# kaal:position:2026-08-26-033

**Affirmed position.** Tool approval is not agent authorization. Dietz and coauthors show why the distinction becomes consequential when one principal invokes another. In Quire, Android applications can communicate despite having different permission sets. A privileged application may then exercise authority for an unprivileged caller. The system addresses that confused deputy problem by preserving the complete call chain and evaluating the requested action against every principal in it. The effective authority is therefore the intersection of permissions across the chain, not the permission of the final tool alone.

This evidence qualifies Kaal's claim about tool composition in a sovereign agent runtime. The source does not inspect Mosaic Companion, Vault boxes, installed tools, or commit 2d920ce. It cannot establish that every tool was available to every agent or that the named approval interface concealed their combined outbound surface. Quire studies communication among smartphone applications, not language model agents. Its contribution is narrower. It demonstrates that a locally valid permission check can fail at the institutional level when the system omits the principal that initiated the composed action.

Per-agent tool access should therefore be an execution constraint, not a descriptive setting. Each invocation should carry the initiating agent, every intervening principal, the selected tool, and the requested resource. Authorization should fail when any principal lacks the required permission. A tool that intentionally acts with its own greater authority should state that transition explicitly and obtain a distinct grant. The user also needs a composed view before approval: the complete tool set available to the agent, the union of reachable domains and resources, and the authority changes created by delegation. Tool-by-tool approval can remain useful. It cannot define bounded consent unless the runtime also evaluates and discloses what those tools become when composed.

**Status.** affirmed  **Published.** 2026-08-26

**Holds when.**

- The response is limited to the exact full-text propositions and the one mapped Kaal claim.
- External evidence level: peer-reviewed USENIX Security systems paper with complete official proceedings full text and implemented Android prototype.
- Mapping review tier: independent substantive scholarly-growth qualification.
- The source does not inspect Mosaic Companion, Vault boxes, installed tools, or commit 2d920ce and therefore cannot verify the repository finding.
- The paper studies Android IPC and RPC among smartphone applications, not language model agents or Model Context Protocol tools.
- Quire evaluates the complete principal chain at a protected endpoint but does not specify a user interface for previewing a composed tool surface.
- The source does not measure whether users approve permissions tool by tool or understand the union of domains and resources created by composition.
- Quire permits an intentional deputy to exercise greater authority explicitly, but the paper does not establish the institutional approval rule for that transition.
- The implementation and performance evaluation establish feasibility in the tested Android prototype, not adoption or effectiveness in sovereign agent runtimes.

**Current debate.** Quire: Lightweight Provenance for Smart Phone Operating Systems: https://www.usenix.org/conference/usenixsecurity11/quire-lightweight-provenance-smart-phone-operating-systems

**Extends.** kaal:claim:7314479-033: https://wulfkaal.github.io/claims/7314479-033

**Scholarly basis.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Source PDF sha256.** `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6`

**Evidence level.** peer-reviewed USENIX Security systems paper with complete official proceedings full text and implemented Android prototype

**Mapping review tier.** independent substantive scholarly-growth qualification

**Mapping confidence.** 0.98  **Mapping ambiguous.** false

**Topics.** institutional-design, governance-design, ai-and-agents, access-control, authorization, least-privilege, confused-deputy, tool-permissions, user-consent, open-source-and-code

**Provenance.** Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-033-reviewed-v1 at https://wulfkaal.github.io/positions/by-claim/7314479-033.html.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
