permissions enforced by the backend outside the model (no role grantable by speech), tool allowlist, deterministic approval for any write, routing fraud detection.
The threat
the attacker obtains rights or actions they do not have by asking and being served (fraudulent request, policy bypass, routing fraud, unauthorized update, workflow escalation).
Angle mortWhy classic frameworks miss it
elevation is not an ACL bug but a property of dialogue with an overly compliant model: I-am-the-admin creates no permission if the backend refuses.
MitigationProposed approach
permissions enforced by the backend outside the model (no role grantable by speech), tool allowlist, deterministic approval for any write, routing fraud detection.
The proposed control
rights granting goes through a deterministic authorization independent of what the model says.
Expected evidence
demonstrate that rights granting goes through a deterministic authorization independent of model speech.