PRAEVA SYSTEMS RESOURCES

Authority before action.

Research notes, incident analysis, primers, and public doctrine for organizations building agentic systems that can act in consequential environments.

FEATURED SERIES
WHEN AGENTS RUN AMOK #002
NEW · AUGUST 26, 2026

Who actually authorized the agent?

An agent can be authenticated, hold valid credentials, and still take an action nobody actually authorized. The second installment looks at why identity and access stop short of answering the authority question.

Read #002 →
When Agents Run Amok series graphic
WHEN AGENTS RUN AMOK #001
INCIDENT ANALYSIS

The credential remained valid. The authority did not.

A compromised agent can remain authenticated while its actions move beyond the authority originally delegated. This installment examines the control gap.

Read #001 →
PRIMER

Identity, access, and authority are not the same thing.

Identity establishes the actor. Access determines what a credential can reach. Authority asks whether the actor is legitimately empowered to take this specific action, for this purpose, at this time.

Praeva is built around the third question. It is not intended to replace IAM, authentication, authorization policy, or endpoint detection. It is designed to evaluate legitimate delegated authority at the execution boundary.

PUBLIC DOCTRINE

Five principles for delegated agent authority.

  1. Authority originates outside the model. Models do not create their own legitimate power.
  2. Delegation should be explicit. Purpose, scope, actions, constraints, expiry, and lineage should be inspectable.
  3. Authority should be locally verifiable. Consequential systems should not rely on vague upstream assumptions.
  4. Authority must be revocable. Runtime decisions must respond when delegation expires or changes.
  5. Decisions should leave evidence. Organizations should be able to reconstruct the authority chain and decision rationale.