Glossary · term

Agent delegation chain

An agent delegation chain is an ordered record of authority passing from an originating principal through one or more AI agents, services or tools. Each hop identifies the actor and what it may do on whose behalf. A governed chain preserves provenance and applicable constraints so a downstream enforcement point can decide whether the current action remains within the authority granted upstream.

Safety2025-01-16Wave 3 · 2025–26Maturity: 3/5

Origin and context

OAuth already distinguished delegation from impersonation and allowed nested actor claims before modern AI agents. In 2025, agent-authorization research applied that foundation to task-scoped AI credentials and chains of accountability. By 2026, NIST was asking how to prove an agent's authority and bind actions back to human authorization, IMDA recommended scoped and recorded agent authority, IETF drafts proposed agent-specific chain mechanics, and AWS demonstrated multi-agent policy checks.

Sources: s1, s2, s3, s4, s5, s6

Why it matters

Without chain context, a sub-agent may receive a shared credential or be judged only by its own identity, losing the user's limits and the parent agent's mandate. That can create confused-deputy behavior, privilege expansion and weak incident reconstruction. Useful controls preserve the originator, bind tokens to the intended service, narrow scopes and argument constraints, limit re-delegation depth and lifetime, record parent links, and support revocation. Those controls must be enforced outside the model's prompt.

Sources: s3, s4, s5, s6

Example

A user authorizes an orchestrator to prepare a report from sales data. The orchestrator delegates retrieval to a specialist, which calls a database tool. The specialist's effective token can retain the user's identity, identify both agents, permit only read operations on the selected dataset, expire with the task and forbid further delegation. The database still evaluates the request against policy; carrying the chain is evidence for authorization, not authorization by itself.

Sources: s4, s5, s6

How it differs

Agent identity

Agent identity identifies and authenticates an acting agent. A delegation chain connects multiple identities to the originating principal and records how authority changes across hops; identity alone does not establish that history.

Agentic zero trust

Agentic zero trust is the wider access-control approach. A delegation chain can supply provenance, scope and task context to its policy decisions, but zero trust also includes inventory, enforcement, monitoring and credential lifecycle.

Agent2Agent Protocol

A2A standardizes parts of agent discovery and communication. A delegation chain concerns authorization provenance and effective authority; communicating with another agent does not automatically delegate credentials or permission.

Maturity and evidence

Maturity is rated 3. The underlying delegation and actor-chain mechanisms build on a standards-track OAuth RFC, while independent research, IMDA, NIST, multiple IETF drafts and AWS converge on preserving origin, constraining downstream authority and auditing each hop. Maturity 4 would imply too much stability: agent-specific proposals remain drafts, terminology and token formats differ, and cross-provider interoperability and effectiveness evidence are limited.

Sources: s1, s2, s3, s4, s5, s6

Limits and open questions

A valid chain can carry an overbroad original grant, encode the wrong policy, omit a relevant actor or be accepted by a weak verifier. Monotonic scope narrowing limits privilege growth but does not show that an action matches natural-language intent. Long chains also increase privacy exposure, latency, revocation complexity and failure modes across trust domains. Treat current IETF drafts and vendor examples as evolving designs, not certified controls or universally interoperable standards.

Sources: s3, s4, s5, s6

Related terms

References

Last updated: 2026-09-07