Agent Authorization
A decision, made before an agent operates, by a named person with the standing to make it, that this identified agent may act for a stated purpose within defined permissions, prohibitions, and review conditions.
VOCABULARY
Core terms used across the frameworks, field notes, and governance writing. Each definition is designed to stay consistent in public use.
A decision, made before an agent operates, by a named person with the standing to make it, that this identified agent may act for a stated purpose within defined permissions, prohibitions, and review conditions.
The accumulation of agents faster than any function can account for them.
Governance Debt is the accumulated backlog of unresolved accountability decisions that builds when AI agents are deployed faster than the governance structures designed to manage them can absorb the volume. Like technical debt, it compounds: each ungoverned agent deployment adds to the backlog, each month without a registry audit increases the exposure, and each incident that surfaces without a clear accountability owner makes the next examination harder to navigate. Governance Debt is always the result of velocity without governance infrastructure — not malice, and not incompetence.
The practice of writing down what an agent is for, and what it may not do, before it is capable of doing anything.
The operating form of Intent Architecture: three layers in fixed order that must exist before an agent is authorized to operate. Context establishes the regulatory obligations, affected stakeholders, and system integrations that determine what the intent can permissibly be. Intent states the purpose in plain language, the authorized scope, the explicit prohibitions, and the expected outputs with their human-review triggers. Governance names the Consequence Owner, the review cadence with its event triggers, and the escalation path that works without the builder. Each layer produces a document, and together the three constitute the authorization record. Introduced in Who Owns the Agent? (Roy, 2026), DOI 10.5281/zenodo.20481551.
The periodic exercise of comparing every agent the platform can see against every agent the organization has authorized, and assigning a disposition to each difference.
The condition in which every function believes another function owns an agent's risk, and the belief is unanimous, reciprocal, and unwritten.
The path an organization travels from not knowing what it runs, to knowing, to preventing new unauthorized deployment faster than it accumulates.
The set of organizational decisions that has to exist beneath the platform controls, establishing who decided that the agent may operate, the limits of that operation, and the authority behind the decision.
The single artifact that carries an agent's purpose, permitted actions, explicit prohibitions, data scope, accountable people, review triggers, and a signature that predates production.
The condition in which each agent in a multi-agent chain is individually approved, no one approved the chain, and the original approval travels the whole length unrevisited.
The standing rule that every signal about an agent, whether a change, a failure, a departure, or a platform announcement, receives a recorded decision rather than a reaction.
The distance between what a system was intended to do and what it actually does.