Definition
Splitting authority across roles so no one component can do everything alone.
In evidence-carrying agent design, the architectural principle that the model proposing actions cannot also certify the facts authorizing them; evidence must come from independent verifiers.