Independent State for Action Admission in AgenticOS
Abstract
LLM-powered agents increasingly act on shared scientific infrastructure using a representation of the environment assembled from tools, retrieval, and memory. That representation can become stale or corrupted, allowing an agent to issue a command that is valid under its context but inconsistent with current system state. A security mechanism drawing environment state from the same information path can inherit the same error. We propose that agentic runtimes expose independently sourced environment observations as a minimal abstraction for action admission, so that the evidence used to admit a command need not share the context path that produced it. We sketch CHARON, which checks commands for consistency with such observations, as one realization.