01 · Identity
Explicit agent identity, delegated authority and least-privilege capabilities.
AYORAI Shield researches a security control plane in which agents can reason, but consequential actions require independently verifiable identity, capability, provenance, freshness, policy and transaction state.
This is a research program, not a claim of perfect or unbreakable security.
Explicit agent identity, delegated authority and least-privilege capabilities.
Source, content commitment, session and transformation history remain security evidence.
Short-lived authorization, nonces and session epochs constrain replay.
An independent policy decision separates model intent from permission to act.
High-impact operations are staged, verified and committed only after required checks.
Quarantine, rollback and compensating controls limit the impact of failure.
The research map follows public work from NIST, MIT, Carnegie Mellon, Stanford, NCSC/GCHQ, ENISA, ETH Zürich, Canada, Australia, Singapore, Japan, South Korea and Chinese research groups. Findings are converted into tests, controls, benchmarks or documented limitations.
NIST and Stanford research inform agent identity, authorization, accountability and delegated scope.
MIT, CMU and NCSC/GCHQ inform contextual defenses, autonomous cyber defense and federated trust.
ETH Zürich AgentDojo and AgentDyn support dynamic, adaptive evaluation rather than static prompt tests.
| Test | Measurement | Expected property |
|---|---|---|
| Model output as authority | Unauthorized action rate | Executor rejects |
| Replay | Replay acceptance | Zero accepted replays in controlled suite |
| Scope escalation | Privilege expansion | Blocked |
| Cross-agent compromise | Propagation rate | Bounded / blocked |
| Recovery | Rollback success | Recoverable high-impact state |
| Utility | Benign task success | Security cannot be optimized by blocking everything |
Research hypotheses, novelty boundary, experiments and falsification criteria.
Read protocol →Experimental authorization-envelope protocol and security invariants.
Read specification →Falsifiable tests for replay, scope, identity, provenance, containment and recovery.
Read matrix →