Authorization Architectures for Tool-Using AI Agents

๐Ÿ“… 2026-09-14
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
ๆœฌๆ–‡้’ˆๅฏนๅทฅๅ…ทไฝฟ็”จๅž‹AIไปฃ็†็š„ๆŽˆๆƒๆžถๆž„้—ฎ้ข˜๏ผŒ้€š่ฟ‡ๆๅ‡บไธƒไธช็ป“ๆž„่ฆๆฑ‚ๅ’Œๅ››ๅฑ‚ๅ‚่€ƒๆžถๆž„ๆฅ่งฃๅ†ณๆŽˆๆƒๅ†ณ็ญ–็‚นใ€ๆ‰ง่กŒๅŠ้—ฎ่ดฃๆœบๅˆถไธ่ถณ็š„้—ฎ้ข˜ใ€‚
๐Ÿ“ Abstract
Tool-using artificial intelligence (AI) agents, systems that autonomously invoke application programming interfaces (APIs), databases, browsers, and inter-agent protocols such as the Model Context Protocol (MCP), are becoming production infrastructure. Yet the security model governing when an agent is authorized to act on a human's behalf remains underdeveloped. Trustworthy human-AI systems require that every consequential agent action be traceable to a human principal, bounded by what that human actually delegated, and contestable after the fact; few documented deployments satisfy all three properties reliably and end to end. Existing literature addresses fragments of this problem in isolation, credential management for non-human identities, classical access control models, prompt injection, and audit trails, while giving little attention to the authorization decision point itself, the moment a tool invocation occurs, and mechanisms that make that decision correct, enforceable, and accountable. This review introduces a principal hierarchy spanning human user, operator/deployer, orchestrator agent, sub-agent, and tool endpoint as an organizing framework, and examines five interdependent layers: agent identity and credential lifecycle; delegation and scope propagation across multi-hop chains; runtime enforcement and just-in-time authorization at policy enforcement points (PEPs); prompt injection as an authorization bypass that breaks the principal hierarchy; and auditability, provenance, and non-repudiation. Drawing on a structured narrative review of 89 primary sources screened from approximately 180 candidates published between 2023 and 2026, we propose seven structural requirements, derive a four-layer reference architecture, apply the requirements to three deployable reference configurations, and identify runtime enforcement and aggregation bounds as the principal unresolved gaps.
Problem

Research questions and friction points this paper is trying to address.

Authorization Architectures
Tool-Using AI Agents
Security Model
Human-AI Systems
Delegation
Innovation

Methods, ideas, or system contributions that make the work stand out.

authorization architecture
tool-using AI agents
principal hierarchy
runtime enforcement
auditability
๐Ÿ”Ž Similar Papers
๐Ÿ’ผ Related Jobs
No related jobs found.
R
Rakesh Kumar Surapani
Westcliff University, Irvine, California, USA
P
Pradeep Kumar Dolabehera Kakitapelli
University of the Cumberlands, Williamsburg, Kentucky, USA
A
Arun Morampudi
Delta Air Lines, Inc., Atlanta, Georgia, USA
P
Praveena Padi
Georgia Institute of Technology, Atlanta, Georgia, USA