Revocable Delegated Authority for Agentic AI in Hybrid Cloud Environments
Abstract
Agentic AI systems act in hybrid cloud environments through federated identity and control-plane APIs, where an action can be technically authorized yet exceed the authority under which an agent should act. This study introduces Authority to Autonomously Act (AAA): a model of delegated autonomy as a continuously re-evaluated, automatically revocable state rather than a standing permission. A two-stage procedure enforces AAA, placing a decidable SAT/SMT veto ahead of a bounded behavioral score, so impermissible actions remain non-executable by construction. The procedure prioritizes and routes admissible ones. The behavioral score extends a Unified Risk Model that reached 0.8937 average precision against a 0.0099 baseline on 1,200,562 insider-behavior windows from the CERT Insider Threat Corpus with injected cloud control plane telemetry. A worked cloud-escalation scenario revokes autonomy programmatically on two independent grounds, and containment holds even after an adversary subverts the agent’s reasoning. The contribution is conceptual and architectural; this article specifies empirical evaluation of the composite scorer as future work and fixes its baselines, primary metrics, and success criteria in advance.