Context-Progressive Execution for Governed Agentic Systems
Abstract
Agentic systems create an authorization problem that conventional request security does not capture: the principal and application may be known at admission, while the execution plan, worker agent, tool, resource, action, and external effect emerge only after reasoning begins. We argue that an Agentic OS should carry a portable execution contract whose security semantics survive framework, transport, provider, and runtime substitution. We introduce context-progressive execution: typed, contract-bound microcontracts over an immutable envelope containing identity and delegation, scope, plan/task purpose, authority, budgets, data policy, and provenance. Context becomes progressively more specific while scope, authority, and budgets cannot silently grow and lineage cannot disappear. Policy decisioning is separated from enforcement at admission, agent invocation, effect execution, and egress. A dependency-light prototype demonstrates the abstraction across HTTP/SSE, Agent2Agent (A2A), and replaceable state/governance providers. We close with falsifiable conformance and fault-injection hypotheses for AgenticOS security semantics.