Abstract
A security architecture is proposed herein for controlling privileged actions by artificial intelligence (AI) agents and automated workloads across operating-system, container, cluster, and tenant namespaces. The architecture evaluates cumulative capability risk and issues narrowly scoped, short-lived operation leases. Each lease is cryptographically bound to the requesting workload, target object, operation arguments, namespace context, policy version, and a human-auditable explanation, and is verified by the operating-system kernel at the moment of execution. By replacing broad standing privileges and application-layer allow decisions with explainable, context-sensitive least privilege, the architecture reduces the time-of-check-to-time-of-use gap, supports immediate invalidation when relevant context changes, and creates a verifiable audit chain from the authorization decision to kernel enforcement and the final operation outcome.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Recommended Citation
Putta, Bharat Kumar, "EXPLAINABLE AI-GOVERNED NAMESPACE CAPABILITY RISK BROKERAGE WITH KERNEL-ENFORCED OPERATION LEASES", Technical Disclosure Commons, (September 16, 2026)
https://www.tdcommons.org/dpubs_series/11738