Empirical Evaluation of Task-Based Permission Scoping Architecture for AI Agents

| Source: arXiv AI

Tags: AI agent security, task-based access control, RoBERTa, enterprise AI security, Claude Haiku

A fine-tuned RoBERTa-large classifier matches Claude Haiku 4.5 for task-permission classification (macro-F1 0.881 vs 0.886) while reducing severity-weighted residual risk from 1.12 to 0.63, and combining role ceilings with the classifier closes 84.4% of attack surface vs 27.9% from role ceilings alone.

Details

AI agents in enterprise settings typically receive the full credential set of the employee role at deployment — a compromise made for human principals because scoping access per task was operationally infeasible. For agents, whose tasks arrive as machine-readable text, this compromise is unnecessary and leaves credentials exposed when the current task does not require them. This paper implements and evaluates a three-layer permission architecture: role-based ceilings (the maximum an agent of this type could need), a task-permission classifier (what this specific task actually requires), and policy-based prohibitions (what is never permitted regardless). The classifier is a fine-tuned RoBERTa-large encoder trained on a 600-prompt labelled dataset. Key results: the RoBERTa-large classifier matches Claude Haiku 4.5 in classification quality (macro-F1 0.881 vs 0.886) while having much lower severity-weighted residual risk (0.63 vs 1.12). Critically, a smaller trusted component does not need to scale with the agent it supervises — the oversight margin is wide. The attack-surface metric quantifies the value: role ceilings alone close 27.9% of severity-weighted surface; adding the task classifier closes 84.4%. The paper argues AI agents are the first principal type for which task-granular access control is enforceable.