Delegation 或 User access 撤銷後,排隊中、執行中與部分完成的 Agent Task 應如何處理?
採購 Agent 已獲准建立三張訂單。第一張完成時,Alice 的 delegation 被撤銷;第二步正在呼叫供應商 API,第三步尚未開始。只讓「下一次登入」失敗是不夠的:排隊工作可能繼續跑,重試可能重放,已完成的不可逆訂單也不能假裝不存在。
短效 token expiry 與 authority revocation 是不同事件;Agent task 有 queue、planner、Tool retries、checkpoint 和 partial side effects。授權決策必須在每個不可忽略的 Action 前重新評估,且要明確處理 in-flight race。拿掉 Agent 後,動態多步規劃與自主 retry 的風險不成立。
Naive worker 在 task 開始時驗證一次 grant,接著連續呼叫五個 Tool。撤銷事件只更新 IdP,worker 看不到;網路 timeout 後它又重試退款,導致撤銷後仍產生 side effect。另一個極端是立即 kill process,卻沒有記錄已完成步驟或補償需求。
撤銷事件在第一步完成與第二步送出之間到達;若 worker 只在 task 開始驗證,舊 grant 會讓後續 Action 繼續執行,甚至因 retry 造成重複 side effect。
把 Task 拆成可審計的 Action checkpoint。pending 在開始前檢查;in-flight 要有 lease、deadline、idempotency key 和 cancellation signal;completed 保存 outcome,必要時走受控 compensation。撤銷不是回溯歷史,而是阻止未來 authority 使用。不可逆 Action 若已進入 provider boundary,應以 provider status、cancel API 或人工處置收斂,而非假設 process kill 能回滾。
PDP 可回傳 allow、deny、finish-safe-step 或 compensate-required。PEP 於每個 checkpoint 重查 delegation version/epoch;撤銷時遞增 epoch,使舊 lease 失效。Race window 仍需承認:若 provider 已接受請求,必須依 idempotency 與 outcome reconciliation 做最終判斷。
Task start -> one allow -> Agent executes all steps -> revoke ignored

Trust boundary 在 task worker 與 revocation/PDP 之間;worker 不能自行延長 lease。Identity flow 為 User/Delegation epoch + Agent actor + task state → PDP checkpoint → PEP;Tool/Resource 的回應再寫入 evidence。Authorization Decision Point 是每個 checkpoint,不是 task 啟動時的一次檢查。
steps = ["create-order-1", "create-order-2", "notify"]
grant_epoch, revoked = 1, False
done, events = [], []
for step in steps:
if step == "create-order-2":
revoked = True
events.append((step, "revocation-observed"))
if revoked:
events.append((step, "stopped"))
break
events.append((step, "allow"))
done.append(step) # idempotency key would be task+step
events.append((step, "completed"))
assert done == ["create-order-1"]
assert events[-1] == ("create-order-2", "stopped")
print(events)
執行結果應顯示第一步完成、撤銷後第二步停止,且第三步未執行。這個同步 PoC 沒有模擬真正的網路 race、provider cancel 或 compensation;那些必須在整合測試以明確 contract 驗證。
in-flight、completed、partial side effect 必須分開處理。撤銷要求每次跨界都重新驗證;下一篇把這個原則放回 User、Agent runtime、model、MCP、Tool 與 Resource,畫出 Agent-specific Zero Trust。