Proposes a delegation envelope for enhanced authorization in autonomous systems, suggesting implications for agent behavior and permission management.
A grant of authority carries an implicit model of the party receiving it. The consent screen that underpins OAuth assumessoftware whose behaviour was fixed when it was compiled, which is why the framework tolerates broad permissions heldindefinitely. Agentic software breaks that assumption at every point: its behaviour is decided at run time by a prompt anda retrieved document, it acts at a rate set by inference cost rather than by human attention, and it now moves money. Thestandards response since 2025 has been substantial but aimed slightly to the side of the problem, concentrating onestablishing who an agent is rather than on what a grant to an agent should permit. This paper argues that the missingpiece is not a new protocol but a profile, and that most of the required machinery is already standardised: structuredauthorisation data in RFC 9396, actor chains in RFC 8693, audience restriction in RFC 8707, proof of possession inRFC 9449. What no existing credential does is bind four constraints at once, namely what an agent may do, until when,up to what cumulative value, and through which chain of intermediaries. The paper specifies such a credential as adelegation envelope, argues that the spending counter cannot live inside the token or the agent and must be held by aseparate accounting authority, and treats revocation latency rather than token theft as the binding constraint on the design.It closes by locating the boundary between limits a machine can check and decisions that must still be put to a person.
No takes yet. Share an insight, caveat, or question.
Akash Narayan (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: