Skip to content

Empirical Evaluation of Task-Based Permission Scoping Architecture for AI Agents

Sep 2026 · 0 citations · 21 references
Computer Science

TL;DR

The research establishes task-based access control as a measured, potentially deployable mechanism for reducing attack surface in agentic deployments.

Abstract

AI agents are provisioned the same as employee-owned hosts in many enterprise settings with a static credential set fixed at deployment which includes all permissions the employee role might ever need. Role-based access control made this compromise for human principals because scoping access per task was infeasible. For AI agents, the compromise leaves every credential standing exposed whether or not the current task uses them. These permissions can later be utilised by a compromised or misaligned agent. Prior work (Noyan, 2026) defined this as the task-context mismatch, and proposed a three-source permission architecture which includes role-based permission ceilings, a task permission classifier and policy-based prohibitions, together eliminating the exposure preemptively. The work released a 600-prompt labelled dataset to evaluate it. This paper presents that evaluation end to end by implementing the security gate; a fine-tuned RoBERTa-large encoder which matched few-shot trained Claude Haiku 4.5 on classification quality (macro-F1 0.881 against 0.886, precision 0.897 against 0.842, severity-weighted residual risk 0.63 against 1.12). The results show the trusted component does not need to scale with the agent it supervises, and the scalable-oversight margin for this control method is wide. We also propose an attack-surface elimination metric which shows the role ceiling alone closes 27.9% of the severity-weighted surface and adding the task classifier closes 84.4%. The gap displays security advantages of task-granular access control over role-granular, and AI agents are the first principal type for which the task-granular access control is enforceable because their tasks arrive as machine-readable text. The research establishes task-based access control as a measured, potentially deployable mechanism for reducing attack surface in agentic deployments.

View source

Similar papers

Preprint Aug 2026

Who Delegates to AI? Evidence from Agent Configurations in Github

A distinct tier of exposure is introduced, delegated exposure, which records whether a worker has committed a task to AI by embedding it into a structured workflow, operationalized through the Agentic Adoption Index (AAI), measuring how closely an occupation's tasks align with the agentic routines that practitioners ha...

Hye-jung Lee, Jihyang Cheon, Lanu Kim · 0 citations
#artificial intelligence Preprint Sep 2026

Substrate-Aware AI Agents: Execution Context as a First-Class Input

A minimal execution contract induces proactive structural adaptation in generated programs, shifting computation away from unconstrained allocations and substantially improving observed resource-time profiles before execution, establishing a controlled proof of concept for substrate-aware agent planning.

Manu Agrawal · 0 citations
Preprint Sep 2026

MetaPermit: Scalable and Auditable Access Control for AI Agents via LLM-Inferred Meta-Attributes

The rise of autonomous AI agents equipped with tools has introduced significant security risks, ranging from unintended tool misuse to adversarial manipulation through Indirect Prompt Injection (IPI) attacks. In practice, deployed agent systems such as OpenAI Codex and Claude Code protect tool invocations through a com...

Han-Zhang Ma, Alicia Y. Hariri, Tian-Xiang Shen et al. · 0 citations
#artificial intelligence Preprint Sep 2026

PACT: Can Enterprise AI Assistants Be Trusted Under Pressure?

This work introduces PACT (Pressure-Applied Compliance Testing), a benchmark for rule-following under pressure in AI agents assisting employees in daily tasks across twelve regulated enterprise domains and forty-eight scenarios, each set in a realistic multi-turn conversation.

Mika Okamoto, Ansel Kaplan Erol · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.