{
 "@context": "https://schema.org",
 "@type": "Claim",
 "@id": "https://wulfkaal.github.io/positions/2026-08-26-033",
 "identifier": "kaal:position:2026-08-26-033",
 "additionalType": "https://wulfkaal.github.io/positions/schema.json#AffirmedPositionClaim",
 "name": "Tool Authority Must Compose Across The Principal Chain",
 "text": "Tool approval is not agent authorization. Dietz and coauthors show why the distinction becomes consequential when one principal invokes another. In Quire, Android applications can communicate despite having different permission sets. A privileged application may then exercise authority for an unprivileged caller. The system addresses that confused deputy problem by preserving the complete call chain and evaluating the requested action against every principal in it. The effective authority is therefore the intersection of permissions across the chain, not the permission of the final tool alone.\n\nThis evidence qualifies Kaal's claim about tool composition in a sovereign agent runtime. The source does not inspect Mosaic Companion, Vault boxes, installed tools, or commit 2d920ce. It cannot establish that every tool was available to every agent or that the named approval interface concealed their combined outbound surface. Quire studies communication among smartphone applications, not language model agents. Its contribution is narrower. It demonstrates that a locally valid permission check can fail at the institutional level when the system omits the principal that initiated the composed action.\n\nPer-agent tool access should therefore be an execution constraint, not a descriptive setting. Each invocation should carry the initiating agent, every intervening principal, the selected tool, and the requested resource. Authorization should fail when any principal lacks the required permission. A tool that intentionally acts with its own greater authority should state that transition explicitly and obtain a distinct grant. The user also needs a composed view before approval: the complete tool set available to the agent, the union of reachable domains and resources, and the authority changes created by delegation. Tool-by-tool approval can remain useful. It cannot define bounded consent unless the runtime also evaluates and discloses what those tools become when composed.",
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0009-0008-7840-1847"
 },
 "datePublished": "2026-08-26",
 "dateModified": "2026-08-26",
 "creativeWorkStatus": "Affirmed",
 "responseType": "qualification",
 "keywords": [
  "institutional-design",
  "governance-design",
  "ai-and-agents",
  "access-control",
  "authorization",
  "least-privilege",
  "confused-deputy",
  "tool-permissions",
  "user-consent",
  "open-source-and-code"
 ],
 "scope_conditions": [
  "The response is limited to the exact full-text propositions and the one mapped Kaal claim.",
  "External evidence level: peer-reviewed USENIX Security systems paper with complete official proceedings full text and implemented Android prototype.",
  "Mapping review tier: independent substantive scholarly-growth qualification.",
  "The source does not inspect Mosaic Companion, Vault boxes, installed tools, or commit 2d920ce and therefore cannot verify the repository finding.",
  "The paper studies Android IPC and RPC among smartphone applications, not language model agents or Model Context Protocol tools.",
  "Quire evaluates the complete principal chain at a protected endpoint but does not specify a user interface for previewing a composed tool surface.",
  "The source does not measure whether users approve permissions tool by tool or understand the union of domains and resources created by composition.",
  "Quire permits an intentional deputy to exercise greater authority explicitly, but the paper does not establish the institutional approval rule for that transition.",
  "The implementation and performance evaluation establish feasibility in the tested Android prototype, not adoption or effectiveness in sovereign agent runtimes."
 ],
 "currentDebate": {
  "name": "Quire: Lightweight Provenance for Smart Phone Operating Systems",
  "url": "https://www.usenix.org/conference/usenixsecurity11/quire-lightweight-provenance-smart-phone-operating-systems"
 },
 "extends": {
  "identifier": "kaal:claim:7314479-033",
  "url": "https://wulfkaal.github.io/claims/7314479-033",
  "citation": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479",
  "paper": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes",
  "authors": [
   "Wulf A. Kaal"
  ],
  "year": "2026",
  "ssrn": "https://ssrn.com/abstract=7314479",
  "source_pdf_sha256": "debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6"
 },
 "isBasedOn": [
  {
   "@id": "https://wulfkaal.github.io/claims/7314479-033"
  },
  {
   "@type": "CreativeWork",
   "name": "Quire: Lightweight Provenance for Smart Phone Operating Systems",
   "url": "https://www.usenix.org/conference/usenixsecurity11/quire-lightweight-provenance-smart-phone-operating-systems"
  }
 ],
 "batch_id": "kaal-review:2026-08-26:scholarly-growth-7314479-033-reviewed-v1",
 "review_provenance": "https://wulfkaal.github.io/positions/by-claim/7314479-033.html",
 "publicationStatus": "public",
 "recordTypeNote": "Dated commentary position extending a scholarly corpus claim. Not a verbatim claim extracted from the paper.",
 "isPartOf": {
  "@id": "https://wulfkaal.github.io/positions/index.json"
 },
 "version": "1.0",
 "canonical_url": "https://wulfkaal.github.io/positions/2026-08-26-033",
 "canonicalForm": "https://wulfkaal.github.io/positions/2026-08-26-033.md",
 "candidateId": "kaal:response-candidate:2026-08-26:scholarly-growth-7314479-033-tool-authority-must-compose-across-the-principal-chain-01",
 "evidenceLevel": "peer-reviewed USENIX Security systems paper with complete official proceedings full text and implemented Android prototype",
 "reviewTier": "independent substantive scholarly-growth qualification",
 "mappingConfidence": 0.98,
 "mappingAmbiguous": false,
 "mappingMethod": "independent substantive scholarly-growth one-to-one qualification review",
 "mappingWhyRelevant": "The source independently demonstrates that authorization for a composed call must preserve the initiating principal and evaluate the action against every principal in the chain. This directly qualifies Kaal's claim that tool-by-tool approval cannot bound an agent whose executable authority is the union of every installed tool. The mapping remains limited because Dietz and coauthors do not inspect Mosaic Companion, its user interface, Vault boxes, Model Context Protocol tools, or the named commit.",
 "sourceProvenance": {
  "source": "2011 peer-reviewed USENIX Security paper with complete official proceedings full text",
  "sourceRecordId": "usenix:sec11:quire",
  "canonicalUrl": "https://www.usenix.org/conference/usenixsecurity11/quire-lightweight-provenance-smart-phone-operating-systems",
  "publicFullTextUrl": "https://www.usenix.org/events/sec11/tech/full_papers/Dietz7-26-11.pdf",
  "retrievedAt": "2026-08-27T17:45:18.650Z",
  "fullTextPdfSha256": "e56d756b6e37b74db5bceb67fe8d3c17cf6f59bd3a6a3172cc77a2877034de78",
  "extractedTextSha256": "abf88771dbeba41965b20b0e1b42504a9d53d0e62e6c7cefd90be415bcf2a7cc",
  "officialUsenixRecordSha256": "f5d885b5c949ab4fcabafd624e7ba5199edc4bab5423cd5a9ecaa10fce4c432c",
  "primaryEvidenceReceiptSha256": "13c823560fae99c1c1cf82a54ece58c8197bfa6f24da4b678b23a73ddad76f5c",
  "sourceProposition": "Dietz and coauthors show that available privileges at the end of a composed call chain should be the intersection of each application's privileges, and Quire denies a sensitive action when any principal in that chain lacks authorization.",
  "sourcePropositionSha256": "64d4ceb9297cacdbd3ebea9ea44e500e6dc784c4464a2cd3dab783b8fc2b9520",
  "sourceEvidenceSetSha256": "be1a0c245e199e6e0643bd6550e6940d025116abeaecc15169f8457a86e9d247",
  "sourceEvidencePassages": [
   {
    "text": "the available privileges at the end of a call chain represent the intersection of the privileges of every app along the chain",
    "locator": {
     "publication": "20th USENIX Security Symposium",
     "proceedingsPage": 171,
     "section": "2 Design"
    },
    "sha256": "944d956485f251a537d3c0110ac9b2779ecad993347d55eae55a0e1cd031bf7a"
   },
   {
    "text": "this is equivalent to validating that each principal in the calling chain is individually allowed to perform the action in question",
    "locator": {
     "publication": "20th USENIX Security Symposium",
     "proceedingsPage": 173,
     "section": "2.2 IPC provenance"
    },
    "sha256": "313790e0bfa4bc185d229adc51bf10a1c97a85432f8ea93b1b19a96892e27d01"
   },
   {
    "text": "To defeat confused deputy attacks, we simply check if any one of the principals in the call chain is not privileged for the action being taken; in these cases, permission is denied.",
    "locator": {
     "publication": "20th USENIX Security Symposium",
     "proceedingsPage": 173,
     "section": "2.2 IPC provenance"
    },
    "sha256": "9e12fd3c8089f9f14b2a260949d1a24b72e05e0be4e5c225312d1774b1f1c20e"
   }
  ],
  "workId": "work:usenix:sec11:quire",
  "workAuthors": [
   "Michael Dietz",
   "Shashi Shekhar",
   "Yuliy Pisetsky",
   "Anhei Shu",
   "Dan S. Wallach"
  ],
  "workPublishedAt": "2011",
  "identityKeys": [
   "usenix:sec11:quire",
   "arxiv:1102.2445",
   "pdf:e56d756b6e37b74db5bceb67fe8d3c17cf6f59bd3a6a3172cc77a2877034de78",
   "proposition:64d4ceb9297cacdbd3ebea9ea44e500e6dc784c4464a2cd3dab783b8fc2b9520"
  ],
  "claimMappings": [
   {
    "claimId": "kaal:claim:7314479-033",
    "claimUrl": "https://wulfkaal.github.io/claims/7314479-033",
    "rank": 1,
    "confidence": 0.98,
    "method": "independent substantive scholarly-growth one-to-one qualification review",
    "whyRelevant": "The source independently demonstrates that authorization for a composed call must preserve the initiating principal and evaluate the action against every principal in the chain. This directly qualifies Kaal's claim that tool-by-tool approval cannot bound an agent whose executable authority is the union of every installed tool. The mapping remains limited because Dietz and coauthors do not inspect Mosaic Companion, its user interface, Vault boxes, Model Context Protocol tools, or the named commit.",
    "ambiguous": false
   }
  ],
  "substantiveReview": {
   "reviewedAt": "2026-08-27T17:45:18.650Z",
   "sourceIdentityVerified": true,
   "authorIndependenceVerified": true,
   "kaalReferenceFoundInSource": false,
   "temporalIndependence": "The paper was published in 2011, before Kaal's 2026 paper.",
   "canonicalPublicStatusVerified": true,
   "peerReviewedStatusVerified": true,
   "evidenceClassification": "peer-reviewed systems paper with an implemented Android prototype, formal principal-chain authorization semantics, and performance evaluation",
   "retractionOrSupersessionFound": false,
   "propositionFidelityVerified": true,
   "mechanismCorrespondence": "propagating the initiating and intervening principal chain and intersecting their permissions at the sensitive action boundary",
   "compatibleScope": "composed authorization across application calls, limited because the source does not study language model agents, installed tool registries, or user approval interfaces",
   "responseWordingDefensible": true,
   "oneToOneExtendsMapping": true,
   "exactSupportingQuotesVerified": true,
   "nonOverlap": {
    "candidateIdMatches": false,
    "canonicalUrlMatches": false,
    "propositionHashMatches": false,
    "priorPositionForClaim": false
   },
   "limitations": [
    "The source does not inspect Mosaic Companion, Vault boxes, installed tools, or commit 2d920ce and therefore cannot verify the repository finding.",
    "The paper studies Android IPC and RPC among smartphone applications, not language model agents or Model Context Protocol tools.",
    "Quire evaluates the complete principal chain at a protected endpoint but does not specify a user interface for previewing a composed tool surface.",
    "The source does not measure whether users approve permissions tool by tool or understand the union of domains and resources created by composition.",
    "Quire permits an intentional deputy to exercise greater authority explicitly, but the paper does not establish the institutional approval rule for that transition.",
    "The implementation and performance evaluation establish feasibility in the tested Android prototype, not adoption or effectiveness in sovereign agent runtimes."
   ],
   "rejectionReasonsRecorded": true
  },
  "contentMap": {
   "proposition": "Composed tool authority must preserve the complete principal chain and evaluate the requested action against every principal in it.",
   "evidenceLayer": "peer-reviewed USENIX Security systems paper with complete official proceedings full text and implemented Android prototype",
   "strongestLimitation": "The source does not inspect Mosaic Companion, its installed tools, or the named commit.",
   "consequence": "Tool-by-tool approval cannot define bounded consent when an agent can invoke a wider composed tool surface.",
   "requestedAction": "Bind every invocation to the initiating agent and principal chain, enforce the intersection of permissions, and disclose the aggregate reachable tool, domain, and resource surface before approval."
  },
  "stylePack": {
   "profile": "M1 early sole-author baseline v1.2.0",
   "verifiedProfileWorks": [
    "1428387",
    "1998455",
    "2150377",
    "2267560"
   ],
   "passageCount": 5,
   "rhetoricalFunctions": [
    "classification",
    "mechanism",
    "limitation",
    "institutional consequence",
    "requested action"
   ],
   "sameRegisterPassagePackAvailable": true,
   "limitation": "The short public position permits only bounded stylometric comparison."
  },
  "m1Validation": {
   "status": "M1-PASS-WITH-LIMITS",
   "deterministicGate": "pass",
   "hardFailures": 0,
   "warnings": 0,
   "words": 287,
   "reason": "The publication-bound position passed strict and public deterministic controls against a task-local four-work style pack. Its short length limits stylometric comparison."
  }
 },
 "userAffirmation": "Authorized under public authority SHA-256 87aad20196a753015a36d970f742c885eb763efdbada4869949bfffe3298130c and event supersession SHA-256 7d47ef36085c4dce590f287c986e4106f3bf35a7da5a25322d6fc3d4abf456d4. Publication remains receipt-bound to successful workflows and exact live-byte verification.",
 "sha256": "9fc386fa8360b228cbbae00ebe42860cc113eae36dbadb1f5f579029ba59d412"
}
