An Authority Lifecycle for Self-Modifying Embodied Agents
Abstract
\begin{abstract} Agents can increasingly synthesize and replace executable behavior while remaining online. For embodied systems, this turns software updating from an operator-mediated event into a recurrent control loop: proposer authority, active version, capabilities, budgets, and physical safety state can change while a candidate is being generated or checked. We argue that AgenticOS should therefore treat self-publication as a \textbf{continuously revalidated authority lifecycle}. The mechanisms involved---verification, privilege separation, capabilities, reference monitoring, and atomic publication---are classical. The agent-specific systems problem is their composition when an autonomous principal repeatedly proposes replacements against concurrently changing policy, can adapt later proposals to prior admission outcomes, and may cause physical effects without a human deployment gate. We separate proposal, activation, execution privilege, runtime resource authority, and effect authority; admission grants a versioned activation record, while containment remains an independent backstop when admission is wrong. \end{abstract}