{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:QPFYCRFYXJ3FRH2JUPTDP6FFME","short_pith_number":"pith:QPFYCRFY","schema_version":"1.0","canonical_sha256":"83cb8144b8ba76589f49a3e637f8a561087ea5ff484a866590f669072e21af46","source":{"kind":"arxiv","id":"2504.21034","version":2},"attestation_state":"computed","paper":{"title":"SAGA: A Security Architecture for Governing AI Agentic Systems","license":"http://creativecommons.org/publicdomain/zero/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Alina Oprea, Anshuman Suri, Cristina Nita-Rotaru, Georgios Syros, Jacob Ginesin","submitted_at":"2025-04-27T23:10:00Z","abstract_excerpt":"Large Language Model (LLM)-based agents increasingly interact, collaborate, and delegate tasks to one another autonomously with minimal human interaction. Industry guidelines for agentic system governance emphasize the need for users to maintain comprehensive control over their agents, mitigating potential damage from malicious agents. Several proposed agentic system designs address agent identity, authorization, and delegation, but remain purely theoretical, without concrete implementation and evaluation. Most importantly, they do not provide user-controlled agent management.\n  To address thi"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2504.21034","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-27T23:10:00Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"00798659b55d603f2b1c9ce144eb005a21a84cf8d148dab9379bf9d2cf074fe0","abstract_canon_sha256":"ab23f91fc8b63df7a478783eacf4f0489646c7a693a3d22452d59481e1e21f07"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:01:45.160023Z","signature_b64":"PDnn9sGgis4kGZUTQoKM5t7ihS//TmGeYJJqiW0EfnOvGj4UFj+h9jYA2DyIaUhIpYYHrDJ4ZlE/6RlOVw25Bg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"83cb8144b8ba76589f49a3e637f8a561087ea5ff484a866590f669072e21af46","last_reissued_at":"2026-07-05T12:01:45.159495Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:01:45.159495Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SAGA: A Security Architecture for Governing AI Agentic Systems","license":"http://creativecommons.org/publicdomain/zero/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Alina Oprea, Anshuman Suri, Cristina Nita-Rotaru, Georgios Syros, Jacob Ginesin","submitted_at":"2025-04-27T23:10:00Z","abstract_excerpt":"Large Language Model (LLM)-based agents increasingly interact, collaborate, and delegate tasks to one another autonomously with minimal human interaction. Industry guidelines for agentic system governance emphasize the need for users to maintain comprehensive control over their agents, mitigating potential damage from malicious agents. Several proposed agentic system designs address agent identity, authorization, and delegation, but remain purely theoretical, without concrete implementation and evaluation. Most importantly, they do not provide user-controlled agent management.\n  To address thi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.21034","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.21034/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2504.21034","created_at":"2026-07-05T12:01:45.159560+00:00"},{"alias_kind":"arxiv_version","alias_value":"2504.21034v2","created_at":"2026-07-05T12:01:45.159560+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.21034","created_at":"2026-07-05T12:01:45.159560+00:00"},{"alias_kind":"pith_short_12","alias_value":"QPFYCRFYXJ3F","created_at":"2026-07-05T12:01:45.159560+00:00"},{"alias_kind":"pith_short_16","alias_value":"QPFYCRFYXJ3FRH2J","created_at":"2026-07-05T12:01:45.159560+00:00"},{"alias_kind":"pith_short_8","alias_value":"QPFYCRFY","created_at":"2026-07-05T12:01:45.159560+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":12,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.19464","citing_title":"Deontic Policies for Runtime Governance of Agentic AI Systems","ref_index":36,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03518","citing_title":"Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI","ref_index":39,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02302","citing_title":"SeClaw: Spec-Driven Security Task Synthesis for Evaluating Autonomous Agents","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2606.20615","citing_title":"Specifying AI-SDLC Processes: A Protocol Language for Human-Agent Boundaries","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2603.18829","citing_title":"Agent Control Protocol: Admission Control for Agent Actions","ref_index":51,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06205","citing_title":"ClawGuard: Out-of-Band Detection of LLM Agent Workflow Hijacking via EM Side Channel","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01091","citing_title":"Governing What the EU AI Act Excludes: Accountability for Autonomous AI Agents in Smart City Critical Infrastructure","ref_index":86,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19657","citing_title":"An AI Agent Execution Environment to Safeguard User Data","ref_index":65,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09998","citing_title":"Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit","ref_index":76,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06738","citing_title":"From Specification to Deployment: Empirical Evidence from a W3C VC + DID Trust Infrastructure for Autonomous Agents","ref_index":16,"is_internal_anchor":false},{"citing_arxiv_id":"2604.15367","citing_title":"SoK: Security of Autonomous LLM Agents in Agentic Commerce","ref_index":95,"is_internal_anchor":false},{"citing_arxiv_id":"2604.14723","citing_title":"Bounded Autonomy for Enterprise AI: Typed Action Contracts and Consumer-Side Execution","ref_index":18,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME","json":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME.json","graph_json":"https://pith.science/api/pith-number/QPFYCRFYXJ3FRH2JUPTDP6FFME/graph.json","events_json":"https://pith.science/api/pith-number/QPFYCRFYXJ3FRH2JUPTDP6FFME/events.json","paper":"https://pith.science/paper/QPFYCRFY"},"agent_actions":{"view_html":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME","download_json":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME.json","view_paper":"https://pith.science/paper/QPFYCRFY","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2504.21034&json=true","fetch_graph":"https://pith.science/api/pith-number/QPFYCRFYXJ3FRH2JUPTDP6FFME/graph.json","fetch_events":"https://pith.science/api/pith-number/QPFYCRFYXJ3FRH2JUPTDP6FFME/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME/action/storage_attestation","attest_author":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME/action/author_attestation","sign_citation":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME/action/citation_signature","submit_replication":"https://pith.science/pith/QPFYCRFYXJ3FRH2JUPTDP6FFME/action/replication_record"}},"created_at":"2026-07-05T12:01:45.159560+00:00","updated_at":"2026-07-05T12:01:45.159560+00:00"}