Inventor(s)

Abstract

A security architecture is proposed herein for controlling privileged actions by artificial intelligence (AI) agents and automated workloads across operating-system, container, cluster, and tenant namespaces. The architecture evaluates cumulative capability risk and issues narrowly scoped, short-lived operation leases. Each lease is cryptographically bound to the requesting workload, target object, operation arguments, namespace context, policy version, and a human-auditable explanation, and is verified by the operating-system kernel at the moment of execution. By replacing broad standing privileges and application-layer allow decisions with explainable, context-sensitive least privilege, the architecture reduces the time-of-check-to-time-of-use gap, supports immediate invalidation when relevant context changes, and creates a verifiable audit chain from the authorization decision to kernel enforcement and the final operation outcome.

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.

Share

COinS