Skip to content
Preprint

Persona-Execution Separation: An Architecture Pattern for Evolving LLM Agents under Execution Audit

Aug 2026 · 0 citations · 47 references
Computer Science

TL;DR

This work presents Persona-Execution Separation (PES), which applies when multi-user deployment, execution audit, and persona churn hold jointly and follows from three goals: free drift, execution traceability, and decoupling.

Abstract

Large language model (LLM) agents in governed organizations must let the persona (instructions, tone, self-presentation) evolve freely, while keeping execution (stateful, audited work) traceable. A single trust domain does not satisfy both cheaply. We present Persona-Execution Separation (PES): persona and execution reside in different trust domains, connected by a governed contract bridge. The persona is singly-homed and may drift; execution is faceless and audited. Status summaries may return; data bodies remain in the restrictive domain except a data-loss-prevention (DLP) exception; identity stays continuous. An approval matrix, DLP, and audit enforce the crossing. PES follows from three goals: free drift, execution traceability, and decoupling. Under LLM representational indistinguishability, any single-domain mechanism meeting all three must re-introduce typed change objects, an external gate, and a stable audit anchor: PES rebuilt at higher coupling cost. A development/pilot case in a regulated platform records five decisions over one month, four with rejected alternatives. A mechanism check found no execution-side re-validation under persona perturbation (five configurations) and no persona fingerprint on hard-asserted fields of completed runs. A controlled replication in regulated coding agents reproduced the separation under isolation across five models and four providers; bridge overhead was under 0.2% of end-to-end time in both environments. A probe of a pre-separation build found the execution path decoupled from the persona by omission, not by construction. The pattern applies when multi-user deployment, execution audit, and persona churn hold jointly.

View source

Similar papers

Review Aug 2026

ClawSentry: A Progressive Multi-Tier Security Monitor for Safeguarding Autonomous LLM Agents

This work argues that agentic risk is progressive: it can enter at four loci of the agent control loop--skill admission, invocation-time intent, execution-time effect, and post-action consequence--while a denied dangerous objective can reappear across surface forms, tools, or turns.

Kai Wang, Zeming Wei, Biaojie Zeng et al. · 0 citations
Preprint Aug 2026

Recognition Without Enforcement: Configuration-Dependent Failures in LLM Agent Instruction Arbitration and External Control

This work treats model self-arbitration as a capability rather than a security boundary and implements an external reference monitor combining authenticated source routing with capability-gated tool execution, deterministically rejects all tested forged, tampered, replayed, and unsigned requests while preserving legiti...

Jun Wen Leong · 0 citations
Preprint Aug 2026

PACE: Policy-Attested Contract Execution for Safe AI Agents in Decentralized Finance

PACE (Policy-Attested Contract Execution), a transaction-level authorization framework that interposes between an LLM-based agent and on-chain execution, is presented and frame its claims as logic-level safety within a reproducible benchmark rather than deployment-ready DeFi security.

Rabimba Karanjai, Yang Lu, Richard T Williamson et al. · 1 citation
Preprint Aug 2026

A Contract-Centered Architecture for Scalable and Manageable Agentic Runtimes

A contract-bounded runtime architecture, a source-preserving data substrate, and a falsifiable measurement protocol are contributed, which proposes a cluster-period randomized crossover experiment with a four-state verdict: supported, falsified, conditional-engineering, or inconclusive.

Ya-Xiao Liu, Peng Liu, Yi-Wen Liu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.