Authorization closure graph improves updates for llm agents
Authorization Closure Graph: Minimal Repair for LLM Agents with Evolving User Instructions
Artificial Intelligence
Summary
Large language model agents often need permission to make changes based on user instructions, but when users change just part of their request, existing methods don’t handle updating these permissions well. The authors propose a system, called Authorization-Closure-Graph (ACG), which tracks permissions and their connections as the instructions change. ACG smartly updates only the parts of permissions affected by revisions and figures out what extra permissions are needed, avoiding unnecessary or outdated authorization requests. Testing with different large language models on real tasks showed that ACG helps agents act more safely and successfully.
What this means in practice
- •For llm application developers: Integrate selective permission updates for language agents adapting to changing user commands to reduce unnecessary authorization prompts and improve workflow safety.
- •For security engineering teams: Implement finer-grained control on evolving permission states in systems using LLM-based automation to prevent use of outdated credentials and minimize risk.
Authors
Qingzhuo Wang, CaiYi Wang, Jinglu Meng, Ruiyang Qin, Kunyu Peng, Zhihua Wei, Wen Shen
Abstract
Tool-using large language model (LLM) agents increasingly perform state-changing actions that require user authorization. Yet existing approaches do not provide a principled mechanism for selectively updating prior authorization when only part of an instruction changes. To this end, we propose an Authorization-Closure-Graph (ACG)-based framework that represents authorization and its dependencies as an evolving, versioned state. ACG selectively invalidates authority affected by a revision while preserving unaffected portions of the authorization state, and computes a minimal repair that identifies only the missing evidence or authority required for execution. This enables agents to adapt to revised instructions while avoiding stale authority and unnecessary authorization requests. We evaluate ACG across three advanced LLMs in two natural tasks, and ACG consistently improves action safety rate and task success rate. Code is available at https://github.com/weiliang822/ACG.