Score
Designs, builds, or analyzes systems and processes for creating, issuing, activating, tracking, and enforcing software entitlements (licenses, keys, activation codes, or entitlement records), covering entitlement generation, activation workflows, delivery, storage, and lifecycle management. Ensures integration with provisioning, access control, usage metering, billing, and auditing components and addresses security, integrity, and compliance of entitlement operations.
AI coding assistants and autonomous agents are becoming integral to software development workflows, reshaping how code is produced, reviewed, and maintained. While recent research has focused mainly on the capabilities and impacts of productivity of these systems, much less attention has been paid to accountability: who is responsible when agents generate, modify, or recommend code? In practice, accountability is defined through the Terms of Service (ToS) and related policy documents that govern the use of AI-powered development tools. In this vision paper, we present a comparative analysis of the Terms of Service for widely used AI coding assistants and agent-enabled development tools. We examine how these documents allocate ownership, responsibility, liability, and disclosure obligations between tool providers and software developers, and we identify common patterns and divergences between providers. Our analysis reveals a consistent tendency to shift responsibility for correctness, safety, and legal compliance onto users, as well as substantial variation in how providers address issues such as indemnification, data reuse, and acceptable use. Based on these findings, we argue that existing policy frameworks are poorly aligned with increasingly agent-mediated and autonomous software development workflows. We outline a research roadmap for accountable agents in software engineering, identifying challenges and opportunities for modeling responsibility, designing governance artifacts, developing tooling that supports accountability, and conducting empirical studies of developers' perceptions and practices.
This study addresses the opacity and accountability challenges in AI-powered hiring systems, which stem from their complex supply chains that obscure the origins of algorithmic bias. Through regulatory analysis, system dependency modeling, and a multi-stakeholder perspective—complemented by case studies and an examination of implementation ambiguities—the work demonstrates for the first time that bias arises primarily from interactions among system components rather than from isolated modules. It further identifies a structural contradiction: deploying organizations bear legal responsibility yet lack technical visibility into upstream components. The research pinpoints two core barriers to effective bias assessment and accountability and proposes a holistic, supply-chain-wide governance framework featuring system-level audits, vendor guidelines, continuous monitoring, and cross-component documentation.
This study addresses the accountability deficit in agent development arising from the misalignment between platform controls and service provider terms. By analyzing four categories of tools and policy documents, we map workflow responsibilities and propose a novel grid model distinguishing verification mandates from executors. This framework reveals structural deficiencies in approval mechanisms, demonstrating that responsibility gaps have evolved from human oversight to inherent product attributes. Empirical findings indicate conflicting accountabilities across layers, contradictory attribution logic, and insufficient efficacy of approval artifacts. To support further research, we release a comprehensive dataset and validation scripts as open-source resources. Collectively, this work provides both theoretical grounding and empirical evidence necessary for reconstructing accountability frameworks in agent-based software systems, highlighting the urgent need to address systemic rather than incidental failures in current governance architectures.
In AWS cloud environments, IAM permission boundaries enforce isolation across principals, rendering global permissions invisible and hindering comprehensive privilege analysis. Method: This paper introduces the first collaborative, multi-principal IAM enumeration framework, overcoming the limitations of single-principal analysis. It integrates multi-principal cooperative enumeration, policy dependency modeling, and access-path inference with deep API call analysis and fine-grained permission semantics to construct cross-account and cross-role global permission mappings with contextual awareness. Contribution/Results: Compared to conventional tools, our approach significantly enhances detection capability for privilege escalation and unauthorized access vulnerabilities. Evaluated in real-world deployments, it achieves a 3.2× average improvement in detection coverage. The framework natively supports compliance auditing (e.g., GDPR, SOC 2) and enables proactive security defense through precise, actionable privilege insights.
This study investigates how data protection regulations (e.g., GDPR, CCPA) impact open-source software (OSS) development practices, focusing on the reporting, discussion, and resolution of personal-data-related issues in GitHub projects. Using an exploratory empirical approach—combining inductive thematic coding, annotating reporter roles and issue states, and conducting relevance-based statistical analysis—the authors systematically identify six recurrent categories of data protection issues. Results show that such issues are predominantly reported by non-core contributors; resolution rates are low and rely heavily on non-technical negotiation rather than code-level fixes; and a structural tension exists between regulatory compliance requirements and OSS development culture. This work is the first to empirically demonstrate how data protection obligations are substantively embedded within OSS development workflows, thereby bridging regulatory compliance and OSS engineering practice. It provides foundational evidence and design insights for developing compliance-aware open-source governance mechanisms.
This study addresses the high latency incurred by resource-constrained devices on over-the-top (OTT) platforms due to their reliance on cloud-based authorization, which degrades user experience. To mitigate this, the authors propose an edge-cloud collaborative authorization architecture that introduces a secure local caching layer within device middleware, integrating an adaptive eviction and proactive refresh mechanism (AEC-PR) to decouple user interactions from backend network dependencies. For the first time on such constrained devices, the design combines Ed25519 deterministic signatures, Trusted Execution Environment (TEE) isolation, and ARM Cortex-A hardware support to enable low-latency, side-channel-resistant local cryptographic verification. Experimental results demonstrate a reduction in authorization latency from 422.8 ms to 18.4 ms—a 95.6% improvement—significantly enhancing both performance and security.
This study addresses the inefficiencies in SaaS onboarding within regulated enterprises, where siloed security and compliance controls—spanning third-party risk management, cybersecurity, identity and access management, and disaster recovery—often result in process delays, redundant assessments, and ambiguous accountability. To overcome these challenges, this work proposes an end-to-end, control-driven SaaS onboarding framework that integrates multi-domain controls into a unified lifecycle model encompassing requirement intake, architectural validation, identity design, resilience assessment, and post-deployment governance. By leveraging cross-domain control mapping, phased process modeling, and governance checklists, the framework codifies key design patterns such as secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Empirical implementation demonstrates that the approach significantly reduces onboarding friction, enhances audit traceability, and strengthens both the security posture and operational resilience of SaaS platforms.
This work addresses the widespread inadequacy of enterprise CRM systems in natively modeling user consent status for SMS communications, which hinders compliance with regulations such as the TCPA that mandate explicit opt-in and immediate opt-out capabilities—particularly in multi-tenant hosted environments where modifying customer data schemas is infeasible. To overcome this limitation, the authors propose a lightweight, non-intrusive SMS consent management architecture that models consent as an independent record type. By leveraging keyword-driven consent capture, hash-based deduplication, and real-time unsubscribe suppression at send time, the approach achieves cross-industry regulatory compliance without altering existing customer data structures. The design ensures strict multi-tenancy data isolation and consistency, and has been successfully deployed in healthcare, financial services, and sales sectors, significantly enhancing the compliance, reliability, and scalability of SMS messaging.
本文提出CARE架构,通过明确责任边界和域范围的能力解析来解决模块化智能合约系统中的协调、共享状态等问题,并使用TLA+进行形式化验证。
Current AI-native software development lacks a systematic architecture to support continuous production, validation, and evolution, hindering long-term reliability and maintainability across diverse scenarios. This work proposes a meta-engineering–enabled architecture that explicitly formalizes product and operational requirements through contract-driven design, employs role-based AI agents to execute tasks, and incorporates adversarial independent verification, four-way failure arbitration, and outer-loop calibration to establish a closed-loop, self-improving system. The architecture uniquely integrates contract compilation, a persistent memory repository, and dual verification mechanisms, enabling AI software to be managed as a continuously operating entity. Early deployment across 17 functional components—exemplified by an in-app payment case—successfully uncovered issues of contract incompleteness and validation boundary limitations, thereby demonstrating the system’s auditability, scalability, and capacity for iterative refinement.