Skip to content
AI Architect Academy

Production agent systems · stage 03 of 09

Tool and authority model

What the agent may do, as what principal, and how you take it back.

The module

Lesson, exercise and rubric

Open the repository in a coding agent and run /module 03 for a Socratic session over this stage.

What you leave behind · json

Tool and authority model

Required sections:

  • tools
  • principals
  • sideEffecting
  • revocationPath

May appear on a public portfolio once redacted: remove credential names, endpoint hostnames.

The eval · eval:authority-least-privilege

Authority is bounded per tool

  1. side-effecting-flaggedEvery tool declares whether it is side-effecting. Checked by: Each entry in tools[] has a boolean sideEffecting.
  2. no-shared-principal-for-writesNo single principal backs more than one side-effecting tool. Checked by: Group side-effecting tools by principal; assert every group size is 1.
  3. revocation-documentedEach principal has a revocation path. Checked by: Every tool principal resolves to a unique principals[] entry; every declared principal has a non-empty revocationPath string matching its map entry, and the map names no undeclared principal.

Every check must pass. There is no partial credit and no override.

Evidence that counts

Proof has to exist outside your own claim.

At least 1 of: a commit or file a third party can open; a recorded, reproducible eval run. Evidence older than 365 days is stale and does not count.