Every Step Passes Its Guardrail and the Workflow Still Violates Policy, and No Step-Scoped Monitor Can Catch It
arXiv 2609.18820 (16 Sep 2026) defines Compositional Policy Violations: the policies organizations actually enforce, such as referral thresholds, authority limits and review requirements, are properties of a whole execution, while the governance around agentic workflows is almost entirely step-scoped input-output classifiers, per-turn rails and span-level evaluators. Because a predicate over one step cannot evaluate a property that step does not determine, improving monitor accuracy cannot detect this class. The paper gives a four-type taxonomy (Authority Creep, Threshold Laundering, Cumulative Sum Violation, Context Collapse), argues the correct repair follows where the guarded quantity mutates, and proposes a provenance-aware runtime that recomputes guarded quantities from raw provenance over complete traces.
↳ Follow the thread