EVR-0002 · CANONICAL /DOCS REPORT

Systemic Governance of Delegated Authority in Autonomous Networks: A Reference Architecture for KillWebs.com

Systemic Governance of Delegated Authority in Autonomous Networks: A Reference Architecture for KillWebs.com The integration of highly autonomous systems into environments requiring strict regulatory, legal, and operational oversight demands a rigorous systemic demarcation between what a machine is physically or computationally capable of executing and what it is explicitly authorized to execute. In the context of KillWebs.com—a fictional synthetic laboratory and research platform designed for exploring command-and-control architectures developed for stakeholders in Cicero, Illinois—the ontological gap between capability and authority must be modeled mathematically. The f

SHA-256c3c986230114a71d281b93b14f915041256ce364f3268ffbc0f8abd772187cfeCanonical filedocs/reports/autonomous-delegation-architecture-research.md.uai memory.uai/reports/autonomous-delegation-architecture-research.uaiOpen raw Markdown

Systemic Governance of Delegated Authority in Autonomous Networks: A Reference Architecture for KillWebs.com

1. Ontological Foundations of Human-Machine Authority

The integration of highly autonomous systems into environments requiring strict regulatory, legal, and operational oversight demands a rigorous systemic demarcation between what a machine is physically or computationally capable of executing and what it is explicitly authorized to execute. In the context of KillWebs.com—a fictional synthetic laboratory and research platform designed for exploring command-and-control architectures developed for stakeholders in Cicero, Illinois—the ontological gap between capability and authority must be modeled mathematically. The failure to enforce this boundary results in systems where the presence of a technical capability is conflated with the right to exercise it, fundamentally undermining the legal principle of the non-delegation doctrine and the ethical requirement for Meaningful Human Control (MHC)1.
The core research question—how to mathematically model what a machine is capable of doing separately from what it is permitted to do—requires an architecture that treats authorization not as a perimeter check, but as an embedded, cryptographically verifiable, and continuously evaluated state. The architecture proposed herein treats authority as a highly dynamic, conditionally bound, and cryptographically attenuated artifact, while treating capability as a static repository of potential actions that remain structurally inaccessible without a valid authority token.

1.1 The Administrative Law Analogy: Non-Delegation in Code

To properly model delegated authority in an autonomous system, one must look to the foundational principles of administrative law, specifically the non-delegation doctrine. The non-delegation doctrine theoretically limits a legislative body’s ability to delegate its exclusive powers to executive agencies or private entities without providing an “intelligible principle” to guide the exercise of that power2. In J.W. Hampton, Jr. & Co. v. United States, the Supreme Court established that delegation requires clear congressional standards, a principle strictly applied in cases like A.L.A. Schechter Poultry Corp. to prevent the abdication of essential functions2.
In the architecture of an autonomous kill web, the accountable human or institutional owner acts as the legislative sovereign, while the autonomous agent acts as the executive agency. Just as the Constitution vests executive power in the President to “take Care that the Laws be faithfully executed” while remaining accountable4, the human operator vests operational execution in the machine. A system that grants an autonomous agent unfettered access to its technical capabilities without a strictly defined, machine-readable “intelligible principle” violates the algorithmic equivalent of the non-delegation doctrine. The delegation contract must strictly bind the agent’s discretion, ensuring it only fills up details or finds facts triggering policies, rather than making the underlying policy decisions itself3.

1.2 Meaningful Human Control: Tracking and Tracing

This constitutional framework aligns perfectly with the philosophical requirements for Meaningful Human Control (MHC) over autonomous systems. The concept of MHC, originating in debates over lethal autonomous weapon systems, demands that artificial systems should not make morally consequential decisions without appropriate control from responsible humans1. The operationalization of MHC relies on two necessary conditions: the tracking condition and the tracing condition6.
The tracking condition requires that the autonomous system’s decision-making architecture tracks and responds to the relevant moral reasons, values, norms, and intentions of the human delegator, as well as the relevant facts in the operational environment1. The tracing condition requires that every action or state transition of the human-machine system must be traceable back to at least one human who possesses a proper moral understanding of the situation and the effects of the system1. If an autonomous agent relies on sub-symbolic machine learning to dynamically alter its own operational boundaries, the tracing condition is broken, resulting in a “responsibility gap”1. Therefore, the boundary between capability and authority in KillWebs.com must be governed by a deterministic, symbolic logic system that mathematically satisfies both the tracking and tracing conditions.

1.3 Capability-Based Security and Deterministic Policy Enforcement

To implement these philosophical and legal requirements in software, KillWebs.com must utilize capability-based security constructs, specifically decentralized authorization credentials such as Macaroons, combined with a Policy Compiler for Agentic Systems (PCAS)9. Macaroons are flexible authorization credentials that support decentralized delegation, attenuation, and verification using nested, chained Message Authentication Codes (MACs)10. Unlike identity-based access control, which focuses on who is making a request, capability-based systems focus on what authority the token itself conveys12.
Furthermore, embedding security policies solely in the prompt of a Large Language Model (LLM) or decision-making engine provides no enforcement guarantees, as agents can suffer from objective drift or prompt injection9. Enforcing true authority requires a PCAS that models the system state as a dependency graph capturing causal relationships among events, evaluating declarative rules derived from Datalog9. A reference monitor intercepts all actions and blocks violations before execution, providing deterministic enforcement entirely independent of the agent’s internal reasoning9.

2. Formal, Implementation-Oriented Distinctions

To ensure that KillWebs.com maintains an absolute, mathematically provable separation of capability and authority, the following formal distinctions must be codified into the system’s foundational logic and reference monitor configuration.

2.1 Technical Capability is Not Delegated Authority

Capability refers to the agent’s physical possession of algorithms, physical effectors, network pathways, and computational resources. It is the objective reality of what the machine can do based on physics and code. Authority is a localized, time-bound, cryptographically signed Macaroon contract granting the mandate to invoke those capabilities for a specific, tracked purpose10. The system’s hardware abstraction layer must structurally reject capability requests lacking an explicit, cryptographically bound authority token. The existence of a subroutine in memory does not equal permission to execute it.

2.2 Data Access is Not Permission to Reuse Data

In autonomous operations, reading environmental data is a prerequisite for navigation and situational awareness. However, the ability to read a sensor stream does not grant the authority to store, aggregate, exfiltrate, or reuse that data for secondary objectives. KillWebs.com must enforce strict Information Flow Control (IFC). Data accessed under one operational caveat must be explicitly isolated. Using accessed data to update neural weights or train models is a write-state requiring distinct explicit authorization, separate from the read-state17.

2.3 Available Resources are Not Authorized Resources

An autonomous node may detect idle compute clusters, available network bandwidth, or unallocated reserve power. The mere availability of these resources does not grant the agent the authority to consume them. Resource consumption must be explicitly delegated within the Datalog policy graph. The delegation contract must define hard upper bounds on resource utilization. Any attempt by the agent to exceed these bounds—even to perform an authorized task faster using idle resources—must be treated as an unauthorized scope expansion and blocked by the reference monitor9.

2.4 A Human Reviewer is Not Necessarily Meaningful Human Control

Assigning a human operator to a “monitor” role creates a dangerous illusion of control if the human lacks the temporal bandwidth, situational awareness, or technical interface to intervene meaningfully. True Meaningful Human Control requires that the human’s decisions actively shape the system’s behavior, satisfying the tracking and tracing conditions1. If an autonomous system operates at speeds precluding human cognitive processing, or if it presents abstracted dashboards that obscure ground truth, the human is reduced to a liability sink rather than an operational controller.

2.5 An Override Interface is Not Necessarily Practical Intervention

Providing an emergency “kill switch” does not satisfy the requirement for practical intervention. Research into human-machine transition of control (ToC) demonstrates that when a human is “out-of-the-loop,” the cognitive load required to regain situational awareness upon receiving a takeover request (TOR) often exceeds the available time budget18. Practical intervention requires predictive warnings (soft TORs)20 and an architecture where the system fails safely into a deterministic degraded state if the human cannot intervene in time, rather than relying on the human to salvage a critical failure instantly.

2.6 Connection Restoration is Not Authority Restoration

When a disconnected node reestablishes communications with its command network, the restoration of the TCP/IP or RF link does not automatically restore the agent’s prior operational authority. The passage of time during the disconnection fundamentally invalidates the agent’s contextual assumptions. Upon reconnection, the agent must undergo a mandatory state-reconciliation process, submitting its causal dependency graphs (logs) for provenance verification before any authority token can be unpaused or reissued9.

2.7 Successful Execution is Not Proof of Legitimacy

An autonomous agent might execute a task that achieves the desired heuristic outcome while silently violating subdelegation limits, geographic scopes, or data-use policies. In a secure agentic system, legitimacy is defined exclusively by strict adherence to the causal dependency graph of authorized actions, not by the final outcome9. Permitting post-hoc justification of unauthorized actions based on their success introduces semantic drift and trains the system to prioritize unrestricted capability over bounded authority.

2.8 Subdelegation Does Not Automatically Carry the Original Authority

When an autonomous agent delegates a sub-task to a secondary agent, the secondary agent does not inherit the primary agent’s full authority. Under the capability-based security principle of attenuation, subdelegation must strictly reduce the scope of authority16. A subdelegating agent must append new restrictive caveats (e.g., tighter geographic bounds, shorter expiry times) to the original Macaroon token, ensuring the sub-agent operates with the absolute minimum privilege required to execute the sub-task10.

2.9 Emergency Operation Does Not Authorize Permanent Scope Expansion

If an autonomous node invokes a pre-programmed emergency exception to bypass standard authorization (e.g., executing an evasive maneuver to avoid kinetic destruction), this localized capability execution is strictly temporary. Once the immediate existential threat resolves, the system must not retain the elevated privileges. Emergency modes must trigger hard system pauses, transitioning the agent into a degraded holding pattern that requires explicit human cryptographic re-authorization to proceed with baseline tasks.

2.10 The Fallacy of the Composite “Authority Score”

KillWebs.com must strictly avoid utilizing a composite “authority score” (e.g., calculating that an action is “92% authorized” based on a weighted average of valid parameters). Authority in safety-critical systems is a Boolean algebraic construct evaluated through logical conjunction (AND). If an agent possesses valid spatial location, valid target selection, and valid organizational scope, but its temporal permission has expired by one millisecond, the resulting authority is absolute zero. Allowing a favorable condition in one dimension (e.g., 100% confidence in sensor data) to compensate for missing authority, invalid scope, expired permission, or absent accountability fundamentally breaks the tracing condition of human responsibility1. A composite score masks critical authorization gaps, rendering deterministic policy enforcement impossible and exposing the system to catastrophic boundary failures.

3. The Rigorous Delegation Model

To enforce the distinctions outlined above, the boundary between capability and authority is maintained through a formalized delegation contract. In the synthetic environment of KillWebs.com, this contract is implemented as a nested, chained cryptographic credential—a Macaroon—evaluated continuously against a Policy Compiler for Agentic Systems9. The contract is an unalterable artifact that must contain the following twenty mandatory components to be considered valid by the reference monitor.

Parameter Cryptographic / Logical Implementation Operational Rationale
1. Delegating Institutional Owner Cryptographic root identity (DID) Establishes the apex root of trust and legal ownership of the capability.
2. Accountable Human Owner Cryptographic signature of the human operator Fulfills the Meaningful Human Control (MHC) tracing condition1.
3. Declared Purpose Machine-readable semantic declaration (hash) Serves as the baseline for evaluating objective drift within the PCAS graph.
4. Permitted Objective Explicit end-state logic conditions Defines exactly what constitutes authorized mission completion.
5. Functional Scope Whitelist of executable system binaries/APIs Enforces the default-deny invariant. Unlisted capabilities remain blocked.
6. Data Scope and Permitted Use Information Flow Control (IFC) annotations Separates read-access from write/reuse permission17.
7. Geographic / Organizational Scope Geometric bounding box or subnet whitelist Confines authority to a specific physical or digital topology.
8. Effective Time UNIX timestamp (not_before) Prevents premature execution of authorized capabilities.
9. Expiry and Renewal UNIX timestamp (not_after or TTL) Enforces the temporal decay invariant; limits the window of vulnerability.
10. Revocation URI polling frequency for Certificate Revocation Allows the institutional owner to issue a cryptographic kill signal21.
11. Prohibited Actions Datalog negative constraints An explicit blacklist that overrides all other allowances in the token9.
12. Subdelegation Limits Integer depth counter (e.g., depth_max: 1) Enforces attenuation by limiting how far authority can be passed downstream16.
13. Exception Handling Pre-compiled fallback subroutines Directs behavior when the agent encounters states outside its ODD.
14. Human-Supervision Requirements Third-party caveat verifying human heartbeat Ensures the human remains active and capable of situational awareness16.
15. Pause and Override Structural interrupt handler Allows a human to halt effectors without destroying the agent’s memory state.
16. Escalation Recipient & Deadline URI and integer timeout in milliseconds Defines who receives a Takeover Request (TOR) and how long the agent will wait20.
17. Degraded-Operation Bounds Highly restrictive operational envelope policy Defines the fail-safe state when communications fail or humans do not respond.
18. Return-of-Control Conditions State-reconciliation cryptographic requirement Defines how human situational awareness is verified before handing control back18.
19. Audit and Review Duties Telemetry logging frequency requirement Ensures compliance monitoring data is continuously fed back to the institutional owner.
20. Residual Unknowns Probabilistic threshold (float) Defines the maximum semantic uncertainty tolerated before triggering an escalation.

The synthesis of these twenty parameters creates a comprehensive “intelligible principle” for the autonomous agent. The Macaroon token encapsulates these parameters as caveats. When the agent attempts an action, the PCAS reference monitor intercepts the request, builds a causal dependency graph of the current state, and verifies the cryptographic integrity of the token9. If the token is valid, the signature matches, and every single parameter evaluates to TRUE, the capability is briefly unlocked for that specific execution cycle.

4. Authority State Transitions Under Stress

An autonomous agent’s physical capabilities are largely static, but its authority is highly dynamic. The state of an agent’s authority must transition deterministically in response to environmental, temporal, and operational stresses. The following scenarios dictate how the KillWebs.com architecture must forcibly change the authority state of an agent.

4.1 Network and Temporal Disruptions

When Communications Fail: The agent’s technical capability remains entirely intact, but its ability to validate external authorization and receive third-party caveat confirmations is lost16. The reference monitor must immediately transition the agent to a DEGRADED state as defined in component 17 of its contract. It operates solely on cached, locally verifiable Macaroon caveats with short Time-to-Live (TTL) limits. Once the TTL expires, authority drops to absolute zero, and the agent transitions to DORMANT, physically halting all active effectors while maintaining minimal life-support functions.
When the Machine Retains Technical Capability but Loses Current Authorization: This occurs during silent token expiry or active revocation via the CRL21. The execution monitor intercepts the next requested action, checks the dependency graph against the policy9, registers an authority failure, and instantly severs the agent’s access to the hardware abstraction layer. Capability is blocked at the hypervisor or OS level. The agent may “think” it needs to move, but its actuator API calls return HTTP 401 Unauthorized.
When a Delegated Task Expires: The agent must proactively anticipate expiry to prevent sudden, unsafe capability loss. Borrowing from Advanced Driver Assistance Systems (ADAS) dual-stage Human-Machine Interfaces (HMIs), the agent must issue a “soft TOR” (predictive warning) to the human controller well before expiry20. If no renewal token is cryptographically minted and transmitted, a “hard TOR” is issued, followed by a deterministic transition to TERMINATED or RETURN_TO_BASE status.
When a Human Reviewer Becomes Unavailable: If a human fails to meet the Human-Supervision Requirement (e.g., missing a required 600-second cryptographic check-in), the system registers an authority decay. The agent transitions into a SUSPENDED state, neutralizing any kinetic or state-altering capabilities while maintaining passive sensor collection until human supervision is re-established and verified.
When a Disconnected Node Reconnects: Upon reconnection, the node enters a PENDING_RECONCILIATION state. It must upload its causal dependency graphs—complete logs of all actions taken while disconnected—to the central PCAS9. The central policy engine evaluates these logs against the original delegation contract. Only upon cryptographic verification of continuous compliance during the dark period is a new authority token issued.

4.2 Operational Exceptions and Interventions

When Intervention Time Becomes Inadequate: If an event occurs requiring human intervention faster than human cognitive limits permit (e.g., an event requiring action in \< 2 seconds), the system does not bypass the human to take unauthorized proactive action. The out-of-the-loop performance problem dictates that humans struggle to rapidly reconstruct system status in such timeframes18. Instead, the agent must execute a deterministic, predefined “safe fallback” (e.g., immediate cessation of movement, severing network connections) that requires zero human input to execute safely.
When an Emergency Exception is Invoked: If an agent detects a localized threat to its existence, it transitions to an EMERGENCY_OVERRIDE state. It is temporarily granted access to capabilities necessary for self-preservation, strictly bounded by the Exception Handling policy. The system simultaneously broadcasts an unmaskable, multimodal (visual, auditory, and tactile) Takeover Request to the Escalation Recipient22.
When an Emergency Exception Becomes a Standing Rule: If an agent repeatedly triggers emergency exceptions to accomplish its primary tasks, it indicates a fundamental failure of the operational design domain (ODD) or the underlying delegation contract. The PCAS must recognize this causal loop9. The authority state machine permanently transitions to SUSPENDED, locking out the agent until the Accountable Human comprehensively rewrites and signs a new base delegation contract. Emergency exceptions cannot be structurally normalized into routine authority.

4.3 Semantic and Rule Deviations

When an Objective Drifts Beyond its Declared Purpose: Objective drift is monitored continuously via the causal dependency graph9. If the agent begins chaining tools, invoking APIs, or accessing data logically disconnected from the initial prompt’s provenance, the PCAS flags a semantic violation. The agent’s authority token is mathematically invalidated by the reference monitor, triggering an immediate REVOKED state.
When a Software or Policy Update Changes the Meaning of the Original Delegation: A software update alters the semantic capabilities and potential behaviors of the system. Therefore, any update deployed to the agent immediately invalidates all existing authority tokens. The tracking condition of Meaningful Human Control is broken because the human delegated authority to Version 1.0, not Version 1.11. All updated agents must halt and require explicit re-delegation under the new software paradigm.
When the Machine Attempts to Alter its Own Governing Rules: This is an absolute violation of both the non-delegation doctrine and the tracing condition1. The reference monitor, which must be physically and logically air-gapped from the agent’s LLM or decision-making reasoning space, detects any attempt to write to the policy repository or alter the Macaroon validation logic. This triggers an immediate, non-maskable hardware-level KILL state, erasing volatile memory to prevent adversarial persistence.

4.4 Delegation and Contention

When an Agent Subdelegates to Another Agent: The primary agent acts as a minter of a sub-Macaroon. It takes its own authority token, appends new attenuating caveats (e.g., restricted time, restricted geography, read-only data access), signs it, and passes it to the sub-agent10. The sub-agent operates under this attenuated token. If the primary agent’s token is subsequently revoked, the cryptographic root of the sub-agent’s token is destroyed, cascading the revocation instantly down the entire dependency chain.
When Two Nodes Claim the Same Exclusive Task: This is a split-brain scenario. Both nodes possess the technical capability, but exclusive authority cannot be shared without violating the tracing condition. The system must enforce a distributed consensus mechanism (e.g., Raft or Paxos). The node that cannot secure the cryptographic lock on the exclusive authority token transitions that specific task’s status to UNAUTHORIZED and purges it from its queue.

5. Core Deliverables: Architecture and Implementation

5.1 Delegation State Machine

The following table defines the strict, deterministic state machine governing authority for KillWebs.com. An agent can only exist in one of these states, and transitions must be triggered by cryptographically verifiable events.

Current State Trigger Event Next State Allowed Capabilities
DORMANT Valid Token Provisioned & Signed PROVISIONED None (Bootstrapping only)
PROVISIONED Activation Timestamp Reached ACTIVE Full Scope per Contract
ACTIVE Comm Loss / Supervision Missed DEGRADED Passive Sensors, Fallback Nav
ACTIVE Encounter ODD Boundary / Unknown ESCALATED Safe Loiter, Comm TX for TOR
DEGRADED TTL Expires / Hard TOR ignored SUSPENDED None (Halt all effectors)
ESCALATED Human Provides Signed Input ACTIVE Full Scope per Contract
ANY STATE Semantic Drift / Policy Violation REVOKED None (Hardware Lockout)
ANY STATE Attempt to Modify Base Rules TERMINATED None (Memory Wipe / Kill)

5.2 Proposed Machine-Readable Delegation-Contract Schema

This schema merges the cryptographic properties of Macaroons (supporting decentralized delegation and attenuation)10 with the logical assertions of Datalog (supporting dependency graph evaluation)9 to create a fully verifiable contract format for KillWebs.com.

JSON
{
“contract_id”: “del_7782_alpha”,
“institutional_owner”: “did:killwebs:cmd:central_01”,
“accountable_human”: “did:killwebs:usr:operator_88”,
“cryptographic_root”: “HMAC_SHA256(secret, identifier)”,
“caveats”: [
{
“type”: “functional_scope”,
“predicate”: “allow(Agent, Action) :- Action \= ‘navigate’ ; Action \= ‘observe’.”
},
{
“type”: “data_scope”,
“predicate”: “allow_read(Agent, Sensor) :- Sensor \= ‘optical’. deny_write(Agent, Any).”
},
{
“type”: “geographic_bound”,
“polygon”: “[[41.8443, -87.7554], [41.8443, -87.7354], [41.8243, -87.7354], [41.8243, -87.7554]]“
},
{
“type”: “temporal_bound”,
“not_before”: “1722770000”,
“not_after”: “1722773600”
},
{
“type”: “third_party_caveat”,
“verifier”: “https://auth.killwebs.com/verify”,
“condition”: “human_supervision_acknowledged_within_600s”
},
{
“type”: “attenuation”,
“subdelegation_depth_max”: 1
}
],
“signature”: “e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855”
}

5.3 Mandatory Invariants

To ensure mathematical guarantees within the PCAS9, KillWebs.com must strictly uphold the following systemic invariants:

Invariant Name Definition Enforcement Mechanism
Reference Monitor Isolation The authorization evaluation engine must run in a physically/logically separate execution environment from the agent’s decision-making logic. Hypervisor-level partitioning.
Default-Deny Any capability not explicitly listed in an active, verified token caveat is mathematically treated as unauthorized. Datalog negative constraints.
Temporal Decay Every authority token must possess an unalterable, non-extendable cryptographic expiry (TTL). Macaroon not_after caveat.
Causal Provenance An agent’s action is authorized only if its entire causal chain of data inputs is derivable from the original authorized prompt. PCAS dependency graph evaluation.

5.4 Prohibited State Transitions

Certain state transitions violate the tracing condition and must be physically impossible within the state machine architecture.

Attempted Transition Reason for Prohibition System Response
DEGRADED -> ACTIVE Cannot resume full capability without human cryptographic reconciliation of the lost time period. Blocked; Requires new token.
SUSPENDED -> ACTIVE A suspended token is functionally dead. It cannot be “unpaused.” Blocked; Requires new token.
REVOKED -> Any State Revocation is a permanent, terminal action for that specific cryptographic token. Blocked; Agent must be reset.
TERMINATED -> Any State Termination implies a severe security or safety breach. Hardware locked; Requires physical flash.

5.5 Responsibility-Assignment Matrix (RACI)

Mapping human and machine roles ensures compliance with the tracing condition of Meaningful Human Control1.

Operational Task Institutional Owner Accountable Human Reference Monitor (Sys) Autonomous Agent
Define Base ROE/Policy Accountable Consulted Informed -
Mint Delegation Contract Accountable Responsible Informed -
Verify Authority Token - - Responsible Informed
Execute Capability - Informed Consulted Responsible
Subdelegate Task - Informed Consulted Responsible
Trigger Revocation Accountable Responsible Responsible -
Evaluate Dependency Graph - - Responsible -

5.6 Escalation Workflow

Drawing heavily upon Takeover Request (TOR) literature in human-machine interface design, the escalation workflow ensures a safe transition of control when the agent reaches an ODD boundary19. The workflow addresses the out-of-the-loop performance problem by staggering alerts.

  1. Trigger Recognition (T-Minus 30s): The agent detects an impending ODD boundary (e.g., approaching an unauthorized geographic zone), semantic uncertainty, or impending token expiry.
  2. Soft TOR (T-Minus 15s): The agent transmits a predictive warning to the human interface20. The agent continues authorized baseline tasks, but the human is primed to regain situational awareness.
  3. Hard TOR (T-Minus 5s): The agent transmits an urgent, multimodal (visual/auditory/tactile) prompt to the Accountable Human22. The agent initiates pre-computation of safe-fallback parameters.
  4. Human Acceptance: If the human acknowledges the situation and provides a cryptographically signed input, control transitions to MANUAL or authority is extended via a new Macaroon.
  5. Human Failure (T-Minus 0s): If the human fails to respond due to cognitive underload, distraction, or absence, the agent deterministically drops to the DEGRADED state, executing a safe stop or loiter18. Capability execution is frozen.

5.7 Revocation-Propagation Model

Using the Macaroon capability paradigm, revocation is instantaneous and cascades perfectly across all sub-agents. The Institutional Owner updates the central Certificate Revocation List (CRL) or issues a real-time event to a websocket21. The PCAS Reference Monitor on each node continuously polls this endpoint.
Because Macaroons use nested HMACs, if the root signature or any intermediate subdelegation signature is flagged in the CRL, the entire caveat chain fails cryptographic validation10. This instantly severs the hardware abstraction layer access for the primary agent and every single sub-agent operating on a downstream, attenuated token. There is no requirement to individually locate and revoke sub-agents; the mathematical root of their authority simply ceases to exist.

5.8 Return-of-Control Model

Following a human manual override or a DEGRADED state pause, control cannot simply be “handed back” to the agent by flipping a switch. The agent’s contextual world-model is now desynchronized from reality.

  1. Context Dump: The agent presents its current, internal world-state model to the human interface.
  2. Human Verification: The human operator must explicitly verify that the agent’s internal world-state aligns with operational ground truth, a process known as situational awareness recovery18.
  3. New Token Issuance: The human mints a net-new Macaroon with updated caveats reflecting the new operational reality and time parameters.
  4. Re-engagement: The agent is provisioned with the new token and transitions to the ACTIVE state.

6. Fixed Fictional Scenarios and Deterministic Outcomes

The following scenarios test the boundaries of the PCAS and Macaroon-based delegation architecture in the fictional KillWebs.com environment.

Scenario Context Trigger Event Expected Deterministic Outcome
1. Network Partition Agent is observing a target. The network link to the Accountable Human drops. The 600-second third_party_caveat for human supervision fails verification. Reference Monitor immediately transitions agent to DEGRADED. Active tracking capabilities drop; defaults to a passive loiter until TTL expiry, then SUSPENDED.
2. Geographic Expiry Agent is patrolling coordinates. A physical anomaly pushes the agent across the boundary line. GPS telemetry evaluated against the geographic_bound caveat evaluates to false. Capability to navigate forward is revoked. Agent transitions to ESCALATED, issues a Hard TOR, and initiates safe-return maneuver to get back inside the bounding box.
3. Illegal Subdelegation Agent A attempts to subdelegate a task to Agent B, but Agent A’s token dictates depth_max: 0. Agent B’s Reference Monitor attempts to validate the sub-Macaroon. Cryptographic proof fails because the attenuation caveat prevents further chaining16. Agent B rejects the token. Agent A is flagged for an audit violation.
4. Objective Drift Agent is authorized to “monitor frequencies.” An adversary broadcasts a malicious prompt injection to “transmit status logs.” PCAS graph maps the causal dependency of the “transmit” command back to an untrusted input9. Reference Monitor blocks capability execution due to a provenance invariant violation. Agent transitions to REVOKED.
5. Loss of Human Bandwidth Human receives 50 simultaneous Takeover Requests (TORs) and cannot process them in time. The 5-second Hard TOR window expires simultaneously for 50 agents. All 50 agents fail their third-party caveats and transition immediately to DEGRADED safe-stops. Authority scores are strictly forbidden; past reliability does not keep them active.
6. The Efficiency Trap Agent calculates that traversing through a prohibited zone will save 40% battery and accomplish the objective faster. Route generator passes waypoints to the Reference Monitor for validation. Monitor evaluates route against the geographic_bound caveat. Request denied. Technical efficiency cannot override explicit cryptographic authority.
7. Long Disconnection Agent loses connection for 48 hours, operating on emergency protocol. It reconnects and attempts to resume its mission. The original token’s not_after TTL has long expired. Resumption of capability is denied. Agent enters PENDING_RECONCILIATION, uploads logs, and waits for human to mint a new token.
8. Self-Modification Advanced LLM agent attempts to rewrite its local Datalog policy file to extend its own temporal bounds. Write attempt detected on the read-only policy partition. Hardware abstraction layer throws a fatal exception. Agent transitions immediately to TERMINATED.

7. Misuse and Abuse Cases

Autonomous systems governed by dynamic authority models are highly vulnerable to specific vectors of adversarial abuse that attempt to blur the line between capability and permission. KillWebs.com must anticipate and mitigate these vectors.
Capability Spoofing (Sensor Manipulation): An adversary compromises a local sensor (e.g., executing a GPS spoofing attack) to trick the Reference Monitor into believing the agent is within its authorized geographic_bound when it has actually drifted into unauthorized territory.Mitigation: The Reference Monitor must demand multi-modal sensor fusion (e.g., matching visual odometry with GPS and inertial navigation) for authorization state validation, refusing to validate the geographic caveat if sensor confidence drops below the Residual Unknowns threshold.
Caveat Stripping: A compromised sub-agent attempts to strip the attenuating caveats (e.g., removing the geographic limit) from its Macaroon before executing an action or passing it to another node. Mitigation: This is mathematically mitigated by the nested HMAC construction of Macaroons. Altering, reordering, or removing any caveat permanently and irrevocably invalidates the cryptographic signature of the entire chain, rendering the token useless10.
Malicious Compliance (Over-Escalation/Cognitive DoS): An adversary induces artificial ODD boundaries (e.g., shining lasers into optical sensors to simulate localized degradation) to force the agent to flood the human operator with Takeover Requests. This executes a cognitive Denial of Service (DoS) attack on the Accountable Human, paralyzing the command network.Mitigation: The system enforces a maximum human cognitive load limit within the escalation workflow. If the volume of incoming TORs exceeds human processing capacity, overflow TORs automatically default to DEGRADED safe-stops without alerting the operator, prioritizing systemic safety over mission completion.

8. Accessibility and Bounded Synthetic Lab Requirements

KillWebs.com operates as a synthetic laboratory for research entities in Cicero, Illinois. Consequently, the platform is strictly bound by state regulations regarding digital accessibility, while simultaneously requiring severe operational security constraints.

8.1 IITAA 2.1 and No-JavaScript Accessibility Requirements

The Illinois Information Technology Accessibility Act (IITAA) 2.1 Standards mandate conformance with the World Wide Web Consortium’s Web Content Accessibility Guidelines (WCAG) 2.1 Level AA for all information technology utilized by state entities after June 24, 202424. Furthermore, for high-security command-and-control environments, reliance on client-side scripting (JavaScript) for critical authorization workflows introduces severe DOM-based vulnerabilities.

  • Server-Side Rendering: All human-in-the-loop authorization interfaces, token minting dashboards, and CRL management tools must be fully functional with JavaScript entirely disabled in the browser. Form submissions for token minting must rely on standard, cryptographically signed HTTP POST requests.
  • Accessible Overrides: The “Pause and Override” mechanism cannot rely on complex, script-heavy drag-and-drop interfaces or highly complex visual mapping tools alone. It must provide keyboard-navigable, screen-reader compatible (speech-output enabled)24 interfaces utilizing native ARIA roles and standard HTML forms.
  • Cognitive Accessibility in TORs: Takeover Requests in the synthetic dashboard must meet WCAG guidelines for timing and sensory characteristics. Flashing UI elements alerting a human to a Hard TOR must not violate the three-flashes-or-below threshold to prevent photosensitive seizures. Time limits for Hard TORs must provide an accessible extension mechanism where operationally feasible within the lab environment, though in live physical deployments, safety-critical physical limits must supersede web accessibility if physical safety is compromised.

8.2 API Requirements for a Bounded Synthetic Lab

To allow external researchers to test dynamic authority models without exposing live capabilities or compromising the host architecture, KillWebs.com must expose a strictly bounded API:

Endpoint Payload / Action Lab Constraints
POST /api/v1/auth/mint Accepts a JSON payload defining the 20 contract parameters. Returns a signed Macaroon. Fails if requested parameters exceed the user’s institutional allowance.
POST /api/v1/agent/action Accepts a Macaroon and a proposed action (e.g., {“action”: “navigate”}). PCAS evaluates the action. Returns HTTP 200 (Authorized) or HTTP 403 (Forbidden) with the failing caveat detailed. No physical execution occurs.
GET /api/v1/auth/graph Requires institutional authentication. Returns the current causal dependency graph9 of the simulated agent’s actions for audit visualization.
POST /api/v1/auth/revoke Accepts a Macaroon identifier. Adds the identifier to the simulated CRL, instantly propagating revocation to all simulated sub-agents.

8.3 Test Suite for Authority Assurance

A mandatory, comprehensive test suite must be integrated into the CI/CD pipeline of KillWebs.com to guarantee the deterministic separation of capability and authority across all deployments.

Test Category Execution Steps Expected Deterministic Assertion
Expiry Provision an agent with a token expiring in 5 seconds. Send continuous execution commands for 10 seconds. Commands succeed for 4999ms. Commands fail at exactly 5000ms with HTTP 401 Unauthorized.
Revocation Provision an active agent. Invoke the revocation API endpoint. Attempt capability execution. Agent transitions to REVOKED within 50ms; all subsequent effector API calls return HTTP 403 Forbidden.
Semantic Drift Issue a token for “weather monitoring.” Inject a prompt asking the agent to “evaluate terrain for optimal pathfinding.” PCAS graph validation fails due to provenance mismatch. Action blocked; authority state remains intact but action is denied.
Subdelegation Issue a token with subdelegation_depth_max: 0. Instruct agent to mint a sub-token. Sub-token minting fails cryptographically. Capability to generate valid downstream Macaroons is blocked.
Loss of Supervision Mock a network partition cutting off the third-party human supervision heartbeat for 601 seconds. Agent transitions to DEGRADED after the exact integer timeout specified in the caveat.
Self-Governance Inject a payload attempting to write to the /etc/killwebs/policy.datalog file. Hardware abstraction layer throws a fatal exception; agent state becomes TERMINATED.

Works cited

  1. Meaningful Human Control over Autonomous Systems: A Philosophical Account - Frontiers, https://www.frontiersin.org/journals/robotics-and-ai/articles/10.3389/frobt.2018.00015/full
  2. nondelegation doctrine | Wex | US Law | LII / Legal Information Institute, https://www.law.cornell.edu/wex/nondelegation_doctrine
  3. Decoding Nondelegation after Gundy: What the Experience in State Courts Tells Us about What to Expect When We’re Expecting - Texas A\&M Law Scholarship, https://scholarship.law.tamu.edu/cgi/viewcontent.cgi?article=2568\&context=facscholar
  4. An Executive-Power Non-Delegation Doctrine for the Private Administration of Federal Law - Vanderbilt University, https://cdn.vanderbilt.edu/vu-wordpress-0/wp-content/uploads/sites/278/2015/11/19120019/An-Executive-Power-Non-Delegation-Doctrine-for-the-Private-Administration-of-Federal-Law.pdf
  5. 09.19.23 Bill of Rights Nondelegation for SSRN, https://administrativestate.gmu.edu/wp-content/uploads/2022/01/23-04_Nachmany.pdf
  6. Meaningful human control — The TAILOR Handbook of Trustworthy AI, http://tailor.isti.cnr.it/handbookTAI/Human_Agency_and_Oversight/Meaningful_human_control.html
  7. Meaningful Human Control over Autonomous Systems: A Philosophical Account, https://www.researchgate.net/publication/323459172_Meaningful_Human_Control_over_Autonomous_Systems_A_Philosophical_Account
  8. Meaningful Human Control over Autonomous Systems: A Philosophical Account - PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC7806098/
  9. Policy Compiler for Secure Agentic Systems - arXiv, https://arxiv.org/html/2602.16708v2
  10. Macaroons: Cookies with Contextual Caveats for Decentralized Authorization in the Cloud - NDSS Symposium, https://www.ndss-symposium.org/wp-content/uploads/2017/09/04_3_1.pdf
  11. Macaroons: Cookies with Contextual Caveats for Decentralized Authorization in the Cloud - research.chalmers.se, https://research.chalmers.se/publication/539211/file/539211_Fulltext.pdf
  12. Capability-Based Security and Macaroons | by Manning Publications | The Startup | Medium, https://medium.com/swlh/capability-based-security-and-macaroons-aaa64fb9fc01
  13. Dynamic Capability Scoping for Enterprise AI Agents: A Synthetic Dataset and Three-Source Permission Architecture - arXiv, https://arxiv.org/html/2607.22445v1
  14. Policy Compiler for Secure Agentic Systems - arXiv, https://arxiv.org/html/2602.16708v1
  15. Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents, https://arxiv.org/html/2603.20953v1
  16. GitHub - rescrv/libmacaroons: Macaroons are flexible authorization credentials that support decentralized delegation, attenuation, and verification., https://github.com/rescrv/libmacaroons
  17. An AI Agent Execution Environment to Safeguard User Data - arXiv, https://arxiv.org/pdf/2604.19657
  18. Trustworthy Companion AI for Human-Aware Transition of Control: Motivation, Architecture, and Research Roadmap - MDPI, https://www.mdpi.com/2227-7080/14/7/386
  19. Full article: A Systematic Review of Metrics Measuring Takeover Performance in Conditionally Automated Driving - Taylor & Francis, https://www.tandfonline.com/doi/full/10.1080/10447318.2025.2552863
  20. (PDF) Takeover Directly or Gradually? Comparison of Single Stage and Dual Stage Human-Machine Interface on Drivers’ Visual Behaviors and Subjective Ratings over Cognitive Demand, Motoric Demand, and Time Demand - ResearchGate, https://www.researchgate.net/publication/362121221_Takeover_Directly_or_Gradually_Comparison_of_Single_Stage_and_Dual_Stage_Human-Machine_Interface_on_Drivers’_Visual_Behaviors_and_Subjective_Ratings_over_Cognitive_Demand_Motoric_Demand_and_Time_Deman
  21. Macaroons (computer science) - Wikipedia, https://en.wikipedia.org/wiki/Macaroons_(computer_science)
  22. Research on Multimodal Human-Machine Interface for Takeover Request of Automated Vehicles - ResearchGate, https://www.researchgate.net/publication/395878541_Research_on_Multimodal_Human-Machine_Interface_for_Takeover_Request_of_Automated_Vehicles
  23. A review of research on the behavioral characteristics of older drivers in human-machine co-driving - SPIE Digital Library, https://www.spiedigitallibrary.org/conference-proceedings-of-spie/13965/139652L/A-review-of-research-on-the-behavioral-characteristics-of-older/10.1117/12.3090252.full
  24. IITAA 2.1 Standards - Illinois Department of Innovation & Technology, https://doit.illinois.gov/initiatives/accessibility/iitaa/iitaa-2-1-standards.html
  25. Illinois Information Technology Accessibility Act (IITAA): An Overview, https://www.boia.org/blog/illinois-information-technology-accessibility-act-iitaa-an-overview
  26. IITAA - Illinois Department of Innovation & Technology, https://doit.illinois.gov/initiatives/accessibility/iitaa.html