agentic AI delegation identity governance zero trust IAM

Delegation in the Age of Agentic AI

15 Jul 2026 8 min

AI agents do not just answer questions. They retrieve data, call APIs, send messages, create records, and trigger workflows, often across multiple systems in a single task. Every one of those actions involves delegation: a human or system granting permission for something to act on its behalf.

Four concepts govern how that delegation works. They are frequently used interchangeably in enterprise conversations, but they answer fundamentally different questions and carry very different risks. Getting them wrong in an agentic AI context is not a theoretical problem. It is how technically valid operations produce unauthorized business outcomes.

Four concepts, four different questions

Delegation of Authority asks: Can they decide? It grants business decision power, and the audit trail is attributed to the delegate.

Delegation of Access asks: Can they touch it? It grants system or data permissions, and the audit trail is attributed to the delegate.

“On Behalf Of” asks: Whose name is it in? It grants scoped proxy capabilities, and the audit trail is dual, showing both parties.

Delegation of Identity asks: Who are they pretending to be? It grants complete substitution, and the audit trail is single, showing only the original.

How they work in practice

Consider an executive (CEO) and their executive assistant (EA). All four concepts can apply in a single working relationship.

Delegation of Authority. The CEO gives the EA the power to sign off on travel expenses up to 1,000 EUR. The EA now has decision rights within that boundary. Any approval is attributed to the EA, acting under the CEO’s mandate.

Delegation of Access. IT grants the EA access to the CEO’s Outlook Calendar to schedule meetings. The EA can see and modify calendar entries, but this does not grant decision-making power over what gets scheduled.

“On Behalf Of.” The EA sends an email from the calendar system. The email header reads: “EA on behalf of CEO.” Recipients and audit logs know exactly who typed it and who it was for. Both identities are visible.

Delegation of Identity. The EA logs into a legacy HR system using a master session token generated by the CEO’s login. The system logs show the action was performed by the CEO. The HR system has no record the EA was ever there.

That last case is the dangerous one, and it is the one that scales most easily with AI agents.

The critical distinction: identity delegation versus “on behalf of”

These two are the most commonly conflated, and the distinction matters most in agentic architectures.

Identity delegation means total impersonation. The original user’s credentials or security context are packaged and passed entirely down the line. Classic examples include Linux sudo (where you literally become the root user) or Kerberos Unconstrained Delegation (where a web server takes a user’s ticket and masquerades as them to a database). The receiving system has no idea the intermediary was involved. If the intermediary is compromised, an attacker can completely hijack any user’s identity.

“On Behalf Of” means attributed proxy. Identity is propagated, but bounded and explicitly logged. Modern OAuth 2.0 Token Exchange and Microsoft Entra ID OBO Flows work this way. The middle-tier service exchanges the user’s token for a new one specifically restricted to what that service needs. The downstream system sees both identities. It enforces the principle of least privilege because the intermediary cannot use the user’s identity to access unrelated systems.

Why this matters for AI agents

When AI agents chain actions across systems (Human to Orchestrator to Analyst Agent to Database Agent to Database API), every hop involves delegation. If those hops use identity delegation rather than attributed proxy patterns, the database sees a human user where there is actually a chain of autonomous software components.

If any component in that chain is compromised or manipulated (through prompt injection, tool misuse, or adversarial content), the attacker inherits everything that human identity can do, and nobody can trace what actually happened.

This is not a speculative risk. A technically valid access token can accompany an action that exceeds the delegator’s business mandate. The workload is genuine, the token signature is valid, the scope permits sending a message, the recipient parameter is syntactically valid. The breach occurs because attacker-controlled content changed the action’s purpose or destination.

The governance response

Safe agentic delegation requires an enforceable relationship among four things: who authorized the task, who performed the action, which operations were permitted, and which business outcomes were authorized. Identity and access management remains necessary, but identity verification and permission checking alone cannot establish that an agent’s action is appropriate to its assigned purpose.

The paper proposes a zero-trust agent framework built on nine principles: independent workload identity, explicit authority mandates, mediated capability acquisition, holder-bound credentials, concrete action validation, transaction-bound approval, constrained re-delegation, protected audit evidence, and operational revocation.

The most actionable recommendations for enterprise architects:

Separate authority from entitlements. Establish versioned mandates for production agents with named business owners, explicit limits, and expiry. Verify that resource permissions cannot silently expand decision authority.

Give each agent an accountable identity. Preserve represented-user context where required, record the actual actor, and contain legacy human impersonation in a narrow brokered adapter. Remove shared human credentials from agent runtimes.

Move enforcement to the transaction boundary. Check exact parameters, business state, aggregate limits, and approval bindings at execution. A generic “read” scope does not define which records may be returned.

Make evidence and revocation acceptance criteria. Require resource-confirmed actor attribution, a reconstructable execution graph, and measured revocation latency before expanding autonomy.

The full paper covers the formal risk taxonomy, a comprehensive comparison matrix across all four delegation types, threat vectors mapped to delegation failures, and the complete zero-trust agent framework with protocol-level references. Read more and download the paper.