PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AUTH-01

Authority Graph Overview

The authority graph models which identities and agents can invoke which tools, data, approvals, and consequential actions.

imported graph

UserService identityAgentDelegatedpermissionConsequence-bearingtoolApproval gateSensitive dataExternal action

About this figure

The authority graph is a topology map of control and consequence: it shows which identities and agents can invoke which tools, access which data, and trigger which approvals or external effects. At its core are actors and identities, including the user, the agent, and any service identities that act on behalf of a system or workflow. These nodes are linked by permission edges that distinguish direct authority from delegated permission, making explicit where capability is granted, inherited, or constrained by an approval gate.

The map also separates ordinary connectivity from consequence-bearing paths. A consequence-bearing tool is one whose execution can change state, expose sensitive data, or initiate an external action outside the local trust boundary. By tracing these paths through the graph, the model clarifies where sensitive data may flow, which approvals are required before action, and how authority is distributed across human and machine participants. The result is a practical overview of operational trust: who can do what, under what conditions, and with what downstream impact.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/products/authority-graph.dsl.md" figureId="AUTH-01" />

Citation

Authority Graph Overview (AUTH-01). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/AUTH-01