Cognitive Admission Control: Risk-Conditioned Assurance for Consequential Actions in Agentic Distributed Systems
cs.DC, cs.AI, cs.SE
Submitted: 2026-09-14
Updated: 2026-09-14
Comments: 15 pages, 1 figure, 2 tables; includes formal proofs, obligation catalogue, and empirical local evaluation
License: http://creativecommons.org/licenses/by/4.0/
The gist: In agentic distributed systems, an agent may be authorized to mutate external infrastructure while lacking evidence that the mutation is ready to execute.
Terminology
Abstract
In agentic distributed systems, an agent may be authorized to mutate external infrastructure while lacking evidence that the mutation is ready to execute. Cognitive Admission Control (CAC) makes this evidence requirement explicit. A policy maps a typed action and its modeled risk to assurance obligations specifying predicates, evidence classes, scope, freshness, and witness-set constraints. A deterministic evaluator distinguishes satisfied, violated, and unresolved obligations; unresolved conditions produce targeted evidence-acquisition requests. Successful admission produces a certificate binding the action, its witness manifest, and dispatch-time guards. We formalize the admission calculus and the assumptions connecting it to mediated execution. The guarantees are policy-relative: physical safety additionally requires sound evidence, an adequate environment model, and preservation of relevant conditions through the effect. A TypeScript prototype is evaluated in 2,730 controlled local trials with independent effect observation and matched fault schedules. Across 390 CAC trials, 120 effects complete without modeled harm and no harmful effects occur. A live-policy baseline achieves the same completion count but admits the constructed correlated-witness failure. Mechanism ablations isolate guard, evidence-class, structural-cut, and remediation behavior. A further 9,000 measurements exercise the complete local dispatch path with persistent replay protection. These results establish tested implementation behaviors and local costs, not production failure rates or comparisons of language-model capability.
Sources
- Post-Deterministic Distributed Systems: A New Foundation for Trustworthy Autonomous Infrastructure
- Mnemosyne: Agentic Transaction Processing for Validating and Repairing AI-generated Workflows
- Scaling LLM Test-Time Compute Optimally can be More Effective than Scaling Model Parameters
- Atomix: Timely, Transactional Tool Use for Reliable Agentic Workflows
- Sovereign Assurance Boundary: Certificate-Bound Admission for Agentic Infrastructure
- ReAct: Synergizing Reasoning and Acting in Language Models
- Let's Verify Step by Step
- Temporary Authority, Permanent Effects: Commit-Time Authorization for LLM Agents
Related papers
- iScheduler: Reinforcement Learning-Driven Continual Optimization for Large-Scale Resource Investment Problems
- SAMM: Sharded Automated Market Maker
- InferScale: GPU-Native KV Injection for Personalized LLM Serving
- Vigil: Accountable Liveness against Selective Silence
- Steelhead: Interleaving Partially Synchronous and Asynchronous Commit Rules on a Shared DAG
- Pushing CPU Speech Synthesis to the Wall: Extreme Inference Tuning under Serverless Architecture and Billing