并发智能体系统的有状态治理
Stateful Governance for Concurrent Agentic Systems
浏览论文内容
中文总结 AI 辅助
本文针对并发智能体系统的有状态治理问题,提出Provenact运行时架构,可防止失效授权,在采购工作流中避免策略违规,为智能体框架的有状态治理提供了可行路径。
中文摘要 AI 辅助
AI智能体正从咨询界面转向执行重要操作的系统:发放退款、预订稀缺库存、配置云资源以及发起资金转账。这些工作流需要对效果而非仅模型输出进行治理。现有安全措施通常根据操作请求时的可用信息判断是否允许该操作。对于有状态策略,该请求时视图可能不完整:预算、库存、审批状态和风险信号可能在效果发生前发生变化,导致先前的授权或审批失效。本文研究并发智能体系统的有状态治理,将失效授权确定为核心故障模式,并定义策略状态可串行性,这一正确性条件要求已提交的效果可解释为针对其发生前的策略状态获得授权。我们提出Provenact,一种运行时架构,该架构将策略保留为可审查的程序,同时协调维护决策所需的状态和效果。在使用PostgreSQL支持的Provenact原型进行的实验中,该系统可防止基线方法遗漏的失效授权,这些基线方法将策略状态作为普通请求上下文传递;在不相关工作进行时保留延迟审批;将策略演进主要保留在策略文本而非受信任的提供方代码中;在无LLM的脚本化采购工作流中避免策略违规,而在该工作流中,智能体治理基线会在共享预算和库存上产生失效授权。更广泛地说,Provenact为将有状态治理边界集成到智能体框架和智能体在共享资源上行动的提供方支持领域提供了一条路径。
英文摘要
AI agents are moving from advisory interfaces into systems that execute consequential operations: issuing refunds, reserving scarce inventory, provisioning cloud resources, and initiating financial transfers. These workflows require governance over effects, not only over model outputs. Existing safeguards often decide whether an action is allowed from the information available when the action is requested. For stateful policies, that request-time view may be incomplete: budgets, inventory, approval status, and risk signals can change before the effect occurs, making an earlier authorization or approval stale. This paper studies stateful governance for concurrent agentic systems. We identify stale authorization as the core failure mode and define policy-state serializability, a correctness condition requiring committed effects to be explainable as authorized against the policy state immediately before they occur. We present MasuGate, a runtime architecture that keeps policies as reviewable programs while coordinating the state and effects needed to preserve their decisions. In experiments with a PostgreSQL-backed prototype of MasuGate, the system prevents stale authorizations missed by baselines that pass policy state as ordinary request context, preserves delayed approvals while unrelated work proceeds, keeps policy evolution mostly in policy text rather than trusted provider code, and avoids policy violations in a scripted, LLM-free procurement workflow where agent-governance baselines produce stale authorizations over shared budgets and inventory. More broadly, MasuGate suggests a path for integrating stateful governance boundaries into agent frameworks and provider-backed domains where agents act on shared resources.