正确性不受管控:智能体工作流的来源完整性
Correct Is Not Governed: Provenance Integrity in Agentic Workflows
- Microsoft(微软公司)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文针对智能体工作流的来源完整性问题,提出确定性因果状态层Matrix作为机构完整性层,可记录依赖、验证证据,使工作可审计,且能限制恢复范围。
AI中文摘要:
智能体工作流通常通过是否达成正确结果来评估,但在机构场景中这并不足够——正确的动作可能依赖错误的权限、无依据的完成声明,或因后续变更而过时的工作。我们将受管控执行定义为决策、完成及对变更的响应均有可检查来源支撑的工作。我们提出Matrix,这是一个确定性因果状态层,用于记录权限与事实依赖、验证完成证据,并选择性使受影响工作失效。在受控对比中,受管控与直接工作流常达成相同结果,但仅受管控路径始终保留管控证据、拒绝无依据的结案,并将恢复限制在依赖任务内。随后的角色分离转移挑战中,确定性强制的完整性合约严重阻止了在其创作上下文外生成的合成数据包。这些结果未证明Matrix是通用准确性增强器,而是支持其作为机构完整性层的核心作用,使智能体工作可审计且可独立验证。
英文摘要:
Agentic workflows are commonly evaluated by whether they reach the correct outcome. That is insufficient in institutional settings, where a correct action may rely on the wrong authority, an unsupported completion claim, or work made stale by a later change. We define governed execution as work whose decisions, completion, and response to change are supported by inspectable provenance. We present Matrix, a deterministic causal-state layer that records authority and fact dependencies, verifies completion evidence, and selectively invalidates affected work. Across controlled comparisons, governed and direct workflows often reached the same outcomes, but only the governed path consistently preserved governing evidence, refused unsupported closure, and limited recovery to dependent tasks. A role-separated transfer challenge then failed: a deterministically enforced completeness contract severely over-blocked synthetic packets produced outside its authoring context. These results do not establish Matrix as a general accuracy enhancer; they support its primary role as an institutional integrity layer for making agentic work auditable and independently verifiable.