What Is Capability-Based Security?
Capability-based security grants authority as unforgeable tokens that both name a resource and confer the right to use it — holding the capability is the permission. There is no separate check of "is this actor allowed?"; possession is the authorisation, and authority is shared by passing the capability along, optionally attenuated. It is a natural model for agents, where a scoped, delegatable token expresses exactly what an agent may do and nothing more.
Holding is permission
Most systems use access-control lists: the actor presents an identity and the system looks up whether that identity may act. Capabilities invert it — the right travels with the token, so there is no ambient authority to be confused or escalated, and delegation is just handing over (a weakened copy of) the capability.
This maps cleanly onto delegated agent authority: a principal issues an agent a capability scoped to a task, the agent may pass on a narrower one, and nothing it holds grants more than was granted — the attenuation rule the estate’s grant model already enforces.
Related standards
Questions
How is this different from an access-control list?
An ACL checks who you are against a list; a capability is the authority itself, held and passed directly, with no ambient lookup.
Why does it suit agents?
Scoped, delegatable, attenuable tokens express least privilege naturally — an agent holds exactly the authority its task needs.
Keep reading
By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.