The failure pattern

Consider a legitimate workflow agent authorized to inspect configuration data. The agent has valid credentials and a legitimate reason to access a defined set of systems. Then the workflow is compromised or the credential is stolen.

The same authenticated identity may now attempt to retrieve additional secrets, move into another system, create a persistent administrator account, or perform destructive operations. At each step, the credential can remain technically valid.

THE AUTHORITY QUESTION Authentication can survive after legitimate authority has ended.

Where runtime authority changes the question

A runtime authority layer does not ask only whether the agent can reach the target. It evaluates whether the requested action remains inside the purpose, scope, resource boundary, delegation chain, constraints, and time window that created the authority in the first place.

ATTEMPTED ACTIONAUTHORITY RESPONSE
Inspect approved configurationALLOW
Retrieve unrelated secretsDENY
Move into an undelegated systemDENY
Create persistent administratorESCALATE
Bulk encryption or destructive database actionDENY

What Praeva would—and would not—claim

Praeva is not positioned as ransomware protection, endpoint detection, an identity provider, or a replacement for enterprise policy systems. A runtime authority control would not make every compromise impossible.

The narrower claim is more important: if an authenticated agent attempts a consequential action that no longer has legitimate delegated authority, the execution boundary should be able to recognize that fact before the downstream action occurs.

You have access. You do not have authority.

Why this becomes more important as agents gain autonomy

Traditional enterprise controls were built around identities, credentials, roles, sessions, and system permissions. Agentic workflows add another layer: delegated purpose can move across multiple steps, tools, systems, and agents.

As that chain grows longer, organizations need a way to verify that authority has not been silently widened along the way. The model should not be the source of truth for its own power.

PRAEVA SYSTEMS Before action, authority.

When Agents Run Amok is a Praeva Systems series examining agent incidents through the lens of delegated authority and pre-execution control.

Discuss a consequential workflow