Papers / Delegation in the Age of Agentic AI

Delegation in the Age of Agentic AI

Authority, Access, On-Behalf-Of Execution, and Identity Impersonation

Jan Uyttenhove | July 2026 | Version 2.0

Download the full paper

PDF, 20+ pages

Download PDF

Abstract

Agentic AI exposes a gap between authenticating a principal, authorizing a resource operation, and authorizing the business decision that motivates that operation. This paper distinguishes four frequently conflated concepts: Delegation of Authority (the right to decide), Delegation of Access (the right to use resources), On Behalf Of execution (represented action with dual attribution), and Delegation of Identity (impersonation with substituted attribution).

Their separation becomes critical in agent-to-agent interactions, where runtime behavior can evolve independently of the permissions initially granted. The paper proposes a zero-trust agent framework combining explicit mandates, independently authenticated workloads, mediated capability acquisition, and verifiable execution records.

Its central thesis: safe agentic delegation requires an enforceable relationship among who authorized the task, who performed the action, which operations were permitted, and which business outcomes were authorized.

In this paper

  1. 01 Executive Overview
  2. 02 Conceptual Definitions
  3. 03 Unified Structural Comparison
  4. 04 The Agentic AI Paradigm Shift
  5. 05 Security Threat Modeling and Governance Architecture
  6. 06 Conclusion and Future Outlook
  7. 07 References
agentic AIdelegationidentityzero trustIAMgovernance

Read the full paper

Covering the formal comparison, threat model, zero-trust agent framework, and recommendations for enterprise architects.

Download PDF

Questions or feedback? Reach out to Jan Uyttenhove on LinkedIn or via jan@insidin.com.