Hacker News new | ask | show | jobs
by dreadpirates 89 days ago
Great research. The 93% unscoped key finding matches what we see in practice. We built nornr.com specifically for the spend side of this: agents request a mandate before any financial action, policy scopes what's allowed (amount, vendor, frequency), every decision gets a signed receipt for audit. Works with existing payment rails. The delegation and revocation gaps you identified are first class concerns in our model. Would be interesting to see how your framework scores projects that adopt a mandate based approach.