Anton Dziatkovskii › Papers

Keeping Agents on a Leash: An Eight-Domain Control Model for AI Agents with Delegated Authority

Anton Dziatkovskii · ORCID 0000-0001-7408-3054

Preprint, 10 September 2026. Version of record: Zenodo, DOI 10.5281/zenodo.22691782. License CC BY 4.0.

Full text (PDF, 8 pages, 215 KB)DOICode: agent-leashCode: agent-approval-gate

Abstract

Design / position paper. An agent with delegated authority is an attack surface with credentials. The research answer is defenses evaluated on benchmarks, and those benchmarks are sobering: indirect prompt injection still succeeds between 10.7% and 29.6% against frontier models in production-like settings (LivePI), and of ten recent defenses on open-ended tasks almost all are either insufficiently secure or significantly over-defensive (AgentDyn). Operators must nevertheless ship.

This paper presents LEASH-8, an eight-domain control model — identity, secrets, tool supply chain, approvals, containment, egress, observability, incident response — stated so that a small operation can implement it and, more importantly, evidence it: each domain carries a minimal implementation and an evidence test its owner must be able to satisfy in under a minute. Around the model are three instruments: a 24-statement scorecard with bands, a reference architecture in which the model plans, a deterministic gate authorizes and a scoped executor acts, and a checklist for designing the approval leg together with a catalogue of approval designs that fail it (including the one that fails by asking about everything and training its reader to stop looking).

No novelty is claimed at the level of principles. Every domain restates least privilege, zero trust, capability security, the confused deputy, supply-chain integrity or operational monitoring; enterprise maturity models (OWASP, CSA) already cover this ground for organizations with security teams, CaMeL formalizes policy enforcement outside the model, and OpenPort specifies risk-gated review, time-bounded approvals and state revalidation. The paper includes a per-domain novelty ledger that says “no novelty” where that is the honest verdict. The contribution is operationalization for the operator who has no security team: the smallest defensible control set, the evidence question that makes each control checkable, and two open reference implementations.

Patterns come from a five-machine production agent operation, and a grounding table marks every such claim as either backed by a public artifact or as unaudited operator experience. This is a design paper, not an evaluation: no user study, no benchmark of our own, and no measurement that a higher score produces fewer incidents — the paper states what would falsify it instead.

Code: github.com/tonydzi/agent-leash (model, scorecard, checklist, reference A2A agent card, MIT) and github.com/tonydzi/agent-approval-gate (standard-library approval gate with decision classes and tests, MIT). Contact: dzyatkovskiy.a2@gmail.com · ORCID 0000-0001-7408-3054 · github.com/tonydzi · tonydzi.github.io.

Keywords

LLM agents · agent security · delegated authority · prompt injection · confused deputy · least privilege · human approval · authorization · policy gate · blast radius · supply chain security · observability · incident response · scorecard · design paper

How to cite

Dziatkovskii, A. (2026). Keeping Agents on a Leash: An Eight-Domain Control Model for AI Agents with Delegated Authority. Preprint. Zenodo. https://doi.org/10.5281/zenodo.22691782

@misc{dziatkovskii2026leash,
  author    = {Dziatkovskii, Anton},
  title     = {Keeping Agents on a Leash: An Eight-Domain Control Model for AI Agents with Delegated Authority},
  year      = {2026},
  publisher = {Zenodo},
  doi       = {10.5281/zenodo.22691782},
  url       = {https://doi.org/10.5281/zenodo.22691782},
  note      = {Preprint, CC BY 4.0}
}

One text, one DOI: the PDF on this page is the Zenodo file byte for byte. Please cite the DOI.

Anton Dziatkovskii · Palo Alto AI Research Lab · All 2026 preprints · Full publication list