{
  "id": 716,
  "url": "https://arxiv.org/abs/2606.22916v1",
  "title": "Intent-Governed Tool Authorization for AI Agents",
  "summary": "AI agents increasingly act through external tools: they read private data, construct structured payloads, submit write requests, export records, and coordinate workflows across application boundaries. Existing authorization mechanisms usually ask whether an integration credential, app, or token can call a tool. That question is necessary but incomplete. A tool call can be authorized by static credentials and still be unjustified by the user's current request. For example, a credential that can r",
  "authors": "Genliang Zhu, Chu Wang",
  "category": "research",
  "topics": "agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-06-22T06:55:57.000Z",
  "fetched_at": "2026-07-14T14:14:46.033Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/716",
  "original_url": "https://arxiv.org/abs/2606.22916v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}