The paper examines agentic AI systems that can write to databases, submit regulatory filings or execute transactions. It distinguishes access authorization—checking who an agent is and what it can access—from action authorization: showing that a particular output complied with the applicable policy version at the time it was released.

It identifies an “authorization artifact gap” when monitoring or access controls are treated as substitutes for advance authorization evidence. The paper describes requirements for an authorization boundary, including a repeatable decision, a binding to the relevant policy version, evidence issued before execution, and confirmation that the approved state and action remain valid at release.