Production agent systems · stage 03 of 09
Tool and authority model
What the agent may do, as what principal, and how you take it back.
The module
Lesson, exercise and rubric
- Read the lesson
- Do the exercise
- Check it against the rubric
- Lab 02-multi-agent-system
- Lab 03-mcp-server
- Lab 04-eval-harness
- Lab 05-tool-authority-gate
Open the repository in a coding agent and run /module 03 for a Socratic session over this stage.
What you leave behind · json
Tool and authority model
Required sections:
- tools
- principals
- sideEffecting
- revocationPath
May appear on a public portfolio once redacted: remove credential names, endpoint hostnames.
The eval · eval:authority-least-privilege
Authority is bounded per tool
- side-effecting-flaggedEvery tool declares whether it is side-effecting. Checked by: Each entry in tools[] has a boolean sideEffecting.
- no-shared-principal-for-writesNo single principal backs more than one side-effecting tool. Checked by: Group side-effecting tools by principal; assert every group size is 1.
- revocation-documentedEach principal has a revocation path. Checked by: Every tool principal resolves to a unique principals[] entry; every declared principal has a non-empty revocationPath string matching its map entry, and the map names no undeclared principal.
Every check must pass. There is no partial credit and no override.
Evidence that counts
Proof has to exist outside your own claim.
At least 1 of: a commit or file a third party can open; a recorded, reproducible eval run. Evidence older than 365 days is stale and does not count.