Agent entitlement schema
A data model for expressing what authority an agent holds, from whom, with what limits, and when it expires.
Why it exists
Most agent stacks express permission as a credential. A credential says what a system can reach. It does not say what a principal authorised, for how long, or on whose behalf — which is precisely what a reviewer asks for.
What it contains
Grant object — grantor, grantee agent, action class, resource scope, constraints, validity window
Delegation chain — how authority derives from a human principal through intermediate services
Constraint vocabulary — value limits, rate limits, jurisdiction, approval requirements, data classification
Revocation and expiry semantics, including what happens to in-flight actions
Evidence binding — how an executed action references the grant that permitted it
Status
The full reference document is being prepared for publication. If you want it as soon as it is out — or want to review a draft and push back on it — say so and I will send it.
Want this applied to your architecture?
The artifacts are general by design. Applying one to a specific estate is what the governance review does.