
AUTHORITY & TRUST
IEEE Fellow (2023, “for contribution to access control and privacy”)
PhD, Purdue University
NSF CAREER Award, 2006
Distinguished Member, ACM
the partnership
Agent systems need more than permissions. They need authority that can be established, delegated, checked, and continuously re-evaluated as identities, contexts, and risks evolve.
James Joshi’s work on access control, trust management, and insider-threat resilience makes that authority layer operational — from the first credential to every consequential agent-to-agent handoff.
the research
Three authority-and-trust directions translate Dr. Joshi’s access-control and security research into accountable agent operations.
DIRECTION 01
Attribute-Based Identity & Access for Agent Fleets
Model identity and authorization as rich, contextual attributes that can express what an agent may do, for whom, and under which conditions.
Identity architecture · access control · policy context
DIRECTION 02
Secure Agent-to-Agent Delegation
Make delegation explicit, revocable, and auditable so authority cannot quietly expand as work moves between agents and organizations.
Delegation chains · signed authority · cross-domain trust
DIRECTION 03
Continuous Trust Evaluation Under Insider-Threat Conditions
Continuously assess evolving agent behavior and context so insider risk is detected before trust assumptions turn into exposure.
Trust evaluation · anomaly context · insider resilience
supporting research
Advanced Access Control & Trust Management
Develop access-control and trust-management models that keep authority precise across distributed, AI/ML, IoT, edge, and cloud environments.
Policy models · identity context · accountable access
Privacy-Preserving AI/ML & Insider-Threat Resilience
Protect sensitive decision systems while detecting and mitigating risks that emerge from trusted but compromised insiders.
Privacy-preserving AI · insider threat · continuous assurance