Authorization Revocation for Long-Running AI Agents: Root-Scoped Quiescence under Delegation and Asynchronous Execution
Stopping a process is not the same as retiring its authority. Root-scoped quiescence accounts for every registered path that can outlive a long-running agent.
Overview
Long-running agents leave authority in more places than the process that started them: credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations may continue after cancellation or credential revocation. Some shared work may also have valid support independent of the retired root.
The protocol creates a linearized root cut, fences further old-root expansion, and collects provider-frontier evidence for every registered path. Old-root effects are stopped, while work with a current and independently sufficient authorization can be rebound exactly and continue.
Core contributions
- 01
Root-scoped quiescence
Defines revocation as a manifest-bound certificate over every cut-relevant acceptance, rather than as process cancellation or a claim of global idleness.
- 02
Delegation-aware authority
Represents alternative and conjunctive support as antichains of minimal sufficient root sets so shared work can be retired or preserved without conflating its authority.
- 03
Compositional evidence
Composes provider-frontier certificates into a cutset and uses exact channel-token accounting to reconcile asynchronous transfers, treating missing or conflicting evidence as indeterminate.
- 04
Executable revocation checks
Exercises late effects, cuts, fences, restarts, stale processes, replay behavior, and semantic regressions through registered traces and an independently implemented checker.
How revocation completes the runtime authority lifecycle
Runtime authorization governs when newly acquired resources may become usable authority. Root-scoped quiescence addresses the opposite transition: how authority is retired after it has spread through delegation and asynchronous execution.
A retired root cannot keep expanding or reaching protected sinks after its local fences. Exact rebind preserves only work that can prove current, independently sufficient support.
- 01Long-running root
- 02Linearized cut
- 03Fenced old-root paths
- 04Certified quiescence
Evidence and scope
This is an arXiv preprint. Its certificate establishes root-relative authorization quiescence only within the bound manifest and configuration; it does not prove global idleness, rollback, or business completion. The guarantees assume registered old-root paths, exact channel conservation, sound provider-frontier evidence, and the stated fencing and linearization conditions. The reported evaluation is provider-free and trace-based rather than a production deployment study.
Abstract
Long-running AI agents outlive initiating processes through credentials, delegated tasks, queues, callbacks, reservations, and provider-side operations. Cancellation, process exit, and credential revocation neither close every pre-cut carrier nor distinguish independently authorized shared work. We define root-scoped authorization quiescence: for each manifested sink, a certificate accounts for every cut-relevant acceptance under the retired root-epoch atom that precedes its local fence and excludes protected acceptance under that atom after the fence, while permitting exact rebind to a current, independently sufficient support. The root-scoped quiescence protocol linearizes a root cut, fences old-root expansion and protected sinks, represents alternative and conjunctive authority as antichains of minimal sufficient root sets, and composes provider-frontier certificates into a cutset over registered old-root paths. Exact channel-token accounting reconciles transfers; missing or conflicting evidence remains indeterminate. Under stated assumptions, we prove post-cut issuer non-expansion, support-sound projection, compositional soundness under exact channel conservation, independent-support preservation, merge-order independence, and crash/replay stability. A provider-free late-effect test suite matches 17/17 registered outcomes. Two cancellation-only and one cut-only execution accept the same class of already scheduled late effect; two cut-plus-fence executions, one restart, and one stale-process execution reject it. A separately implemented checker verifies 17/17 traces and rejects 44/44 consistently rehashed semantic regressions. The certificate establishes root-relative authorization quiescence within its bound manifest and configuration, not global idleness, rollback, or business completion.
Cite this work
Use the DOI record for stable bibliographic information and citation formats.
