iT邦幫忙

2026 iThome 鐵人賽

DAY 28
0
AI Security

AI Agent 憑什麼動手?30 天拆解 Agent Identity、Delegation 與 Authorization系列 第 28 篇

Day 28|Agent 權限被撤銷後,已經開始的 Task 怎麼辦?

  • 分享至 

  • xImage
  •  

Core Question

Delegation 或 User access 撤銷後,排隊中、執行中與部分完成的 Agent Task 應如何處理?

今天的問題

採購 Agent 已獲准建立三張訂單。第一張完成時,Alice 的 delegation 被撤銷;第二步正在呼叫供應商 API,第三步尚未開始。只讓「下一次登入」失敗是不夠的:排隊工作可能繼續跑,重試可能重放,已完成的不可逆訂單也不能假裝不存在。

為什麼這不是傳統 IAM 問題

短效 token expiry 與 authority revocation 是不同事件;Agent task 有 queue、planner、Tool retries、checkpoint 和 partial side effects。授權決策必須在每個不可忽略的 Action 前重新評估,且要明確處理 in-flight race。拿掉 Agent 後,動態多步規劃與自主 retry 的風險不成立。

Threat / Failure Scenario

Naive worker 在 task 開始時驗證一次 grant,接著連續呼叫五個 Tool。撤銷事件只更新 IdP,worker 看不到;網路 timeout 後它又重試退款,導致撤銷後仍產生 side effect。另一個極端是立即 kill process,卻沒有記錄已完成步驟或補償需求。

撤銷事件在第一步完成與第二步送出之間到達;若 worker 只在 task 開始驗證,舊 grant 會讓後續 Action 繼續執行,甚至因 retry 造成重複 side effect。

核心概念

把 Task 拆成可審計的 Action checkpoint。pending 在開始前檢查;in-flight 要有 lease、deadline、idempotency key 和 cancellation signal;completed 保存 outcome,必要時走受控 compensation。撤銷不是回溯歷史,而是阻止未來 authority 使用。不可逆 Action 若已進入 provider boundary,應以 provider status、cancel API 或人工處置收斂,而非假設 process kill 能回滾。

PDP 可回傳 allow、deny、finish-safe-step 或 compensate-required。PEP 於每個 checkpoint 重查 delegation version/epoch;撤銷時遞增 epoch,使舊 lease 失效。Race window 仍需承認:若 provider 已接受請求,必須依 idempotency 與 outcome reconciliation 做最終判斷。

Architecture Pattern

Naive / Unsafe Design

Task start -> one allow -> Agent executes all steps -> revoke ignored

Recommended Design

https://ithelp.ithome.com.tw/upload/images/20260925/20120151jnXeDdnr2M.png

Trust boundary 在 task worker 與 revocation/PDP 之間;worker 不能自行延長 lease。Identity flow 為 User/Delegation epoch + Agent actor + task state → PDP checkpoint → PEP;Tool/Resource 的回應再寫入 evidence。Authorization Decision Point 是每個 checkpoint,不是 task 啟動時的一次檢查。

小型 PoC

steps = ["create-order-1", "create-order-2", "notify"]
grant_epoch, revoked = 1, False
done, events = [], []
for step in steps:
    if step == "create-order-2":
        revoked = True
        events.append((step, "revocation-observed"))
    if revoked:
        events.append((step, "stopped"))
        break
    events.append((step, "allow"))
    done.append(step)                 # idempotency key would be task+step
    events.append((step, "completed"))

assert done == ["create-order-1"]
assert events[-1] == ("create-order-2", "stopped")
print(events)

執行結果應顯示第一步完成、撤銷後第二步停止,且第三步未執行。這個同步 PoC 沒有模擬真正的網路 race、provider cancel 或 compensation;那些必須在整合測試以明確 contract 驗證。

今天得到什麼

  • Token expiry 不等於已發 authority 的即時撤銷。
  • 長任務要在 Action checkpoint 重新決策,並以 lease/epoch 限制舊 authority。
  • in-flight、completed、partial side effect 必須分開處理。
  • 停止、完成安全步驟、reconcile 與 compensation 都要留下 evidence。

下一篇

撤銷要求每次跨界都重新驗證;下一篇把這個原則放回 User、Agent runtime、model、MCP、Tool 與 Resource,畫出 Agent-specific Zero Trust。

參考資料


上一篇
Day 27|怎麼證明某個 Action 真的是 Agent 在當時被允許執行?
下一篇
Day 29|Zero Trust 如果套到 AI Agent,Trust Boundary 應該畫在哪?
系列文
AI Agent 憑什麼動手?30 天拆解 Agent Identity、Delegation 與 Authorization 共 30 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言