Abstract
Current work on securing autonomous AI agents treats identity, delegation, and error correction as separate problems, addressed by separate standards. This paper argues they are the same problem, observed at three different points in a task’s lifecycle. The underlying cause is how task intent is represented: fields of a task are either explicitly constrained by the user or left open for an agent to decide, and no current schema distinguishes the two.
The Intent Graph is an addressable schema in which every task field is tagged declared or open, dependency between fields is tracked explicitly, and both authorization revocation and later outcome correction operate as the same graph traversal at different times.