<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Testing Mission-Bound Authorization on Control Plane by Karl McGuinness</title><link>https://notes.karlmcguinness.com/series/testing-mission-bound-authorization/</link><description>Recent content in Testing Mission-Bound Authorization on Control Plane by Karl McGuinness</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 07:50:00 -0700</lastBuildDate><atom:link href="https://notes.karlmcguinness.com/series/testing-mission-bound-authorization/index.xml" rel="self" type="application/rss+xml"/><item><title>Closing the Agent Authorization Gaps</title><link>https://notes.karlmcguinness.com/notes/closing-the-agent-authorization-gaps/</link><pubDate>Wed, 22 Jul 2026 07:50:00 -0700</pubDate><guid>https://notes.karlmcguinness.com/notes/closing-the-agent-authorization-gaps/</guid><description>The standards community is converging on a problem statement: agents break OAuth&amp;rsquo;s pre-approval paradigm, tokens cannot represent delegation chains, revocation cannot reach a task, and consent screens cannot survive a thousand scopes. The agent authorization use-case catalog names nine scenarios and rolls its analysis up to five major gaps, and this part answers the catalog line by line at both grains with machinery that existed before it was published: task-level revocation is the Mission kill switch, bulk revocation is Mission Management, multi-hop chains are act chains and Child Missions, scope explosion dies at Mission-grain consent, and the paradigm mismatch is the discovery loop. One answer is partial and one is delegated, and the tally is stated rather than smoothed.</description></item><item><title>Making Compliance a By-Product</title><link>https://notes.karlmcguinness.com/notes/making-compliance-a-by-product/</link><pubDate>Wed, 22 Jul 2026 07:40:00 -0700</pubDate><guid>https://notes.karlmcguinness.com/notes/making-compliance-a-by-product/</guid><description>The third kind of outside framing is the one with auditors behind it. NIST AI RMF, the EU AI Act, and ISO/IEC 42001 converge on one demand: show me. Show me who is accountable, what the system is for, how you observe it, and how you stop it. In most agent stacks the honest answer is archaeology through session logs. In this architecture the artifact that enforces is the artifact that documents: the Mission is the documented purpose, the approval is the accountable decision, the evidence family is the log, and Termination is the interrupt. The crosswalk maps eight obligations onto machinery that exists for safety reasons, and then names what compliance still requires, because evidence is not certification.</description></item><item><title>Containing the OWASP Agentic Threats</title><link>https://notes.karlmcguinness.com/notes/containing-the-owasp-agentic-threats/</link><pubDate>Wed, 22 Jul 2026 07:30:00 -0700</pubDate><guid>https://notes.karlmcguinness.com/notes/containing-the-owasp-agentic-threats/</guid><description>Security reviewers do not arrive with your framing. They arrive with OWASP&amp;rsquo;s: fifteen agentic threats from memory poisoning to human manipulation, plus the LLM Top 10. This part crosswalks both onto the handbook and refuses the move that makes crosswalks worthless, claiming everything. Each threat gets one of three verdicts. Contained means the threat lands on machinery built for it, with a draft behind it. Bounded means the cause is out of authorization&amp;rsquo;s reach but the blast radius is capped at the action gate. Delegated means it is not an authorization problem and a named complement owns it. Six of the fifteen are contained, nine are bounded, and half the LLM Top 10 is honestly someone else&amp;rsquo;s layer.</description></item><item><title>Answering the Laws of AIdentity</title><link>https://notes.karlmcguinness.com/notes/answering-the-laws-of-aidentity/</link><pubDate>Wed, 22 Jul 2026 07:20:00 -0700</pubDate><guid>https://notes.karlmcguinness.com/notes/answering-the-laws-of-aidentity/</guid><description>Patrick Parker&amp;rsquo;s Seven Laws of AIdentity describe the dynamics a system must govern when agents act through delegated authority: split actors, generated intent, bounded agency, continuous authorization, least exposure, justifiable action chains, and proof-carrying action. This part maps those laws onto Mission-Bound Authorization without turning resemblance into compliance. The strongest matches are generated intent and bounded agency. Continuous authorization and split-actor attribution require the runtime and identity profiles. Least exposure, chain necessity, policy retention, evidence completeness, and embodied action remain conditional or outside the current wire model.</description></item><item><title>Splitting the Lethal Trifecta</title><link>https://notes.karlmcguinness.com/notes/splitting-the-lethal-trifecta/</link><pubDate>Wed, 22 Jul 2026 07:10:00 -0700</pubDate><guid>https://notes.karlmcguinness.com/notes/splitting-the-lethal-trifecta/</guid><description>Simon Willison named the combination that makes agents dangerous: access to private data, exposure to untrusted content, and the ability to communicate externally, held together in one loop. Any two legs are safe. All three are an exfiltration machine waiting for a poisoned document. This part runs the handbook against that threat model: the three legs become separately typed action classes under one Mission, the external leg becomes a consequential action that needs a fresh parameter-bound permit, mediated custody keeps the egress credential out of the agent&amp;rsquo;s hands, and the harness downgrades egress once untrusted content enters the session. Then the honest residuals: enforcement scope, composition, and the semantic gap.</description></item></channel></rss>