Authority Propagation Models: PoP vs PoC and the Confused Deputy Problem
Provenance-bounded execution can prevent downstream privilege expansion, but continuity of authority does not establish the legitimacy of the authority at the origin.
Registries, attestations, assurance and the infrastructure through which trust claims become actionable.
Provenance-bounded execution can prevent downstream privilege expansion, but continuity of authority does not establish the legitimacy of the authority at the origin.
A continuity model can prevent downstream authority manufacture, but a governable system still needs explicit rules for how legitimate authority is created, revoked, disputed, and restarted.
Credential interoperability is not a property of shared formats alone: it exists only when verifiers can obtain the constitutional and logistical materials needed to decide what to trust, while retaining responsibility for the assumptions that make acceptance legitimate.
Syntelos reframes trust as a runtime evaluation of attestations against policy, but leaves unresolved the governance of that policy layer, where real authority over system behavior resides.
For agentic systems, governance must shift from persistent identity-based permission to action-bound, exhaustible authority that produces verifiable provenance at the moment an effect occurs.