OSuite OSuite.ai
Sign in Request access
SeriesCompany Notes FrameworkCAVA, PCAA TypeResearch milestone
At a glance
CAVA is cited in both selected papers; PCAA is cited in the approval-laundering paper.
The papers investigate interpreter changes and transitive effects, two distinct challenges at the approval-to-execution boundary.
These are independent research citations, not institutional endorsements or evaluations of OSuite.

Two independent research teams have cited CAVA and PCAA in new papers on agent security. For a small team building in public, seeing other researchers engage with the work is a milestone worth pausing for.

We started with a practical question: when someone approves an agent action, what exactly have they approved? A tool name is often too broad. A command string may omit context. A log produced afterward cannot, by itself, establish that the action stayed within its authority.

PCAA develops proof-carrying action governance. CAVA addresses canonical action identity across heterogeneous runtimes. They are part of the research behind OSuite. It is encouraging to see these questions being examined independently, with other researchers bringing their own mechanisms and tests.

When the same tool call changes meaning

In When Valid Tool Calls Change Meaning: Formation-Consistent Dispatch for LLM Agents, Geonwoo Kim and Brent ByungHoon Kang of KAIST investigate a subtle failure: a tool call can remain valid while the implementation that gives it meaning changes.

Their Formation-Consistent Dispatch approach retains the interpreters authorized to give that action meaning. Section VIII-B places CAVA among related work on isolation, provenance and runtime action binding:

Isolation and provenance systems mediate components or bind runtime actions [56, 57, 58, 59, 60, 61]. FCD retains the interpreters authorized to give that action meaning.

CAVA is reference [60] in that group. The distinction matters: preserving an action's identity and preserving the interpreter that gives it meaning are related, but not interchangeable, problems.

When approval stops at the entry point

Agent Approval Laundering: Transitive Effects Beyond the Approved Invocation comes from authors affiliated with the Chinese Academy of Sciences, the University of Chinese Academy of Sciences, Beihang University and Beijing University of Posts and Telecommunications.

The paper examines what an approved invocation activates downstream. Approving a package-manager command, for example, is not necessarily the same as approving every script or side effect it triggers. In Related Work, the authors write:

Proof-Carrying Agent Actions and CAVA bind action identity, receipts, canonicalization, and attestation [16, 17]

They then distinguish that work from their closure-bound approval approach, which measures coverage between the decision-time approval object and the invocation's execution closure. That is a useful distinction for anyone building controls around real developer tools.

What we are celebrating

CAVA appears in both papers; PCAA appears in the approval-laundering paper. Both sources are arXiv preprints, and the links above preserve the v1 manuscripts we checked. Their citations are not evidence that either team has deployed or evaluated OSuite, nor do they imply a partnership or institutional endorsement.

What they do show is that our published work is becoming part of an independent technical discussion. For us, that is the point of publishing: make an idea precise enough that someone else can locate it, distinguish it from their own contribution, and take the problem further.

Thank you to the authors for engaging with the work. We will keep publishing the mechanisms, the evidence and the limits. The next milestone is not a bigger claim. It is a better answer to what happens between approval and execution.

[Explore the citation record and our research library](/research#citations).

Continue Company Notes
Company Notes

OSuite opens its field program for AI action governance.

June 24, 2026
Strategy Notes

AI sovereignty is incomplete without action sovereignty.

July 13, 2026

Approve high-risk AI work before it runs.

Request enterprise access and send your first governed decision today.

Request enterprise access Read the docs