Delegation in the Age of Agentic AI
Authority, Access, On-Behalf-Of Execution, and Identity Impersonation
Abstract
Agentic AI exposes a gap between authenticating a principal, authorizing a resource operation, and authorizing the business decision that motivates that operation. This paper distinguishes four frequently conflated concepts: Delegation of Authority (the right to decide), Delegation of Access (the right to use resources), On Behalf Of execution (represented action with dual attribution), and Delegation of Identity (impersonation with substituted attribution).
Their separation becomes critical in agent-to-agent interactions, where runtime behavior can evolve independently of the permissions initially granted. The paper proposes a zero-trust agent framework combining explicit mandates, independently authenticated workloads, mediated capability acquisition, and verifiable execution records.
Its central thesis: safe agentic delegation requires an enforceable relationship among who authorized the task, who performed the action, which operations were permitted, and which business outcomes were authorized.
In this paper
- 01 Executive Overview
- 02 Conceptual Definitions
- 03 Unified Structural Comparison
- 04 The Agentic AI Paradigm Shift
- 05 Security Threat Modeling and Governance Architecture
- 06 Conclusion and Future Outlook
- 07 References
Read the full paper
Covering the formal comparison, threat model, zero-trust agent framework, and recommendations for enterprise architects.
Download PDFQuestions or feedback? Reach out to Jan Uyttenhove on LinkedIn or via jan@insidin.com.