Capability is explicit. Authority is never inferred from intelligence.
The model, agent runtime and owner occupy different trust positions.
Model
- May
- Generate an inference within supplied context.
- May not
- Hold credentials, approve authority or claim execution evidence.
Agent
- May
- Plan and execute named capabilities under policy.
- May not
- Expand its grant or conceal blocked state.
Specialist
- May
- Perform one bounded role with a scoped capability bundle.
- May not
- Delegate beyond the parent mission boundary.
Owner
- May
- Approve, reject, narrow, pause or revoke consequential work.
- May not
- Transfer non-delegable ownership to the agent runtime.