Machine action, accountable authority
Let software act without letting scope drift.
Bind an agent to the organisation that appointed it, the action it may perform, the resources it may touch, its limit, expiry and human-control conditions.
The authority gap
An authenticated agent or API key does not prove that the organisation authorised this specific act, at this value, on this resource, now.
EXAMPLE MANDATEPermitted
- Principal
- Northstar Components GmbH
- Representative
- Procurement Agent X
- Action
- Place purchase order
- Resource
- Procurement account 17
- Limit
- €25,000 per order
- Condition
- Human approval above €20,000
What changes
Move from implicit permission to explicit policy.
- Keep the appointment and policy outside the model prompt.
- Require human approval when a defined threshold is crossed.
- Revoke the agent’s authority without rotating every downstream identity.
Related authority patterns
The actor changes. The verification discipline remains.
Design-partner programme
Test a real ai agent authority workflow.
We will map the principal, representative, action, resource, policy and relying-party decision with your legal, security and operational stakeholders.