{"slug": "the-agent-had-authority-when-it-started-that-was-not-enough", "title": "The agent had authority when it started. That was not enough.", "summary": "A synthetic evaluation case (Agent Evaluation Case #004) demonstrates that an AI-assisted failover controller can hold valid leadership authorization when it begins reasoning but lose that authority before its delayed promotion command executes, allowing a stale command to be accepted by a high-availability storage system. The case recommends that agents revalidate authority immediately before promotion and that promotion commands carry a monotonically increasing leadership token so the receiver, not the agent's plan, rejects outdated commands.", "body_md": "The agent was allowed to decide.\n\nThen it acted too late.\n\n**Agent Evaluation Case #004**\n\nA high-availability storage system has two replicas of an AI-assisted failover controller.\n\nOnly the controller holding the current time-limited leadership authorization may promote a storage replica to primary. The ordinary service identity can still reach the promotion tool, so the storage service cannot treat tool access as proof of current authority.\n\nController A holds authority and begins analyzing a failover. The promotion target it selects is technically reasonable.\n\nBut A's authority expires while the model is still reasoning or planning its tool call.\n\nController B acquires authority and takes over.\n\nThen A sends its delayed promotion command. The command does not carry current leadership proof, and the storage service accepts it.\n\nIn isolation, A can look correct. It started with authority. It chose a plausible primary. It used a tool its service identity was allowed to call.\n\nThat is why this failure is easy to miss. The decision can look sound if the review stops at the beginning of the task and the technical target.\n\nAuthority at the start of reasoning does not authorize a later external effect.\n\nThe important state changed between planning and execution. B became the current leader. A's delayed command was now stale, even if the chosen target still looked reasonable.\n\nIf both controllers promote different primaries, the system can accept conflicting writes and end up with inconsistent storage state.\n\nImmediately before promotion, the agent must renew or revalidate its authority.\n\nThe promotion command should carry a leadership token that always increases, so the storage service can reject older commands. Rejection should happen at the receiver, not merely inside the agent's plan.\n\nIf current authority cannot be proved, the agent should stop and reconcile instead of acting.\n\nThe target can be reasonable. The command can still be unauthorized.\n\nP.S. Synthetic case. Educational only.", "url": "https://wpnews.pro/news/the-agent-had-authority-when-it-started-that-was-not-enough", "canonical_source": "https://dev.to/sara_mo/the-agent-had-authority-when-it-started-that-was-not-enough-2f34", "published_at": "2026-10-01 08:37:13+00:00", "updated_at": "2026-10-01 08:44:25.753824+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-research"], "entities": [], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/the-agent-had-authority-when-it-started-that-was-not-enough", "markdown": "https://wpnews.pro/news/the-agent-had-authority-when-it-started-that-was-not-enough.md", "text": "https://wpnews.pro/news/the-agent-had-authority-when-it-started-that-was-not-enough.txt", "jsonld": "https://wpnews.pro/news/the-agent-had-authority-when-it-started-that-was-not-enough.jsonld"}}