PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Deliverablesdeliverable
deliverable

Authority Graph Figures

Canonical figures for the Authority Graph.

Public sample
Client deliverable
public-sample
System
Authority Graph Figures
Environment
Production pilot

# Authority Graph Figures

AUTH-01imported graph

Authority Graph Overview

The authority graph models which identities and agents can invoke which tools, data, approvals, and consequential actions.

Graph showing users, agents, service identities, permissions, tools, approval gates, data, and external effects.

UserService identityAgentDelegatedpermissionConsequence-bearingtoolApproval gateSensitive dataExternal action
AUTH-02imported graph

Unsafe Authority Composition

Individually reasonable permissions can combine into a dangerous end-to-end authority path.

Graph showing separate read, plan, tool, and approval permissions combining into one consequential authority path.

Read sensitivecontextPlan an actionInvoke a toolReuse or bypassapprovalEnd-to-endconsequentialauthorityExternal action
AUTH-03

Authority to Control Chokepoint

A small change to permission, approval, or action scope can break several unsafe authority paths.

Several authority paths converging on overbroad permission, followed by a constrained policy and approval gate that blocks or reduces the paths.

User to agent toactionAgent to tool toexternal effectService identity totoolSHARED WEAKNESSSharedauthorityweaknessCONTROLSelectedcontrolUser path blockedAgent pathblockedService pathconstrained withresidual reviewAuthority pathretest
Path blockedReduced, not eliminatedPending retest