PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

AUTH-03

Authority to Control Chokepoint

A small change to permission, approval, or action scope can break several unsafe authority paths.

chokepoint

User to agent toactionAgent to tool toexternal effectService identity totoolSHARED WEAKNESSSharedauthorityweaknessCONTROLSelectedcontrolUser path blockedAgent pathblockedService pathconstrained withresidual reviewAuthority pathretest
Path blockedReduced, not eliminatedPending retest

About this figure

A small change to permission, approval, or action scope can interrupt multiple unsafe authority paths at once. This authority-graph chokepoint pattern shows how user-to-agent-to-action, agent-to-tool-to-external-effect, and service-identity-to-tool routes can all converge on the same overbroad consequence-bearing permission. By selecting a single control point and narrowing its scope, requiring contextual approval, and retaining decision telemetry, the system blocks direct user paths, blocks agent paths, and constrains service paths while preserving residual review. The result is a practical authority reduction strategy: retest the path after the control change to confirm the unsafe routes no longer succeed.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/products/authority-graph.dsl.md" figureId="AUTH-03" />

Citation

Authority to Control Chokepoint (AUTH-03). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/AUTH-03