AI agents need explicit authority, not just credentials and tools
An AI agent may be able to authenticate, call APIs, hold a key, execute code or operate infrastructure. None of those facts should silently mean the agent has sovereign authority to change rights, approve transactions, assert external truth or bind a human or organization.
Authentication is not authorization
Authentication establishes which account, key or process is acting. Authorization establishes what that actor is allowed to do. ENTITY treats those as different questions and adds scope, delegation, revocation, provenance and rights context to the authorization decision.
What an agent authorization record needs to answer
| Question | Required governance concept |
|---|---|
| Which agent/process acted? | Persistent identity or attributable runtime identity. |
| Who authorized it? | Explicit delegating ENTITY / authority chain. |
| What may it do? | Scoped rights/capabilities and applicable policy. |
| For how long? | Validity, expiry, supersession and revocation semantics. |
| On which objects? | Bound resource/object/domain scope. |
| What evidence did it rely on? | Evidence/provenance separate from authority. |
| What did it change? | Signed/governed event and resulting state. |
| Did an economic consequence follow? | Explicit value/economic lineage rather than inferred entitlement. |
Tool access does not create sovereign authority
An agent with database access, a cloud role, filesystem control or API credentials may be operationally powerful. ENTITY's boundary is that infrastructure possession and tool capability do not automatically become sovereign protocol authority. A protected state transition still needs the applicable authorized relationship.
Signed agent output is not automatically truth
A signature can establish that an agent or key produced a record. It does not establish that the model output is factually correct, legally authoritative or owned by the signer. External-world claims remain evidence-bound and may be disputed, superseded or independently verified.
Revocation matters more for autonomous systems
Long-running agents can outlive the context in which access was originally granted. Delegated authority therefore needs fail-closed expiry/revocation behavior. A revoked agent should not retain effective rights merely because it cached a credential, a tool session or an earlier copy of policy state.
AI, NIKI and ENTITY
Within the current ENTITY architecture, bounded NIKI reasoning is not the root of sovereign authority. Reasoning may propose, classify or project; ENTITY remains the authority/rights/governance layer for protected state. This prevents a reasoning component from manufacturing authority merely because it generated a plausible decision.
Useful external tests
Try to construct a case where an authenticated agent can act outside delegated scope, a revoked agent remains effective, a signed model claim is promoted to truth without evidence, or infrastructure control becomes ENTITY authority. A reproducible counterexample is useful security evidence.