Delegated Authorization in Autonomous Systems - Akash Narayan
Authors/Creators
Description
A grant of authority carries an implicit model of the party receiving it. The consent screen that underpins OAuth assumes
software whose behaviour was fixed when it was compiled, which is why the framework tolerates broad permissions held
indefinitely. Agentic software breaks that assumption at every point: its behaviour is decided at run time by a prompt and
a retrieved document, it acts at a rate set by inference cost rather than by human attention, and it now moves money. The
standards response since 2025 has been substantial but aimed slightly to the side of the problem, concentrating on
establishing who an agent is rather than on what a grant to an agent should permit. This paper argues that the missing
piece is not a new protocol but a profile, and that most of the required machinery is already standardised: structured
authorisation data in RFC 9396, actor chains in RFC 8693, audience restriction in RFC 8707, proof of possession in
RFC 9449. What no existing credential does is bind four constraints at once, namely what an agent may do, until when,
up to what cumulative value, and through which chain of intermediaries. The paper specifies such a credential as a
delegation envelope, argues that the spending counter cannot live inside the token or the agent and must be held by a
separate accounting authority, and treats revocation latency rather than token theft as the binding constraint on the design.
It closes by locating the boundary between limits a machine can check and decisions that must still be put to a person.
Files
Delegated Authorization in Autonomous Systems - Akash Narayan.pdf
Files
(543.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:2e7fe10870c0511865a74d20ab3fb11b
|
543.4 kB | Preview Download |