Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Authorization Revocation for Long-Running AI Agents: Root-Scoped Quiescence under Delegation and Asynchronous Execution

A certificate-based protocol for proving that retired authorization roots can no longer expand, even when agents delegate, queue, and execute asynchronously
Genliang Zhu; Chu Wangยท 2026ยท DOI 10.48550/arXiv.2609.21284

The core problem

Long-running AI agents do not terminate when their initiating process exits. They persist through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations. This creates a revocation problem that conventional mechanisms do not solve: cancellation, process exit, and credential revocation neither close every pre-cut carrier nor distinguish independently authorized shared work from work that depends on the retired authority.

The paper identifies a gap between *stopping* an agent and *quiescing* the authorization root that sustains it. A root may be retired, yet already-issued credentials, queued messages, scheduled callbacks, and provider-side reservations can still accept effects after the cut. The authors therefore define **root-scoped authorization quiescence**: for each manifested sink, a certificate must account for every cut-relevant acceptance under the retired root-epoch atom that precedes its local fence, and must exclude protected acceptance under that atom after the fence, while permitting exact rebind to a current, independently sufficient support.

The central claim is not global idleness, rollback, or business completion. It is a bounde

Innovation

Under stated assumptions, the authors prove six properties: post-cut issuer non-expansion, support-sound projection, compositional soundness under exact channel conservation, independent-support preservation, merge-order independence, and crash/replay stability.

**Post-cut issuer non-expansion** means that after the root cut, the retired root cannot issue new authority that reaches a protected sink. **Support-sound projection** means that any accepted effect can be projected to a current, independently sufficient support. **Compositional soundness under exact channel conservation** means that provider-frontier certificates compose without losing accounting, provided channel tokens are conserved exactly. **Independent-support preservation** means that work authorized by a current, independently sufficient root is not invalidated by the retirement of . **Merge-order independence** means that the certificate outcome does not depend on the order in which independent evidence is merged. **Crash/replay stability** means that crashes and replays do not create new acceptance under the retired root.

The empirical results align with the proofs. The provider-free late-effect

Long-running AI agents do not terminate when their initiating process exits. They persist through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations. This creates a revocation problem that conventional mechanisms do not solve: cancellation, process exit, and credential revocation neither close every pre-cut carrier nor distinguish independently authorized shared work from work that depends on the retired authority.
The paper identifies a gap between *stopping* an agent and *quiescing* the authorization root that sustains it. A root may be retired, yet already-issued credentials, queued messages, scheduled callbacks, and provider-side reservations can still accept effects after the cut. The authors therefore define **root-scoped authorization quiescence**: for each manifested sink, a certificate must account for every cut-relevant acceptance under the retired root-epoch atom that precedes its local fence, and must exclude protected acceptance under that atom after the fence, while permitting exact rebind to a current, independently sufficient support.

Why it matters

The paper's contribution is a shift from *revocation as deletion* to *revocation as accounting*. In conventional systems, revoking a credential is treated as removing a capability. For long-running AI agents, that is insufficient because the capability may already be manifested in queues, callbacks, reservations, and provider-side operations. The root-scoped quiescence protocol instead requires a certificate that accounts for every cut-relevant acceptance under the retired root-epoch atom, and excludes protected acceptance after the fence.

The antichain representation of authority is a key design choice. By representing alternative and conjunctive authority as antichains of minimal sufficient root sets, the protocol can distinguish independently authorized shared work from work that depends on the retired root. This is what enables independent-support preservation: a current, independently sufficient support can be rebound exactly, without being invalidated by the retirement of .

The provider-frontier composition is another key choice. Because AI agents often rely on third-party providers, the protocol cannot assume direct control over provider-side state. Instead, it composes provider-frontier certificates into a cutset over registered old-root paths. Exact channel-token accounting reconciles transfers, and missing or conflicting evidence remains indeterminate. This makes the protocol robust to partial visibility, but it also means that quiescence is bounded by the manifest and configuration.

The limitations are explicit. The certificate does not establish global idleness, rollback, or business completion. It establishes root-relative authorization quiescence within its bound manifest and configuration. For practitioners, this means the protocol is a building block for revocation in asynchronous, delegated, provider-mediated AI systems, not a complete solution to agent shutdown. The 17/17 trace verification and 44/44 regression rejection suggest that the checker is a practical tool for validating quiescence claims, but the provider-free test suite leaves open the question of how the protocol behaves under real provider-side operations with incomplete evidence.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ