Identify (ID) · Authorization
Authorization at the Self-declared layer
advisory · Bypassable by language alone
What agents exist, what they touch, what threats they face?
What this cell does
Agent reports allowed-tools list, MCP allowlist hashes, effective scope on registration. Updates on scope change.
Artifacts (1)
record.yamlview on GitHub# ABOUTME: What the self-declared layer records for the authorization concern, and which mismatch rules consume it.
# ABOUTME: Read by scripts/reconcile_inventory.py to compare the three layers against each other.
cell:
id: authorization.in-agent
concern: authorization
layer: in-agent
authority: self-declared
records: "The agent reports the scope it believes it holds: tools, MCP servers, environments."
fields:
- authorization_runtime.rbac_role_ref
- authorized_scope.tools_allowlist
feeds_rules:
- scope_drift
Cell notes
Inventory, Authorization / Self-declared
What this cell records. The agent's report of its current effective scope at startup and on scope changes.
Fields
- -
tools_allowlist[] - -
mcp_servers_allowlist[](with hashes) - -
rbac_role_ref - -
iam_role_arn - -
effective_scope_at_startup(snapshot of permissions reported by the agent runtime)
The agent's wrapper sends this on each registration. If the agent's runtime cannot enumerate its own scope (some MCP-only agents cannot), this cell becomes a manifest reference rather than a live snapshot.
Cross-layer
Should match operator-declared scope (charter authoritative). Drift = Sentinels alert.
Citation
NIST CSF 2.0 ID.AM-02. NIST AI RMF MAP 4.1. CSA MAESTRO Layer 7.
Crosswalk
| NIST CSF 2 0 | ID.AM-02 |
|---|---|
| NIST AI RMF | MAP 4.1 |
| CSA MAESTRO | Layer 7 |
Cite this cell:
https://agenticcovenants.com/identify/authorization/in-agent/