Systems and methods for delegated authority management, runtime enforcement, and revocation in autonomous computational entities
Described herein are systems, methods, and media for governing delegated execution authority in computational entities. An authority object comprising authority constraints is generated and associated with an autonomous computational entity independently of identity credentials. Proposed actions may be intercepted at runtime and evaluated against the authority object to determine execution eligibility. The execution of the proposed action is controlled by permitting, modifying, delaying, attenuating, redirecting, or suppressing the action. Authority objects may be dynamically modified or revoked with revocation propagating across systems.
1 . A computer-implemented method for controlling execution of actions by a computational entity executed at one or more computer processors, the method comprising:
(a) receiving, from a delegator, a request to delegate execution authority to a computational entity;
(b) generating an authority object comprising one or more authority constraints;
(c) associating the authority object with governance of execution of actions generated by the computational entity;
(d) intercepting, at runtime, prior to execution, and at an execution boundary, a proposed action generated by the computational entity;
(e) evaluating the proposed action based at least on the one or more authority constraints of the authority object; and
(f) controlling execution of the proposed action based on the evaluation, wherein controlling execution of the proposed action comprises one or more of: permitting, modifying, delaying, attenuating, redirecting, and suppressing execution of the proposed action.
2 . The method of claim 1 , wherein associating the authority object with the execution of actions generated by the computational entity is done independently of any identity credentials of the computational entity.
3 . The method of claim 1 , wherein associating the authority object with the execution of actions generated by the computational entity is done independently of any identity credentials of the delegator.
4 . The method of claim 1 , wherein the delegator is a second computational entity.
5 . The method of claim 1 , wherein the one or more authority constraints comprise a temporal execution constraint, and wherein the temporal execution constraint specifies a duration, an expiration time, or an execution window.
6 . The method of claim 1 , wherein the one or more authority constraints comprise a contextual execution constraint, and wherein the contextual execution constraint is based on environmental, system, or situational data.
7 . The method of claim 1 , wherein the one or more authority constraints comprise a behavioral execution constraint, and wherein the behavioral execution constraint is based on historical or predicted behavior of the autonomous computational entity.
8 . The method of claim 1 , wherein the one or more authority constraints comprise a delegation permission specifying whether and how execution authority may be further delegated.
9 . The method of claim 1 , further comprising associating the authority object with governance of execution of actions generated by one or more additional computational entities.
10 . The method of claim 9 , wherein the one or more additional computational entities are in a delegation chain comprising the computational entity.
11 . The method of claim 10 , further comprising attenuating the authority object after associating the authority object with the execution of actions generated by the computational entity or the one or more additional computational entities.
12 . The method of claim 1 , further comprising repeating steps (d)-(f) one or more times, and wherein the authority object persists through each repetition.
13 . The method of claim 1 , further comprising evaluating the proposed action based on the one or more authority constraints during execution of the proposed action.
14 . The method of claim 1 , wherein the one or more authority constraints are sourced from a CRE.
15 . The method of claim 1 , further comprising revoking one or more authority constraints of the authority object while preserving at least one authority constraint.
16 . The method of claim 1 , further comprising modifying the authority object based on one or more contextual or behavioral signals.
17 . The method of claim 1 , wherein controlling execution of the proposed action comprises rolling back or remediating one or more effects caused by execution of the proposed action.
18 . The method of claim 1 , further comprising generating an audit record associated with the authority object.
19 . The method of claim 1 , further comprising generating an accountability record, wherein the accountability record records one or more effect of the one or more authority constraints on the execution of the proposed action.
20 . The method of claim 1 , further comprising sharing the evaluation of the proposed action based on the one or more authority constraints of the authority object across multiple computing systems.
21 . The method of claim 1 , wherein evaluating the proposed action based on the one or more authority constraints is performed across multiple computing systems.
22 . A computer-implemented system for controlling execution of actions by a computational entity comprising at least one computer processor and instructions executable by the at least one computer processor to provide an application comprising:
(a) an authority management engine configured to perform operations comprising:
i) receive, from a delegator, a request to delegate execution authority to a computational entity,
ii) generate an authority object comprising one or more authority constraints, and
iii) associate the authority object with governance of execution of actions generated by the computational entity; and
(b) an authority enforcement layer configured to perform operations comprising:
i) intercepting a proposed action generated by the computational entity prior to execution of the proposed action;
ii) evaluating the proposed action based at least on the one or more authority constraints of the authority object; and
iii) controlling execution of the proposed action based on the evaluation, wherein controlling execution of the proposed action comprises one or more of: permitting, modifying, delaying, attenuating, redirecting, and suppressing execution of the proposed action.
23 . A non-transitory computer-readable medium storing instructions that, when executed by one or more computer processors, cause the one or more computer processors to perform operations comprising:
(a) receiving, from a delegator, a request to delegate execution authority to a computational entity;
(b) generating an authority object comprising one or more authority constraints;
(c) associating the authority object with the execution of actions generated by the computational entity;
(d) intercepting, prior to execution, a proposed action generated by the computational entity;
(e) evaluating the proposed action based at least on the one or more authority constraints of the authority object; and
(f) controlling execution of the proposed action based on the evaluation, wherein controlling execution of the proposed action comprises one or more of: permitting, modifying, delaying, attenuating, redirecting, and suppressing execution of the proposed action.