SovereignRoot blog

AI agent boundaries, honestly explained

Practical, no-hype writing on signed policy files, prompt injection, and what actually enforces a boundary.

Agent delegation and authority amplification

Child agents can silently amplify authority. Attenuation-only delegation and a root ceiling keep scope creep in check.

Signing JSON in the browser with Web Crypto

ECDSA P-256, RFC 8785 canonicalization, JWK thumbprints, and encrypted key export.

AI agent authorization: the grant layer and the ceiling layer

OAuth, delegation receipts and scope tokens grant authority. A signed root policy caps it.

What a signed AI policy file can and can't do

A signed sovereignty.json is tamper-evident and portable. It is not, by itself, a security boundary.

How to define AI agent boundaries that survive model changes

Deny-overrides, require-approval, and attenuation-only semantics — a practical guide.

Prompt injection, policy files, and the enforcement gap

Putting a policy in a prompt is not the same as enforcing it. Here's the gap.