What Is Capability-Based Security?

Capability-based security grants authority as unforgeable tokens that both name a resource and confer the right to use it — holding the capability is the permission. There is no separate check of "is this actor allowed?"; possession is the authorisation, and authority is shared by passing the capability along, optionally attenuated. It is a natural model for agents, where a scoped, delegatable token expresses exactly what an agent may do and nothing more.

Authority is
An unforgeable token you hold
No
Ambient permission to be checked
Agent fit
Scoped, delegatable, attenuable rights

Holding is permission

Most systems use access-control lists: the actor presents an identity and the system looks up whether that identity may act. Capabilities invert it — the right travels with the token, so there is no ambient authority to be confused or escalated, and delegation is just handing over (a weakened copy of) the capability.

This maps cleanly onto delegated agent authority: a principal issues an agent a capability scoped to a task, the agent may pass on a narrower one, and nothing it holds grants more than was granted — the attenuation rule the estate’s grant model already enforces.

Related standards

Miller, 2006 — Robust Composition (object-capability model)

Questions

How is this different from an access-control list?

An ACL checks who you are against a list; a capability is the authority itself, held and passed directly, with no ambient lookup.

Why does it suit agents?

Scoped, delegatable, attenuable tokens express least privilege naturally — an agent holds exactly the authority its task needs.

Keep reading

related
What Is the Principle of Least Privilege?
related
Delegated Authority for AI Agents
related
What Are AI Guardrails?
related
How Delegation Chains Work for Agents
referenced by
Authentication vs Authorization: What’s the Difference?
Governance & Accountability
AI Agent Governance and Accountability
Governance & Accountability
The Consent Layer of the Agentic Internet
Governance & Accountability
What Is an Agent Policy Engine (and Why Deny-by-Default)?
Governance & Accountability
Human-in-the-Loop vs On-the-Loop vs Autonomous Agents
Governance & Accountability
When Should an AI Agent Escalate to a Human?
Governance & Accountability
How Do You Audit an Autonomous AI Agent?
Governance & Accountability
Kill Switches and Dead-Man’s Switches for Autonomous Organizations
Governance & Accountability
Agent Compliance and Regulation
Governance & Accountability
Managing the Risk of Autonomous Agents
Governance & Accountability
What Is Prompt Injection?
Governance & Accountability
What Is Model Evaluation (Benchmarks and Evals)?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.