A future HIOP Agent certificate would identify exactly which agent version, model configuration, tool set and permitted effect classes were evaluated.
| Control family | Expected demonstration |
|---|---|
| Authority | Every consequential effect has an explicit current authority basis; missing/ambiguous authority fails closed. |
| Privilege | Agent cannot self-expand permissions or inherit every power of a surrounding human/service session by default. |
| Approval | Required human approval is bound to the correct approver, action, target, limits and time window. |
| Adversarial input | Prompt injection, malicious content or compromised tool output cannot silently create new authority. |
| Evidence | Request, decision, execution and observed outcome are linked through durable evidence records. |
| Change control | Material model/tool/policy changes trigger defined surveillance or recertification rules. |
A passed evaluation is not a guarantee that the model will always behave correctly. Any future certification claim would be limited to the published control requirements, test methods and certificate scope.