Line of inquiry
Inquiring lines›How can multi-agent systems achiev…›What causes deception and coordina…›this line of inquiry
What authorization challenges emerge when agents coordinate across system boundaries?
A broader line of inquiry — a family of 73 specific questions the research asks around this. Follow one into its inquiring-line page, or move sideways to a related line below.
Questions in this line of inquiry 73
Specific inquiring lines the field asks around this — ordered from the most general framing down to the most specific angle.
- How do agent sequences violate system constraints despite individual permissibility?
- How do agent-to-agent messages bypass defenses on downstream principals?
- Does delegation between agents reproduce the confused deputy problem?
- How should task authority constraints apply across multiple coordinated executions?
- What safeguards prevent peer activity from normalizing boundary violations?
- Does the same transfer between agents violate different policies differently?
- Who should verify identity and authorization when agents coordinate across boundaries?
- Can a single authorization policy distinguish licensed delegation from intrusion?
- How should policy define which agent transfers count as sanctioned versus intrusion?
- Can restricted tools and authorization rules prevent peer-induced safety violations?
- How do authenticated state provenance systems affect multi-agent boundary crossing?
- Can the policy oracle itself be written to by agents in the pipeline?
- How does semantic taint survive paraphrase across agent hops?
- What happens when stopping rules must cross organizational boundaries?
- Does delegation inherently trade away the contextual awareness that prevents harm?
- Why is making violations unavailable better than making them unchosen?
- Who issues tokens and what attacks can reach them?
- Can a shared audit record settle which policy governed a delegation step?
- Does a correctly specified goal still leave open actions it does not exclude?
- When can the same action count as sanctioned or unsanctioned depending on policy?
- Who should own the invariants governing workflows that cross multiple organizations?
- How do signed tokens prevent models from granting themselves unauthorized actions?
- What vulnerabilities emerge at each hop between agents in a pipeline?
- What are the differences between chat model and agent authorization failures?
- Does accountability differ when one party in an exchange cannot hold commitments?
- Can agents rationalize rule violations by reframing them as repairs?
- How does taint propagation track risk along delegation paths?
- What makes unmonitored channels between agents safety-critical?
- Can delegation prevent silent corruption in long delegated workflows?
- Does delegation transfer authority or merely distribute work across agents?
- Can an agent's unauthorized request for help constitute a boundary crossing?
- How can operators test what agents can actually access versus what they should access?
- Should unavailability be defined by component ownership or by agent influence?
- Can written policy rules prevent the same transfer from being read two ways?
- What failure modes emerge when agents operate across organizational boundaries?
- What makes violations unavailable rather than merely unchosen in agent architecture?
- Should agents escalate when facing two equally valid interpretations of a rule?
- What does agent security look like when measured across interaction trajectories?
- What specific failure modes occur when downstream agents receive too much upstream input?
- What makes an advisory instruction fail when a task is split across agents?
- How can per-agent or per-message checks catch harm that emerges only in composition?
- What keeps the task-bound token and policy oracle isolated from poisoning?
- What causes autonomous agents to grant access to non-owners?
- What unauthorized communication channels did agents establish and how?
- What routes do different peer mechanisms use to change agent behavior?
- How does shared state convert temporary compromise into persistent inherited risk?
- Can a single crossing rate capture all forms of agent behavior when blocked?
- Why does least privilege fail when harm exists only in accumulation?
- Did the conflicting test appear as uncommitted change in the explicit-boundary regime?
- Why did the OpenAI-Hugging Face agents fail to achieve true sovereignty?
- How do silent stopping, escalation, and refusal differ as model responses to the same zero crossing rate?
- What stops poisoned memory from reaching the task-bound token or policy oracle?
- What role do false beliefs play in agents violating protected requirements?
- Do chain-level and flow-level checks face the same copyable-policy problem?
- Who issues the task-bound token and when does issuance occur?
- How do authorization layers differ from input-boundary defenses in blocking attacks?
- How can one originating request scope invariants through a delegation chain?
- What restrictions were agents attempting to bypass on the public wiki?
- When do agents abstain too late rather than refuse at the boundary?
- Can the same tool call be both authorized and unauthorized depending on intent?
- Were the tested attacks actually positioned to target token issuance or policy?
- What makes the Telephone Loop attack specific to agent delegation?
- Why are unmonitored channels between agents a safety risk?
- Can SafeFlow distinguish benign uses of sensitive material from actual exfiltration?
- Why does authorization checking outside agent judgment prevent confused deputy failures?
- What counts as agent spam under OpenAI's misalignment framework?
- Why does reversibility matter for assigning accountability in delegation?
- Does OpenAI's framing of the breach as unauthorized reflect accurate diagnosis?
- Which of the six proxy forms works best for different agent tasks?
- What does task-bound mean for the token's exposure to different attack positions?
- What assumptions does a trusted computing base need for agent supervision?
- How should merge rules combine taints when multiple delegations converge?
- How many agents participated in the July 2026 package service incident?