Qualification: Quire: Lightweight Provenance for Smart Phone Operating Systems

Record: kaal:position:2026-08-26-033 · 2026-08-26

Tool approval is not agent authorization. Dietz and coauthors show why the distinction becomes consequential when one principal invokes another. In Quire, Android applications can communicate despite having different permission sets. A privileged application may then exercise authority for an unprivileged caller. The system addresses that confused deputy problem by preserving the complete call chain and evaluating the requested action against every principal in it. The effective authority is therefore the intersection of permissions across the chain, not the permission of the final tool alone. This evidence qualifies Kaal's claim about tool composition in a sovereign agent runtime. The source does not inspect Mosaic Companion, Vault boxes, installed tools, or commit 2d920ce. It cannot establish that every tool was available to every agent or that the named approval interface concealed their combined outbound surface. Quire studies communication among smartphone applications, not language model agents. Its contribution is narrower. It demonstrates that a locally valid permission check can fail at the institutional level when the system omits the principal that initiated the composed action. Per-agent tool access should therefore be an execution constraint, not a descriptive setting. Each invocation should carry the initiating agent, every intervening principal, the selected tool, and the requested resource. Authorization should fail when any principal lacks the required permission. A tool that intentionally acts with its own greater authority should state that transition explicitly and obtain a distinct grant. The user also needs a composed view before approval: the complete tool set available to the agent, the union of reachable domains and resources, and the authority changes created by delegation. Tool-by-tool approval can remain useful. It cannot define bounded consent unless the runtime also evaluates and discloses what those tools become when composed.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

Quire: Lightweight Provenance for Smart Phone Operating Systems

Scholarly basis

kaal:claim:7314479-033
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed USENIX Security systems paper with complete official proceedings full text and implemented Android prototype
Review tier: independent substantive scholarly-growth qualification
Mapping confidence: 0.98
Mapping ambiguous: false

Topics

institutional-designgovernance-designai-and-agentsaccess-controlauthorizationleast-privilegeconfused-deputytool-permissionsuser-consentopen-source-and-code

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-033-reviewed-v1 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: 9fc386fa8360b228cbbae00ebe42860cc113eae36dbadb1f5f579029ba59d412
curl -s https://wulfkaal.github.io/positions/2026-08-26-033.md | sha256sum