Interesting discussion from
@SherifDefi 🤔'The agent permission never stopped.'
A time box buys you a human review, and it makes the permission fail closed when no review happens. The first is a nice-to-have. The second is the safety property.
@szrxbt went at this in our ideathon with acta on
[ ARKIV ] a monthly grant with a risk limit, specific tasks authorised inside it, and the grant lapsing on its own instead of waiting to be revoked.
nitter.net/SherifDefi/status/2099…
A Huge percentage of agent wallet setups focus on how much an agent can spend.
Fewer focus on how long that permission actually lasts.
A session key that never expires is a standing risk even if the spending cap looks tight, because tight today doesn't mean tight in six months if nobody remembers to revoke it.
Time-boxed permissions solve a different problem than spending caps do, they force a human back into the loop on a schedule.
Caught one recently that had been live for four months with nobody actively managing it.
Spending cap was reasonable… the fact that it could still fire at all was the actual issue.