17.0Temporal Windows

Authority that only exists when it should.

Grant authority that is valid only within a defined time window, so permissions exist when the work happens and disappear when it does not.

Time-boxed permissions

17.1

Bind an agent's authority to a schedule or window, so it cannot act outside the times you intend.

  • Authority valid only in-window
  • Blocked outside the window
  • No lingering standing access
Time-boxed permissions

Pairs with delegation

17.2

Delegated and session authority can expire with the task, the session or a fixed window, narrowing the blast radius over time.

  • Expire with task or session
  • Fixed windows for sensitive work
  • Least privilege that keeps up
Pairs with delegation

Enforced, not advisory

17.3

The window is checked at the intercept, so an out-of-window action is blocked, not merely flagged.

Enforced, not advisory

More in Tool & Runtime Security.

Related capabilities on the same authorisation layer. Every one is enforced before an action runs and sealed to the Provenance Vault.

1.0MCP & Tool Security

Decide which agent may call which tool.

Learn more
2.0AI Gateway

Authorise every model call.

Learn more
3.0Runtime Containment

Contain or kill any agent, instantly.

Learn more
4.0Breakglass

Emergency access without invisible exceptions.

Learn more

See Temporal Windows in your workflow.

Put one workflow behind Xybern and watch every agent action authorised, and sealed to the vault.