# How AIOX Agent Authority Works: Exclusive Powers and Enforcement Explained

> Discover how the AIOX Agent Authority principle grants exclusive powers to autonomous agents. Learn about enforcement and unauthorized action blocking in SynkraAI aiox-core.

- Repository: [SynkraAI/aiox-core](https://github.com/synkraai/aiox-core)
- Tags: deep-dive
- Published: 2026-03-15

---

**The AIOX Agent Authority principle is a constitutional, non-negotiable rule that assigns exclusive operational powers to specific autonomous agents, with a gate layer blocking any unauthorized action before it reaches execution.**

The **AIOX Agent Authority** system forms the governance backbone of the SynkraAI/aiox-core framework, ensuring deterministic and conflict-free workflows by strictly partitioning responsibilities. By mandating that each agent operate only within its legally defined jurisdiction, the framework prevents operational collisions—such as multiple agents attempting simultaneous Git pushes—while maintaining fully auditable automation pipelines.

## What Is AIOX Agent Authority?

**Agent Authority** is a foundational constitutional principle defined in [`.aiox-core/constitution.md`](https://github.com/SynkraAI/aiox-core/blob/main/.aiox-core/constitution.md). It guarantees that every autonomous agent possesses a clearly delineated sphere of influence that no other agent may infringe upon.

The primary **purpose** is to prevent conflicting actions, such as two agents attempting to push the same Git commit or modify critical infrastructure simultaneously. By making responsibilities explicit, the system ensures workflows remain auditable, safe, and deterministic.

**Enforcement** occurs through the framework’s gate layer, which interprets the constitution in real-time. Any attempt to perform an operation outside an agent’s exclusive authority is blocked before the task reaches execution, effectively acting as a constitutional firewall against workflow corruption.

## How the Authority Matrix Operates

The authority mechanism functions through three distinct governance stages documented in [`.claude/rules/agent-authority.md`](https://github.com/SynkraAI/aiox-core/blob/main/.claude/rules/agent-authority.md):

### Declaration

Each agent’s exclusive rights are formally declared in the constitution’s concise authority table and expanded upon in the detailed rules file. These declarations serve as the single source of truth for what operations an agent may perform directly versus what requires delegation.

### Delegation

When an agent encounters a task outside its jurisdiction, it must **delegate** that operation to the agent holding the relevant authority. For example, the constitution explicitly documents delegation patterns such as `ANY agent → @devops *push`, indicating that regardless of which agent initiates the workflow, only `@devops` may execute the final push command.

### Escalation

When an agent cannot fulfill a task due to authority constraints or operational complexity, it escalates to `@aiox-master`. This supreme agent may temporarily override constitutional boundaries when necessary for framework health, acting as the final arbiter for exceptional circumstances.

## Exclusive Powers by Agent Role

The following matrix details the non-transferable operations that each agent alone may execute. Any attempt by another agent to perform these actions triggers an immediate gate violation.

| Agent | Exclusive Authority |
|-------|---------------------|
| **@devops** | `git push` / `git push --force`, `gh pr create` / `gh pr merge`, MCP (multi-cloud-platform) add/remove/configure, CI/CD pipeline management, release and tag creation |
| **@pm** | Epic orchestration commands (`*execute-epic`, `*create-epic`), `EPIC-{ID}-EXECUTION.yaml` management, requirements gathering, spec-pipeline writing |
| **@po** | Story-validation commands (`*validate-story-draft`), epic-context tracking, backlog prioritisation |
| **@sm** | Story-creation commands (`*draft`, `*create-story`), story-template selection |
| **@dev** | Local Git workflow (`git add`, `git commit`, `git status`, `git branch`, `git checkout`, local `git merge`, `git stash`, `git diff`, `git log`), story file updates (File List, checkboxes, AC) — **must** delegate push/PR actions to `@devops` |
| **@architect** | System-architecture decisions, technology selection, high-level data architecture — delegates detailed DDL to `@data-engineer` |
| **@data-engineer** | Detailed schema design, query optimisation, RLS policies, index strategy, migration planning — **does not** own system-wide architecture |
| **@aiox-master** | Can execute *any* task directly, enforce constitutional rules, and override boundaries when necessary for framework health |

According to the source code in [`AGENTS.md`](https://github.com/SynkraAI/aiox-core/blob/main/AGENTS.md), these boundaries are considered constitutional pillars, meaning they are immutable without explicit framework-level amendments.

## Real-World Workflow Example

Consider a standard story-to-release pipeline where authority boundaries dictate the execution flow:

```text
@sm *draft → @po *validate → @dev *develop → @qa *qa-gate → @devops *push

```

1. **`@sm`** creates the story using `*draft` or `*create-story`—operations exclusively reserved for the Story Master role.
2. **`@po`** validates the story draft using `*validate-story-draft`, an authority exclusive to the Product Owner.
3. **`@dev`** performs local Git operations (`git add`, `git commit`, `git branch`) and updates story files, but **must delegate** the `*push` command to `@devops` since remote repository modifications fall outside `@dev` jurisdiction.
4. **`@qa`** executes the quality gate check using its exclusive testing authority.
5. **`@devops`** performs the final `git push`, creates the release tag, and manages CI/CD deployment—operations no other agent may execute.

If any agent attempts to skip the delegation chain—for instance, if `@dev` tries to run `git push` directly—the gate system aborts the pipeline and reports an **Agent Authority** violation before the command reaches the repository.

## Constitutional Source Files

The AIOX Agent Authority system is codified across three critical documents within the SynkraAI/aiox-core repository:

- **[`.aiox-core/constitution.md`](https://github.com/SynkraAI/aiox-core/blob/main/.aiox-core/constitution.md)** — Defines the high-level, non-negotiable *Agent Authority* principle and the concise exclusivity table that establishes the constitutional framework.
- **[`.claude/rules/agent-authority.md`](https://github.com/SynkraAI/aiox-core/blob/main/.claude/rules/agent-authority.md)** — Contains the detailed delegation matrix, per-agent operation lists, cross-agent workflow flows, and escalation rules that operationalize the constitution.
- **[`AGENTS.md`](https://github.com/SynkraAI/aiox-core/blob/main/AGENTS.md)** — Lists *Agent Authority* as a core constitutional pillar and ties the principle to the gate enforcement mechanism that protects workflow integrity.

Together, these files form the immutable source of truth that guarantees each agent acts strictly within its legally-defined jurisdiction.

## Summary

- **AIOX Agent Authority** is a constitutional, non-negotiable principle that partitions operational powers to prevent workflow conflicts.
- The **gate layer** enforces these boundaries by blocking unauthorized operations before execution, as defined in [`.aiox-core/constitution.md`](https://github.com/SynkraAI/aiox-core/blob/main/.aiox-core/constitution.md).
- **Eight specialized agents** hold exclusive powers ranging from Git operations (`@devops`) to story creation (`@sm`) and architectural decisions (`@architect`).
- **Delegation is mandatory** when an agent requires an operation outside its jurisdiction, with patterns like `ANY agent → @devops *push` formalized in [`.claude/rules/agent-authority.md`](https://github.com/SynkraAI/aiox-core/blob/main/.claude/rules/agent-authority.md).
- **`@aiox-master`** serves as the constitutional override mechanism, capable of executing any task when framework health requires boundary suspension.

## Frequently Asked Questions

### What happens if an agent violates the AIOX Agent Authority principle?

The framework’s gate layer intercepts the unauthorized operation before execution and aborts the pipeline, reporting an **Agent Authority** violation. For example, if `@dev` attempts `git push` instead of delegating to `@devops`, the system blocks the command and logs the constitutional breach.

### Can agents permanently transfer their exclusive powers to another agent?

No. Exclusive powers are constitutional and non-transferable. However, agents may **delegate** specific task instances to the appropriate authority holder (e.g., requesting `@devops` to execute `*push`). Only `@aiox-master` can temporarily override boundaries, and solely for framework health emergencies.

### How does @aiox-master differ from other agents in the authority hierarchy?

Unlike specialized agents with narrow jurisdictions, `@aiox-master` possesses universal authority to execute *any* task, enforce constitutional rules, and override boundaries when necessary. It serves as the ultimate escalation path when standard delegation chains cannot resolve operational deadlocks.

### Where are the specific delegation patterns documented?

Delegation matrices and cross-agent workflow rules are maintained in [`.claude/rules/agent-authority.md`](https://github.com/SynkraAI/aiox-core/blob/main/.claude/rules/agent-authority.md), which details allowed operations, blocked commands, and escalation procedures. The high-level principle appears in [`.aiox-core/constitution.md`](https://github.com/SynkraAI/aiox-core/blob/main/.aiox-core/constitution.md), while [`AGENTS.md`](https://github.com/SynkraAI/aiox-core/blob/main/AGENTS.md) provides the architectural context linking authority to workflow enforcement.