← Latest papers
💻 computer science

Effective Segregation of Duties in Agentic Enterprise Authorization: Evaluating Shared-Dependence Risk in Maker–Checker Controls

This paper introduces the concept of Effective Segregation of Duties (SoD) to distinguish between nominal identity separation and actual independent assurance in AI-driven authorization, demonstrating through a large-scale P2P benchmark that effective risk mitigation relies on evidence mediation and heterogeneous checker models rather than mere principal distinctness.

Original authors: Mohamed Abbas Elmasry

Published 2026-09-23
📖 5 min read🧠 Deep dive

Original authors: Mohamed Abbas Elmasry

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the world of large organizations, from banks to government agencies, there is a fundamental rule for keeping things safe: no single person should have the power to start a transaction and finish it alone. This principle, known as the separation of duties, ensures that if one person makes a mistake or attempts to act improperly, a second person will catch it before anything harmful happens. For decades, this system relied on two different humans checking each other's work. Today, however, many of these tasks are being handed over to artificial intelligence agents. These are software programs that can read documents, make decisions, and even execute financial transfers. The question facing security experts is no longer just about having two different AI programs, but whether those two programs are truly independent. If both agents rely on the same underlying technology, the same sources of information, or the same way of thinking, they might make the exact same mistake at the same time, rendering the safety check useless.

A recent study set out to test this exact scenario. Researchers created a simulated environment based on real-world procurement rules, where an AI agent acting as a "maker" would propose a purchase, and a second AI agent acting as a "checker" would decide whether to approve it. The goal was to see how often the checker would fail to stop a bad proposal. The team tested different ways of setting up these two agents. In some cases, both agents used the same type of AI model. In others, they used different models. They also tested whether the checker was allowed to see the maker's reasoning or if it had to look at the raw facts directly, and whether the checker had to rely on the information the maker chose to highlight or if it could access the original, unfiltered data.

The results were stark. When the system was set up with the highest level of shared dependence—where both agents used the same AI model, the checker could see the maker's reasoning, and the checker only saw the information the maker had selected—the safety system failed more than sixty percent of the time. In these situations, the second agent simply agreed with the first agent's errors, allowing unsafe transactions to proceed. However, when the researchers changed the setup to reduce these shared dependencies, the results improved dramatically. By using a different AI model for the checker, hiding the maker's reasoning, and giving the checker direct access to the original source data, the failure rate dropped to just over thirteen percent. This means that simply having two different AI agents is not enough; the way they are connected and what information they see matters far more than their identities.

The study also looked at how often the system would get in the way of good work. A safety check that rejects every single proposal, even the safe ones, is useless because it stops business from happening. The researchers found that the improved setups did not cause this problem. The systems that caught more bad proposals did not reject significantly more good ones. This suggests that it is possible to build AI safety checks that are both strict and efficient, provided they are designed to avoid the specific traps that cause them to fail together.

One of the most significant findings was about how information flows between the two agents. The biggest improvement came when the checker was given direct access to the original evidence rather than relying on a summary provided by the maker. When the maker acted as a middleman for the data, the failure rate was much higher. This indicates that the first agent can unintentionally, or intentionally, filter out the very details needed to spot a mistake. By cutting out the middleman and letting the second agent see the raw facts, the system became much more reliable. Similarly, hiding the first agent's written explanation from the second agent helped reduce errors, suggesting that the second agent was sometimes being swayed by the first agent's confidence or logic rather than sticking to the facts.

The researchers also tested what happens when two different types of AI models are paired together. They found that using a different model for the checker significantly reduced the chance that both would fail on the same bad proposal. However, they were careful to note that this result was specific to the pair of models they used. It does not guarantee that any two different AI models will always work well together, but it does prove that mixing models is a powerful strategy for breaking the chain of shared errors. The study also highlighted a practical challenge: one of the different model combinations was more prone to technical glitches that made its answers unreadable. This reminded the researchers that safety is not just about intelligence, but also about reliability. If a safety check cannot produce a clear answer, it cannot do its job.

Ultimately, this work changes how we should think about safety in automated systems. It shows that the old rule of "two different people" does not automatically translate to "two different AI agents." If the two agents are too similar in how they think, what they see, or how they are built, they will likely fail together. True safety requires a deliberate design that forces the second agent to look at the problem from a different angle, using different tools and different information. The study concludes that organizations cannot simply assume their AI safety checks are working because they have two agents. They must measure the actual performance of those checks, ensuring that the second agent is truly independent and capable of catching the mistakes of the first. Only by treating safety as a measurable outcome rather than a structural label can we trust these powerful new tools with our most sensitive decisions.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →