A wallet or smart-account workflow that gives software an explicitly bounded ability to prepare or execute actions. It is an implementation pattern, not an ERC-4337 feature, safety guarantee, or reason to grant a model unrestricted signing authority.
Supports: ERC-4337 describes UserOperations, an EntryPoint, bundlers, and smart accounts with custom validation logic. It does not prescribe a universal authorization policy for an agent.
Supports: Prompt injection and excessive agency are recognized risks, supporting constrained, reviewable authority for consequential wallet actions.
ERC-4337 lets a smart account define validation logic; it does not define a universal policy for agent permissions.
Authority should specify the chain, implementation, permitted calls, value limits, expiry, review state, and recovery path.
MPC, multisig, session keys, and simulations are implementation-specific controls, not blanket safety guarantees.
Start read-only, then drafts, then narrowly scoped and independently reviewed authority if it is genuinely needed.
A workflow can prepare a USDC deposit draft on one named chain. A separately reviewed account policy accepts only that contract and function for seven days, below a defined value limit. The user approves each transaction, and the policy can be paused or revoked without giving the workflow access to recovery material.
An informal way to describe how much an AI system can observe, plan, call tools, and act. It is not a standardized maturity score, a measure of trustworthiness, or permission to give an agent broad authority.
A cryptographic design in which parties jointly perform a signing or other key operation without exposing their private inputs to one another. The security outcome depends on the threshold, implementation, device isolation, policy, recovery, and operators.
A controlled component that prepares, validates, signs, submits, and monitors a state-changing operation. In an agent workflow, it must treat model output as an untrusted proposal, not as authority to move funds or call a contract.
A hardware-backed isolated execution environment that can protect specified code and data under an explicit platform threat model. Its assurance depends on the implementation, attestation policy, measured software, key release, configuration, and remaining hardware and software attack surface.
Explore all our strategic guides about AI to take your operations to the next level.
View all articles