Delegated Authority for AI Agents

Delegated authority is how a human or organisation grants an AI agent permission to act — for a bounded set of powers, for a limited time, and revocably. The governing rule is attenuation: a grant may only ever carry a subset of the granter’s own authority, never more. Verifying an agent means verifying the whole delegation chain back to an accountable human, not just checking a signature at its end.

Rule
Attenuation — a subset, never inheritance
Bounded by
Scope, expiry, revocation
Verify
The chain, not just the signature
Principle
Least privilege

Why attenuation is the whole rule

If a child grant could hold authority its parent lacks, delegation would be an escalation of privilege rather than a controlled hand-off. So the invariant is absolute: every grant is a subset of the granter’s powers. A change that would break it is wrong, whatever its convenience.

Authorization is not authentication. Knowing an agent is who it claims to be does not tell you what it may do. Delegation answers the second question, and enforcement comes before minting — a system that can issue authority ahead of the thing that checks it is issuing theatre.

Questions

How do you revoke an agent’s authority?

A grant carries expiry and can be revoked; verification checks the chain at use time, so a revoked or expired link fails the whole chain.

What is least privilege for agents?

Granting an agent only the narrowest authority its task requires, for the shortest time, so a compromised or mistaken agent can do the least possible harm.

Where this lives in the estate

flashyID — the grant kernel: issue, attenuate, verify

Keep reading

related
What Is AI Agent Identity?
related
AI Agent Governance and Accountability
related
What Is an Autonomous Agent Organization (AAO)?
related
How Do Autonomous Agents Pay?
referenced by
AAO vs DAO: What Is the Difference?
referenced by
What Is an AI Agent Wallet?
referenced by
How Should AI Agents Authenticate?
referenced by
Zero-Trust Architecture for AI Agents
referenced by
How Do You Audit an Autonomous AI Agent?
referenced by
Decentralized Identifiers (DIDs) for AI Agents
referenced by
OAuth for AI Agents
referenced by
How Do AI Agents Negotiate Terms and Price?
referenced by
Who Is Liable for an Autonomous Agent Organization?
referenced by
Kill Switches and Dead-Man’s Switches for Autonomous Organizations
referenced by
What Is Agent Orchestration?
referenced by
Verifiable Credentials for AI Agents
referenced by
How Delegation Chains Work for Agents
Identity & Authority
Key Management for AI Agents

By Michael Gord · published 2026-09-26 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.