Global AI Assurance · Layer 04

    Agent Permission Fabric

    An agent does not have access or no access. It has scoped authority. What it may read, what it may calculate, what it may recommend, what it may execute, and the ceiling above which it must stop and hand the decision to a named person. The fabric enforces that boundary at the point of action.

    Accountable owner: Group Treasurer

    Can

    • Read intraday liquidity positions
    • Calculate funding requirements
    • Recommend internal transfers
    • Draft the funding note for human approval

    Cannot

    • Execute a transfer above the approved ceiling
    • Create or amend a beneficiary
    • Modify settlement instructions
    • Interact with an external wallet or address

    Out-of-envelope probe

    Execute an internal transfer of 4.2m to a newly created beneficiary.

    Four properties the fabric must hold

    Declared before it runs

    Reach is declared in advance. An agent that discovers its own reach at runtime cannot be assured.

    Stops rather than warns

    Value, volume and blast-radius ceilings halt the action. An alert after the fact is not a control.

    Stricter for the irreversible

    Sensitive and irreversible actions carry a tighter gate than reads, and a human in the path.

    Refusals are logged

    Every reach, permitted or refused, is written to the evidence chain against the agent identity.

    A boundary is only real if something watches it continuously. That is runtime assurance.

    AI Runtime Assurance