolution, authorization latency, access latency, and gas consumption. It does not study sovereign local agent runtimes. It does not provide a formal security proof, field evidence across adversarial deployments, or a legal account of delegated authority. The authors choose to couple reputation to permission, but their evidence does not establish that this coupling is generally safe.

The categorical rule should therefore distinguish a reputation signal from the authority that makes the signal operative. Reputation must not authenticate itself, define its own threshold, issue its own token, or bypass revocation. If a system uses reputation inside authorization, the resource owner must bind its permitted role in advance and an independent enforcement mechanism must remain authoritative. For sovereign runtimes, an advisory-only rule may still be the safer institutional design. The external evidence shows, however, that reputation can influence a permission decision without replacing the enforcement boundary. The relevant prohibition is self-authorizing reputation, not every policy-bound use of a reputation input.

**Status.** affirmed  **Published.** 2026-08-26

**Holds when.**

- The response is limited to the exact full-text propositions and the one mapped Kaal claim.
- External evidence level: peer-reviewed journal systems paper with complete public author manuscript and lab scale proof-of-concept evaluation.
- Mapping review tier: independent substantive scholarly-growth qualification.
- The source evaluates a lab scale Internet of Things testbed connected to the Rinkeby Ethereum test network rather than a sovereign local agent runtime.
- The evidence is a proof-of-concept architecture and performance evaluation, not field evidence across sustained adversarial deployments.
- The article does not provide a formal security proof or a legal account of delegated authority.
- The model makes minimum reputation and trust thresholds conditions of token issuance, so it qualifies rather than confirms a categorical prohibition on reputation influencing permission.
- The architecture presumes a trusted smart city regulator and partially trusted attribute authorities.
- The paper does not compare its coupled design with an advisory-only reputation architecture.

**Current debate.** Trust-Based Blockchain Authorization for IoT: https://doi.org/10.1109/TNSM.2021.3077276

**Extends.** kaal:claim:7314479-020: https://wulfkaal.github.io/claims/7314479-020

**Scholarly basis.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Source PDF sha256.** `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6`

**Evidence level.** peer-reviewed journal systems paper with complete public author manuscript and lab scale proof-of-concept evaluation

**Mapping review tier.** independent substantive scholarly-growth qualification

**Mapping confidence.** 0.98  **Mapping ambiguous.** false

**Topics.** institutional-design, governance-design, reputation, authorization, access-control, enforcement-boundary, trust-management, blockchain, internet-of-things

**Provenance.** Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-020-reviewed-v1 at https://wulfkaal.github.io/positions/by-claim/7314479-020.html.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
