Runtime Authorization for Resources Acquired by AI Agents
A provenance-bounded runtime authorization architecture that quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a d...