--
You received this message because you are subscribed to the Google Groups "friam" group.
To unsubscribe from this group and stop receiving emails from it, send an email to friam+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CACTLOFriN9PKEZci%3DP%2BLT7Qv5H8qxbD%3D_RL9cR1sG4R%2B0Qg_xg%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CAK-_AD5Yc0a9y%3DeAMLgEvSVa9z2wEdwE%2Bupw7%3DzxbgAU4aLcwQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CANpA1Z3uD_gj3FpG%2Bw8Mo3w5wcBPzsdLk4136djv6%3DwO4cscxg%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CANpA1Z3uD_gj3FpG%2Bw8Mo3w5wcBPzsdLk4136djv6%3DwO4cscxg%40mail.gmail.com.
I think we may be conflating two layers: the UX or policy language used to express and decompose intent, and the mechanism that enforces the resulting authority.
Some parts of intent can be compiled into permissions when they are observable at the enforcement point. "Read only the first paragraph" becomes enforceable if a component outside the agent's authority exposes only that paragraph. Having the broadly authorized agent create the proxy itself is voluntary restraint. Other parts, such as purpose and preference, are not permissions at all.
So permissions can represent an enforceable projection of intent, but not necessarily the whole of it.
To view this discussion visit https://groups.google.com/d/msgid/friam/CALGH9Z_a-m02T390t3wdee4AFGjo5WQ2BhfVc%2BwHvwXebUHzNA%40mail.gmail.com.




To view this discussion visit https://groups.google.com/d/msgid/friam/CALGH9Z_a-m02T390t3wdee4AFGjo5WQ2BhfVc%2BwHvwXebUHzNA%40mail.gmail.com.
Hi Matt,
> As permission more precisely conveys intent, agents lose agency.
Perhaps we are using “permission” in two different ways. I don’t expect permissions to convey intent to the agent; instructions do that. If permissions progressively prescribe the agent’s next steps, then sufficiently precise permissions become a workflow, leaving the agent with little agency.
I mean permissions as an independently enforced boundary on effects. They do not tell the agent what to do; they determine which attempted actions the enforcement point will accept. In the Thai example, the boundary might constrain distance, price, or permissible destinations while leaving the agent to decide which is best and how to get there.
With complete enforcement, every executed effect must fall within that boundary and attempts outside it are denied. Whether the agent understood or fulfilled the original intent is a separate concern.
The same distinction applies when an agent delegates. It can give a sub-agent instructions describing the work while separately constraining what the sub-agent is allowed to execute.
Raoul, > Probably need actual agreed upon definition of "intent".
Intent can remain an ambiguous upstream input. The security boundary can still be drawn where some portion of the intent is translated into explicitly enforceable constraints, with the limits of that projection made clear. A complete formal definition is not a prerequisite for useful enforcement.
The resulting guarantee is not ideal but still useful: the agent will stay within the authority of the intended task that was defined roughly based on the translated human's intent.
To view this discussion visit https://groups.google.com/d/msgid/friam/CANpA1Z3fZ93%2Brjc7MUXhU-6ybzzC98XS7onLAVX0tpMt4OCypg%40mail.gmail.com.