[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81821-en":3,"doc-seo-81821-105":31,"detail-sidebar-cat-0-en-105":85},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},81821,4398048950312,"Violet","https://ap-avatar.wpscdn.com/avatar/400002538284de19e3c?_k=1778320343897328908",8,"Research & Report","Janus: a Playground for User-Involved Agentic Permission Management","AI agents that autonomously execute tool calls on a user’s behalf introduce urgent permission-management questions: what should users do, and what should the system do? Despite many proposed solutions, the user’s role in agentic permission management remains insufficiently explored. Janus is a playground platform for implementing and evaluating user-involved permission designs, combining Janus-Core (modular designs) and Janus-Harness (automated evaluation). Six assistants are implemented and assessed across scenarios and synthetic responders, showing user input strengthens privacy and security, augmentation reduces cognitive load, and realistic behaviors like permission fatigue matter. No single design is best for all contexts.","Janus: a Playground for User-Involved Agentic Permission Management  \nNatalie Grace Brigham∗ , Eugene Bagdasarian†, Tadayoshi Kohno‡, and Franziska Roesner∗  \n∗ University of Washington, † University of Massachusetts Amherst, ‡Georgetown University  \narXiv :2607 .0 15 10v 1 [ cs .AI] 1 Jul 2026  \nAbstract—AI agents that autonomously execute tool calls on a user’s behalf raise pressing questions about permission management: what role could users play, and what role should they play? Despite many proposed approaches, the user’s role in agentic permission management remains under explored. We introduce Janus, a playground system for implementing and evaluating user-involved agentic permission management designs. Janus consists of two components: Janus-Core, a modular agentic system supporting a diverse spectrum of permission management designs, and Janus-Harness, an automated evaluation framework. Grounded in a conceptual model that identifies key design axes for user involvement, we implement six permission assistants spanning the design space and evaluate them across three scenarios and three synthetic responders. We demonstrate that user input is critical and can significantly strengthen privacy and security, that AI augmentation of user decisions can help reduce cognitive load, and that realistic user behavior including permission fatigue must be accounted for in system design. No single design performs optimally across all contexts, motivating amore principled and context-sensitive approach to deploying permission assistants in agentic systems. Janus is publicly available to support future investigation into this dimension of agentic system design.  \n1. Introduction  \nAI agents, or agentic systems, are defined as “compound software systems, inclusive of one or more AI models, that operate within an environment and take actions within it” [1] . Compared with prior systems, they enable users to complete tasks with unprecedentedly low levels of involvement, with the capacity to handle short and long-horizon tasks, collaborate with other agents, and operate over a diverse set of inputs. These capabilities carry significant implications for privacy and security, particularly given threats from prompt injection attacks [2], [3], hallucination-induced misbehavior [4], and misalignment with user intent [5] .  \nControlling what an agent does or can do is therefore critical. A classic principle in systems security is the principle of complete mediation, which holds that “every access to every object must be checked for authority” [6] . A related principle is the principle of least privilege: “every program and every user of the system should operate using the least set of privileges necessary to complete the job” [6] . Together, these principles demand that an agentic system  \nverify all resource accesses and limit itself to only those resources necessary for the user’s requested task.  \nIn practice, however, the sheer volume of access decisions and the complexity of real-world scenarios make this difficult to achieve. Consider an agent tasked with managing a user’s email inbox. Incoming messages vary widely, from explicit attacks like phishing attempts to non-malicious but ambiguous requests which modern large language models (LLMs) often struggle to resolve [7], [8] . An individual asking the agent to forward family reunion details to them may be a legitimate relative or may not be; the right action may depend entirely on context that only the user has. Multiply this ambiguity across dozens of daily interactions, and the challenge of principled permission management becomes clear. Furthermore, since agentic systems can produce unpredictable trajectories and users interact in unstructured language, evaluating permissions is additionally difficult.  \nThere are numerous approaches an agentic system could take toward permission management, with different types of user involvement. A straightforward option, initially used by many commerc","cbCaiiaMuQN9OqUQ","https://ap.wps.com/l/cbCaiiaMuQN9OqUQ","pdf",493106,5,1,16,"English","en",105,"# Introduction\n## Permission management challenges\n## Design options for user involvement\n## Janus overview and goals","[{\"question\":\"What do the evaluations suggest about user involvement?\",\"answer\":\"The results indicate that user input is critical for improving privacy and security, AI augmentation can reduce users’ cognitive load, and system design must account for realistic user behaviors such as permission fatigue.\"}]","Janus: a Playground for User-Involved Agentic Permission Management | PDF",1784176371,40,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":80,"head_meta":82,"extra_data":84,"updated_unix":29},"janus-a-playground-for-user-involved-agentic-permission-management","",{"@graph":37,"@context":79},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/janus-a-playground-for-user-involved-agentic-permission-management/81821/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-07-29","2026-07-16",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73],{"name":74,"@type":75,"acceptedAnswer":76},"What do the evaluations suggest about user involvement?","Question",{"text":77,"@type":78},"The results indicate that user input is critical for improving privacy and security, AI augmentation can reduce users’ cognitive load, and system design must account for realistic user behaviors such as permission fatigue.","Answer","https://schema.org",{"og:url":53,"og:type":81,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":83,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":86},[87,91,95,99,103,108,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":88,"show_sort_weight":89,"slug":90},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":92,"show_sort_weight":93,"slug":94},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Comic",60,"comic",{"id":104,"doc_module":4,"doc_module_name":47,"category_name":105,"show_sort_weight":106,"slug":107},6,"Technology",50,"technology",{"id":109,"doc_module":4,"doc_module_name":47,"category_name":110,"show_sort_weight":30,"slug":111},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":47,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":47,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":47,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":47,"category_name":129,"show_sort_weight":20,"slug":130},19,"General","general"]