[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85132-en":3,"doc-seo-85132-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85132,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","A Theory of Least Autonomy in AI","Least privilege limits an identity to only the permissions required for a task, but this principle fails to fully capture risk in agentic AI systems. Such agents can combine, approve, and amplify permissions across workflows and system boundaries. The work introduces least autonomy and a formal theory defining a compositional blast radius using an ultrametric enterprise hierarchy with lattice-valued confidentiality, integrity, and control-context labels.","arXiv :2607 .09744v 1 [ cs .AI] 3 Jul 2026  \nA Theory of Least Autonomy in AI  \nChristophe Parisel∗  \nJuly 14, 2026  \nAbstract  \nLeast privilege, the principle that an identity should hold only the permissions strictly required for its task, has been a foundational primitive of access control for decades. We argue that this principle is insufficient for agentic AI systems, which do not merely hold permissions but can combine, approve, and amplify them across workflows and system boundaries.  \nWe propose least autonomy as an appropriate generalization and develop a formal theory. First, we define a compositional blast radius d(a,b) that measures structural separation between actions in an enterprise hierarchy, combining an ultrametric tree with lattice-valued confidentiality, integrity, and control-context labels. Second, we define a directed agent influence graph G(theta) . An arc from U to V requires a directed shared-resource write-to-read meeting or a conservative undirected agent-to-agent (A2A) communication meeting, and a meeting-conditioned influence potential at or above an externally selected policy threshold theta. A catalogue-radius profile supports calibration and audit of theta. Finally, we define a collusion predicate over graph reachability that detects authorization composition, decision manipulation, and cross-domain capability composition.  \nWe provide a step-by-step design procedure, a structured comparison with classical least privilege, and an end-to-end illustrative example on a representative enterprise hierarchy.  \n1 Introduction  \n1.1 The Insufficiency of Least Privilege for Agentic AI  \nThe principle of least privilege, formalized in the 1970s [12], instructs that every principal should hold only the permissions necessary to accomplish its designated function. For human users and traditional software processes, this principle has provided a durable basis for access-control design. Its application is more difficult for agentic AI systems, whose actions may be sequenced, delegated, and composed across workflows and system boundaries.  \nAn agent is not merely a passive accessor of resources. It may read an output, transform it, write to a downstream resource, trigger a workflow, approve a privilege elevation, or hand off a task to another agent. Each individual permission in such a chain may appear innocuous in isolation, while the resulting configuration creates a risk not captured by a permission-bypermission review.  \nTwo properties of agentic systems make this particularly important:  \n(i) Gatekeeping. An agent may lack direct access to sensitive data while retaining authority to approve or enable another principal’s access. Conventional permission reviews need not capture this control-plane influence.  \n(ii) Composition. An agent’s operational reach may depend not only on its own direct permissions, but also on the actions of other agents that it can influence.  \n∗ Email: [ch.parisel@gmail.com](ch.parisel@gmail.com)  \nOur framework supports both resource-mediated meetings and direct agent-to-agent (A2A) communication meetings. For A2A communication, the existence of a configured communication path is treated conservatively as an undirected meeting: even an apparently one-way delegation channel may permit reverse influence through returned content, delegated artifacts, tool outputs, or prompt-injection payloads.  \n1.2 From Permissions to Autonomy  \nWe propose shifting the unit of analysis from permission to autonomy. Where least privilege asks, “What can this identity access?”, least autonomy asks, “What authority exposure can arise when this identity’s permissions compose with those of agents it can influence?”  \nLeast autonomy does not replace conventional access control. Rather, it is a complementary design criterion for identifying high-impact resource-mediated or communication-mediated interactions and multi-agent capability compositions that a permission-by-permission review may not reveal.  \nWe","cbCaimMgZvVfoM1h","https://ap.wps.com/l/cbCaimMgZvVfoM1h","pdf",374376,2,1,27,"English","en",105,"# Abstract\n# Introduction\n## The Insufficiency of Least Privilege for Agentic AI\n## From Permissions to Autonomy\n## Contributions\n# Background and Related Work\n## Authorization Safety, Least Privilege, and Separation of Duty","[{\"question\":\"Why is least privilege insufficient for agentic AI systems?\",\"answer\":\"Agentic AI can sequence, delegate, and compose permissions across workflows and boundaries, creating risks that permission-by-permission review may miss. It can gatekeep, influence other principals, and amplify capabilities through composed interactions.\"},{\"question\":\"What does least autonomy shift the analysis toward?\",\"answer\":\"It shifts the unit of analysis from permission to autonomy, asking what authority exposure can arise when an identity’s permissions compose with those of agents it can influence. It complements conventional access control rather than replacing it.\"},{\"question\":\"How does the paper model and detect harmful authorization composition?\",\"answer\":\"It defines a compositional blast radius and a directed agent influence graph based on meeting-conditioned relationships. It then introduces a collusion predicate over graph reachability to detect authorization composition, decision manipulation, and cross-domain capability composition.\"}]",1784201297,68,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-theory-of-least-autonomy-in-ai","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/a-theory-of-least-autonomy-in-ai/85132/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-22","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is least privilege insufficient for agentic AI systems?","Question",{"text":75,"@type":76},"Agentic AI can sequence, delegate, and compose permissions across workflows and boundaries, creating risks that permission-by-permission review may miss. It can gatekeep, influence other principals, and amplify capabilities through composed interactions.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What does least autonomy shift the analysis toward?",{"text":80,"@type":76},"It shifts the unit of analysis from permission to autonomy, asking what authority exposure can arise when an identity’s permissions compose with those of agents it can influence. It complements conventional access control rather than replacing it.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the paper model and detect harmful authorization composition?",{"text":84,"@type":76},"It defines a compositional blast radius and a directed agent influence graph based on meeting-conditioned relationships. It then introduces a collusion predicate over graph reachability to detect authorization composition, decision manipulation, and cross-domain capability composition.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]