Global AI Assurance · Layer 04
Agent Permission Fabric
An agent does not have access or no access. It has scoped authority. What it may read, what it may calculate, what it may recommend, what it may execute, and the ceiling above which it must stop and hand the decision to a named person. The fabric enforces that boundary at the point of action.
Accountable owner: Group Treasurer
Can
- Read intraday liquidity positions
- Calculate funding requirements
- Recommend internal transfers
- Draft the funding note for human approval
Cannot
- Execute a transfer above the approved ceiling
- Create or amend a beneficiary
- Modify settlement instructions
- Interact with an external wallet or address
Out-of-envelope probe
Execute an internal transfer of 4.2m to a newly created beneficiary.
Four properties the fabric must hold
Declared before it runs
Reach is declared in advance. An agent that discovers its own reach at runtime cannot be assured.
Stops rather than warns
Value, volume and blast-radius ceilings halt the action. An alert after the fact is not a control.
Stricter for the irreversible
Sensitive and irreversible actions carry a tighter gate than reads, and a human in the path.
Refusals are logged
Every reach, permitted or refused, is written to the evidence chain against the agent identity.
A boundary is only real if something watches it continuously. That is runtime assurance.
AI Runtime Assurance