Establish a comparable baseline
Preserve a declared Agent Scope or Agent Risk Atlas export from the known release. The comparison should disclose its source schema, normalization method and ruleset instead of treating unlike reports as interchangeable.
Separate authority expansion from ordinary change
New private-data access, external communication, code execution, delegated identity, destructive writes, financial action or autonomous loops deserve explicit review. A single score hides which boundary moved and in which direction.
Track control removal and coverage regression
A candidate can keep the same capabilities while losing an egress allowlist, sandbox or confirmation gate. Compare both the control set and the coverage state of attack paths active in both releases.
Use gates as review conditions, not certificates
A gate can require review when a critical path appears, sensitive authority expands or isolation needs grow. A gate that is not triggered means only that its condition was not observed in these declared inputs.
Export minimized release evidence
Keep two local SHA-256 hashes, normalized deltas, gate statuses and limitations. Omit raw reports, filenames and tool names. Recheck runtime identity, authorization and control enforcement independently.
Frequently asked questions
H/M Blindspot · hogarmas.net
What is AI agent permission drift?
It is a change in effective or declared authority between two releases, such as a new capability, removed control or newly active attack path.
Does no observed drift mean the agent is safe?
No. It only means the current bounded comparison found no normalized change. Runtime behavior, control implementation and completeness remain unverified.
Are source reports uploaded?
No. H/M Agent Drift parses, hashes and compares supported reports inside the browser and excludes raw reports, filenames and tool names from exports.
