Research Note
Agent Action Authorization Research Note
Meeting-derived action should move through explicit states: candidate, confirmed commitment, assigned owner, approved write, executed change, verified result, and recover
Agent Action Authorization Research Note
Meeting-derived action should move through explicit states: candidate, confirmed commitment, assigned owner, approved write, executed change, verified result, and recoverable record.
A transcript can be wrong. A speaker can brainstorm without committing. A participant can commit without authority to bind another person. A correct commitment can still belong in the wrong system.
NIST's AI RMF Measure playbook recommends auditability, histories, oversight measures, override records, and documented go or no-go decisions. NIST's 2026 agent identity and authorization concept paper frames agent identity, delegation, least privilege, auditing, and human-in-the-loop authorization as open enterprise design problems.
The smallest safe write uses a named human or service identity, minimum scope, a complete preview, idempotency or duplicate protection, a returned record identifier, and a reversal or correction path.
Human review must occur at the authority transition, not merely somewhere in the workflow.
Sources
Follow the evidence.
- security guidancemodelcontextprotocol.io
- 18 U.S.C. 2511law.cornell.edu
- agent identity and authorization concept papernccoe.nist.gov
- local-first software essayinkandswitch.com
- device encryption guidancecisa.gov
- meeting recap studymicrosoft.com
- MCP specificationmodelcontextprotocol.io
- reader-focused meeting summarization researchaclanthology.org
- authorization guidemodelcontextprotocol.io
- agent evaluation worknist.gov
- current Quill documentationquillmeetings.com
- key-management guidancecsrc.nist.gov
- server conceptsmodelcontextprotocol.io
- California Penal Code section 632leginfo.legislature.ca.gov
- AI RMF Measure playbookairc.nist.gov
- data sovereignty pagequillmeetings.com
- current About pagequillmeetings.com
- OWASP's MCP security guidancecheatsheetseries.owasp.org
- SP 800-209nist.gov
- query-focused meeting summarization researchaclanthology.org