Capability-Based Security
A security model that grants an agent only unforgeable, narrowly-scoped tokens conferring specific authority, eliminating ambient permissions so a compromised or over-eager agent cannot exceed its explicitly delegated powers.
grounded in: Doctrine (principles.md) Guardrails layer: 'bounded autonomy: no big blind rewrites, no secrets, no new external network calls'; reinforced by the 'Agent wire-level transparency' trend theme on auditi
Connected concepts
Agent identity & access mgmt, Agent sandboxing, Guardrails / bounded autonomy, Default-deny egress
Explore it live in the knowledge graph →