Control under delegated authority ·

Equality-Support Covers for Exact Branch-Set Preservation under Fixed Actuator Interfaces

A controller limited to a fixed catalogue of modes can usually keep a system safe by cutting off risky futures. This paper asks when it can keep exactly the safe ones, and how few modes that takes.

Read the paper PDF ↗ (opens in a new tab)

The problem

Many systems are controlled through a fixed set of predeclared modes: firmware interlocks that disable the same commands everywhere, or the permission profiles an AI platform ships to gate which tools an agent may call. Such a catalogue can usually keep the system safe by pruning, but it often prunes good futures along with the bad. The paper asks the stricter question: can the catalogue preserve exactly the set of safe futures, all of them and nothing else, and how few entries does that need?

What the paper does

The first step turns a global requirement into a local one. Exact preservation holds precisely when, at every point, the chosen mode allows exactly the next states from which the system can still stay safe, no more and no fewer. Each mode then has a set of states where it is safe and a smaller set where it is exact, and finding the fewest modes becomes a covering problem: choose modes whose exact sets together cover every state.

The paper works this out for two common kinds of interface: masks that switch off a fixed set of controllable events everywhere, and nested interfaces whose modes run in order from most to least permissive.

What it shows

For masks, a mode is safe when it blocks every hazardous event, and exact when it also leaves at least one way into each safe next state. When each event leads somewhere different, finding the fewest exact modes takes polynomial time, while finding the fewest merely safe modes is NP-hard: the stricter goal is the easier one to optimise. For nested interfaces safety needs a single mode, and the exact count is found by a fast greedy method.

The two counts can be as far apart as possible. In both families, one mode can suffice for safety while exactness needs as many modes as there are states. The running example is tool gating for an agent with search, send and purge, where purge can destroy context irrecoverably: there, a single profile that blocks purge alone is exact.

What it does not claim

Exactness here compares the sequences of states a system passes through, so two events that lead to the same state count as one. The model assumes complete tables, a controller that does not remember history, every event available everywhere, and uncontrollable moves that stay safe. The counts are relative to the catalogue on offer, and are not lower bounds on sensors, memory or communication.

Where it sits

A single-author paper in supervisory control theory, written with autonomous agents in mind: its keywords include agentic artificial intelligence, and its running example is a permission profile. The companion paper, on veto authority that changes with history, takes up the case where the interface itself varies.

All 10 papers →