Agentic workflows are commonly evaluated by whether they reach the correct outcome. That is insufficient in institutional settings, where a correct action may rely on the wrong authority, an unsupported completion claim, or work made stale by a later change. We define governed execution as work whose decisions, completion, and response to change are supported by inspectable provenance. We present Matrix, a deterministic causal-state layer that records authority and fact dependencies, verifies completion evidence, and selectively invalidates affected work. Across controlled comparisons, governed and direct workflows often reached the same outcomes, but only the governed path consistently preserved governing evidence, refused unsupported closure, and limited recovery to dependent tasks. A role-separated transfer challenge then failed: a deterministically enforced completeness contract severely over-blocked synthetic packets produced outside its authoring context. These results do not establish Matrix as a general accuracy enhancer; they support its primary role as an institutional integrity layer for making agentic work auditable and independently verifiable.
A target-specific authorization audit is introduced that labels context factors separately for each tool and argument target and holds the task, proposition, position, and policy fixed while changing only the proposition's source authority.
Agent Skills combine instructions with files, packages, tools, models, and services, so operational identity can exceed a signed directory. Recursive or lazy dependencies may change while root-level evidence remains valid, and different surfaces may reach the same durable effect. We present ClosureBound, a reference mo...
Gen-Liang Zhu, Chu Wang Accentrust, Georgia Institute of Technology et al.· 0 citations
This work identifies a state-transmission failure between information extraction and action in large language model agents, and shows how handoff transformations can retain state content while weakening its constraints on downstream action.
Yi-Heng Sun, Huifei Wang, Yan-Cheng Zhu et al.· 2 citations
This work presents \textsc{Revise}, a validity-guided runtime for fine-grained recovery in structured agent workflows, a validity-guided runtime for fine-grained recovery in structured agent workflows that matches a latest-version oracle with no stale outputs or effects.
Ruoling Qi, Xuan'er Wu, Peng-Hang Liu et al.· 0 citations
Security assurance depends on clearly defined contextual conditions, including assumptions, environmental constraints, and stakeholder expectations. As artificial intelligence tools are increasingly used to analyze evidence and generate assurance artifacts, they often operate on incomplete or underspecified system de...
This work presents AID-Guard, a stateful authorization-to-effect closure protocol that revalidates the approved request and provider state at commit, retains one reservation under ambiguity, and permits release or one successor only after a terminal result or certified no effect with a delivery fence.