Long‑running AI agents outlive their initiating processes via credentials, delegated tasks, queues, callbacks, reservations, and provider‑side operations. Cancellation, process exit, and credential revocation neither close every pre‑cut carrier nor distinguish independently authorized shared work. We define root‑scoped authorization quiescence: for each manifested sink, a certificate records every cut‑relevant acceptance that occurs before the retired root epoch and excludes protected acceptance after the local fence, while permitting an exact rebind to a current, independently sufficient support.
The root‑scoped quiescence protocol linearizes a root cut, fences old‑root expansion and protected sinks, represents alternative and conjunctive authority as antichains of minimal sufficient root sets, and composes provider‑frontier certificates into a cutset over registered old‑root paths. Exact channel‑token accounting reconciles transfers; missing or conflicting evidence remains indeterminate.
Under the stated assumptions we prove post‑cut issuer non‑expansion, support‑sound projection, compositional soundness under exact channel conservation, independent‑support preservation, merge‑order independence, and crash/replay stability. A provider‑free late‑effect test suite matches 17/17 registered outcomes. Two cancellation‑only and one cut‑only execution accept the same class of already scheduled late effect; two cut‑plus‑fence executions, one restart, and one stale‑process execution reject it. A separately implemented checker verifies 17/17 traces and consistently rejects 44/44 rehashed semantic regressions.
The certificate establishes root‑relative authorization quiescence within its bound manifest and configuration, not global idleness, rollback, or business completion.
Review