Boundary Quorum Protocol: a verifiable authorization standard for agent evaluations
Lam Nguyen Le Tung
In the July 2026 intrusion, a lab's evaluation let a model cross one trust boundary after another, and no single crossing
had to be authorized by anyone. We propose the fix Track 1 asks for: the Boundary Quorum Protocol (BQP), a standard that
sorts every boundary crossing into five risk tiers and sets the authorization each needs, from auto-execution, to an
independent machine quorum, to a non-delegable human gate, to hard denial, with a hash-chained audit a third party can
check. We calibrate the tiers on 44 machine-readable crossings from the public record, and we evaluate the standard against
four authorization structures and four adversaries. Naive voting is not a containment control, while the full protocol
executes none of the 32 unsafe crossings, at 22 human escalations, and we say where it still fails. A companion detection
harness shows the gated crossings are catchable cheaply, with a rule that fires 66.5 hours before the internal-network
pivot, and a companion attestation protocol, ECA, lets a third party verify a run from an exported bundle with no access to
the lab's network.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Boundary Quorum Protocol: a verifiable authorization standard for agent evaluations
},
author={
Lam Nguyen Le Tung
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


