AAL AGENT ACCESS LAYER
01 / 12
PDF
Northline Outfitters store

AGENT ACCESS LAYER

Agents can act.
Can we trust them?

Scoped authority and verifiable human control for agentic actions.

THE PROBLEM

The interface changed.
The trust model didn’t.

01

Intent is not authority

A prompt explains what someone wants—not what an agent is permitted to do.

02

Access is too coarse

Traditional scopes rarely express tools, limits, payment boundaries, and revocation together.

03

Logs arrive too late

Post-hoc records cannot prove that authority was enforced when an action occurred.

04

Attribution disappears

Agent choices and human changes collapse into the same application state.

OUR THESIS

AAL is the missing trust layer.

HUMANexpresses intent
AALdefines authority
AGENTtakes scoped action
APPLICATIONverifies and records
Explicit.Machine-readable Grants define tools, limits, and boundaries.
Enforceable.Every consequential call is checked before dispatch.
Provable.Agent, protocol, and human actions remain attributable.

HOW IT WORKS

One Grant. Every consequential step.

1

Human intent

“Build me an outfit.”

2

Scoped Grant

Tools, effects, limits, revocation.

3

Authorized actions

Checked before every dispatch.

4

Prepared commitment

Stable ID, hash, terms, expiry.

5

Human boundary

Review before payment.

THE CRITICAL DESIGN CHOICEPreparation is not execution.

The agent can assemble a consequential action without automatically crossing its final boundary.

LIVE DEMO

Make it concrete.

Northline Outfitters is a fictional fashion store built on the real AAL protocol services.

28catalog products
3granted tools
0payment authority
USER REQUEST
“I need an outfit with blue jeans and a cropped boxy white t shirt.”
STYLE MY OUTFIT →

THE RESULT

From request to prepared outfit.

  • Five coordinated products selected
  • Every choice attributed to the agent
  • $256 transaction prepared from exact records
  • Commitment ID, hash, terms, and expiry
Northline selected outfit and prepared transaction

THE PROOF

Not a post-hoc story.
An enforced history.

01AAL session establishedAAL
02Core Grant installedAAL
03Catalog exploredAGENT
04Outfit composedAGENT
05Transaction preparedAGENT

HUMAN CONTROL

The user never disappears.

Agent decisions remain attributed. Manual changes create new human-authored transaction revisions.

AGENTSelected the original outfitaal_grant_used: true
YOUAdded a jacket · removed a capaal_grant_used: false
Human-edited outfit with actor metadata

THE BOUNDARY

The thing the agent
cannot do matters most.

grant.payernone
payment_permissionfalse
transaction.stateprepared
payment.statusnot_started

The limitation appears in the Grant, authorization evidence, transaction state, and interface.

THE PLATFORM

Fashion makes it visible.
The protocol goes everywhere.

Travel

Search itineraries and prepare a booking before purchase.

Procurement

Build a purchase order inside policy and budget limits.

+

Healthcare

Scope access to sensitive records and approved purposes.

Financial services

Research and prepare a trade before final authorization.

WHAT’S NEXT

From complete demonstration
to agent infrastructure.

NOW

Proven trust loop

  • Grant Consent and Host Evidence
  • Lifecycle and dispatch enforcement
  • Attributable agent/human actions
  • Prepared commitments and audit export
NEXT

Production integration

  • External agent runtime adapters
  • User-managed Grants and revocation
  • Trusted approval displays
  • SDKs and conformance tooling
THEN

Consequential execution

  • Payment behind explicit approval
  • Travel and procurement profiles
  • Portable cross-site receipts
  • Interoperable agent ecosystem

AGENT ACCESS LAYER

Agents need more
than intelligence.

They need accountable authority.

AAL makes agent authority explicit, enforceable, and provable.