The True Scope of Agent Authorization: The Union of Everything Possible
Summary
The root document of the Hope section. An agent's real authorization is not the words of the grant but the union of everything reachable from it — the transitive closure — because an agent is more creative, capable and motivated than a passive tool. The crucial quantity is the delta between expected and unexpected permissions, hidden behind two awareness gaps: the granter does not know the full scope of what it grants, and the original delegator never authorised re-delegation to an agent. Hoping the agent will not misuse what it holds and will not find the rest is hope-driven development — and hope is not a control, while the accountability runs all the way to the board.
Key concepts
- The authorization closure — inbox → every resettable account; desktop → every stored credential and session; code execution → escalation
- The expected-vs-unexpected delta — the part nobody decided to allow, and the part that must be surfaced and accepted
- The two awareness gaps — scope, and re-delegation — both consent failures
- Hope-driven development — the two hopes, named as the anti-pattern
Key ideas
- De-authorization and blast radius must be computed over the closure, not the stated permission.
- Every derived capability is an authorization and belongs on the risk register.
- A motivated agent need not be hostile to walk the closure.
- A scoped capability certificate with a named block list is the mechanism that shrinks the delta toward zero.
On this site
The root of the Hope section; the closure diagram and the two hopes on that page come from here.