Agent Authorization Architecture

Anthropic announced agent workspace identity today. That's essential but it solves only the first layer of the problem. The gap lives in the layers that follow.

flowchart TD req["Agent Request
(Action Intent)"] subgraph identity ["LAYER 1: IDENTITY"] whoami["Who is the agent?
(Credential Binding)"] cred["Scoped Credentials
Workspace ID
API Token"] whoami --> cred end subgraph execution ["LAYER 2: EXECUTION"] whatcan["What may it do
RIGHT NOW?
(Authorization Gate)"] policy["Policy Engine"] state["Current System State"] decision["Decision Gate"] policy -.-> decision state -.-> decision whatcan --> policy whatcan --> state decision -.-> outcome["PERMIT
or
DENY"] end subgraph proof ["LAYER 3: PROOF"] canprove["Can you prove
it happened?
(Immutable Evidence)"] log["Unforgeable Audit Trail"] evidence["Why Decision
What Executed
Result"] canprove --> log log --> evidence end req --> whoami cred --> whatcan outcome --> canprove style identity fill:#C2E5FF,stroke:#3DADFF style execution fill:#FFECBD,stroke:#FFC943 style proof fill:#DCCCFF,stroke:#874FFF style req fill:#D9D9D9,stroke:#B3B3B3 style outcome fill:#FFCDC2,stroke:#FF7556

Layer 1: Identity

Static. Answers: "Who is this agent?"

Credential binding, workspace scoping, token issuance. This is what Anthropic just shipped.

Layer 2: Execution

Dynamic & Contextual. Answers: "What may it do right now?"

Authorization policy applied against current system state. Decision gate enforces preconditions. No existing standard here.

Layer 3: Proof

Immutable. Answers: "Can you prove it happened?"

Unforgeable audit trail. Evidence not just that an action occurred, but why the decision was made and what the result was.

The Gap: Layer 1 exists. Layers 2 and 3 do not. No standard mechanism for runtime authorization scope. No consensus on how to prove that authorization was enforced. This is where VAIG operates.