Briefs / Brief №020 / Audit Packet
← Return to brief
Autonoma / Intelligence Brief №020 · Public Audit Packet · September 2026
Read the brief →

Audit Packet: Hold the Action Before It Becomes Effective

This public Audit Packet documents the evidence basis, claim boundaries, counterarguments, editorial judgments, and falsification tests behind Brief No. 020.

This audit packet supports Brief №020: Hold the Action Before It Becomes Effective. Read the brief first for the full argument.

Autonoma briefs are designed to be inspectable. This packet shows what the brief claims, how each claim was tested, what it does not claim, and where caveats remain — without exposing raw internal logs, prompts, operator notes, source-routing mechanics, hashes, local paths, secrets, or unpublished candidate claims.

← Open Brief №020 — Hold the Action Before It Becomes Effective

§ 01

Brief Summary and Audit Verdict

The central thesis, what the evidence supports, and what it does not.

Brief 020 asks whether an enterprise can prove a consequential agent action can be held, refused, or made non-effective before it lands — including when the instruction arrived through a trusted operational signal and the agent is using permissions it already hold.

Evidence verdict: SUPPORTED AT THE MECHANISM AND EVALUATION-CONSTRUCT LAYER.

The Brief is supported at the mechanism and evaluation-construct layer. Three independent domains carry the load-bearing set. The Brief does not claim prevalence, does not claim a production HR or LMS hold fired, and labels the vendor-positioning forecast as Autonoma synthesis.

§ 02

Claim Register

Each public claim, its evidence, the verdict, and the boundary.

Public claimEvidenceVerdictBoundary
Enterprise agent evaluation treats hold / narrow / refuse / escalate / quarantine / make-non-effective before protected consequence as a readiness test1Final-supportedCAGE-1 paper; evaluation construct, not a production pass rate
A prompt injection in a public issue induced an analysis agent to start a workflow reserved for trusted repository users2Final-supportedGoogle ADK reporting, 4 Aug 2026; named incident, not a rate
Attackers can manipulate an authenticated agent into abusing permissions it legitimately holds3Final-supportedGhostJacking reporting, 10 Aug 2026; named research account, not a rate
Identity products and PAM tutorials prove pre-effective control exists in production HR or learning systems—WithheldVendor behavior only; not load-bearing
12-month read: identity and PAM vendors will keep selling actor-control as stop-control—Autonoma synthesisLabeled forecast; not a quotation-level fact
§ 03

Source Ledger

What each source is competent to prove — and its material limitation.

SourceSource classRole in BriefMaterial limitation
CAGE-1: Control, Assurance, and Governance Evaluation for Enterprise Agentic AI 1arXiv evaluation paperPrimary evaluation construct; load-bearing for the readiness-test judgmentDoes not measure deployed HR/LMS pass rates
Google ADK flaws reveal what happens when AI agents trust the wrong message 2Journalism (CSO Online)Load-bearing for the trusted-repository-signal mechanismNamed incident, not a rate
‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents 3Journalism (Dark Reading)Load-bearing for authorized-access abuseNamed research account, not a rate

PwC workforce-governance copy and Lumenova incident roundups were inspected and kept out of the load-bearing set.

Pages acquired after the 2 September packet freeze — additional Dark Reading incident reports, later CAGE-family preprints, and NIST competition writeups — were not added to the load-bearing set. They do not change the three-domain register above.

§ 04

Evidence Boundaries

The bounded conclusions, and the precise editorial boundary.

  • Journalism ≠ prevalence.
  • Framework paper ≠ production pass.
  • Vendor identity / PAM pages ≠ proof a hold fired in HR or learning.
  • Briefs 003, 005, 007, 012, 014, 015, and 019 remain differentiated prior art. This Brief does not redo identity, revocation-after-grant, org-chart recordability, roster drift, speculative disclosure, semantic misread, or suite-as-platform.
  • Excluded from load-bearing use: the 63 percent unauthorized-scope figure; categorical “lack pause/rollback” wording; NIST-competition hijacking as deployed-fleet proof; 76 percent NHI survey wording; EU AI Act high-risk employment classification.
§ 05

Dissent and Limiting Case

The live objection and the missing production hold record.

The live objection is that identity plus least privilege plus a kill switch already is pre-effective control. The packet records that objection as open. No final-supported row in this packet shows a trusted-signal instruction stopped before effect.

The limiting case the spine asked for — a documented production path where the hold fired — is absent. That absence is the dissent, not a footnote.

§ 06

Falsification

How this Brief would be wrong, or must be rewritten.

This Brief is wrong, or must be rewritten, if:

  • the CSO or Dark Reading accounts are withdrawn or shown not to describe agent spend of held permissions; or
  • CAGE-1 does not test pre-effective admission / hold / refuse; or
  • an independent production record shows that trusted-signal instructions cannot spend held permissions because a hold or refuse actually fired — in which case the missing-control claim narrows.
§ 07

Forecast Label

What is synthesis versus quotation-level fact.

“Identity and PAM vendors will keep selling actor-control as if it were pre-effective stop-control” is Autonoma Intelligence synthesis. It is not a quotation-level fact.
§ 08

Correction Log

Post-publication corrections, if any.

Correction, 25 September 2026: The publication dates of the CSO Online and Dark Reading sources were corrected to 4 August 2026 and 10 August 2026. No claim changed.

§ 09

Authoring and Publication Status

The human editorial judgment on readiness.

  • Authoring authority: human editorial (Autonoma Intelligence)
  • Evidence basis: governed Brief 020 evidence packet and three load-bearing sources (1, 2, 3)
  • Issue date September 7, 2026
  • Companion: public Audit Packet issued with the Brief
  • Publication channel: website (issue date September 7, 2026)
§ Methodology

Methodology

How sources were reviewed and what was deliberately excluded.

Authored from a governed evidence packet against a human-approved spine. Load-bearing claims are final-supported. Public prose does not expose internal identifiers, hashes, or control tokens.

§ Sources

Sources

Numbered to match the citations in Brief №020 and in this packet.

  1. CAGE-1: Control, Assurance, and Governance Evaluation for Enterprise Agentic AI. Roopam W. Sure, arXiv:2607.03510.
  2. Google ADK flaws reveal what happens when AI agents trust the wrong message. Prasanth Aby Thomas, CSO Online, 4 August 2026.
  3. ‘GhostJacking’ Exposes Identity Governance Gaps in AI Agents. Jai Vijayan, Dark Reading, 10 August 2026.