Leadership1 distinct publisher3 min readPublished
The token standards for delegated machine authority are older than the agent boom, yet nothing portable records how far a mandate extends once it crosses company lines, which leaves accountability for a committed purchase unsettled.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
Follow the chain that Aditya V Kashyap sets out and the problem stops being abstract: human to enterprise agent to specialist agent to external agent to tool, with the operative question being not who the agent is but on whose authority it acts and how far that authority extends [7]. His illustration is a traveler who lets an assistant spend $2,000 on a trip, and then the awkward follow-ons: can the hotel sub-agent spend the whole amount, can it delegate again, can the airline's agent reuse the credential, can the traveler revoke mid-task, and can each party verify the chain without learning more about the traveler than it needs [8]. Every one of those is a policy someone inside the firm has to write down before the transaction, not reconstruct after it.
The pieces to write it with already exist. Enterprises have run machine identity for decades on PKI, service accounts and policy engines, and OAuth 2.0 has handled delegated access since 2012 [5], roughly fourteen years before this argument was published [1]. RFC 8693 defines token exchange with delegation semantics, including a nestable claim that records who acts for whom [9]; RFC 9396 replaces flat scopes with structured authorization details [10]; RFC 9700 favors sender-constrained tokens, which blunt the value of a stolen token to an attacker without the matching key material [11]. From those you can express something as specific as "Agent B may invoke Tool C for Company A on this task, for 15 minutes, below $10,000, and may not delegate further" [12]. The shortfall lies in agreement on what those words mean once the mandate leaves your domain, a gap Kashyap treats as an open implementation problem rather than a cryptographic one, with the missing portable artifact standing as a proposal rather than a standard [12][13].
Scopes, expiry and revocation have existed for years, which might suggest this is a solved problem in new clothes. What sets agents apart, per the source, is the combination: autonomy, delegation, dynamic tool use, persistent state and interaction with other autonomous actors, which together give an agent substantially more runtime discretion over which tools to call, whom to contact, what to disclose and what to delegate than a conventional service moving through a predetermined workflow [6].
Zero trust gets the posture right without supplying the artifact. NIST SP 800-207 rejects network location as a basis for trust and makes access a dynamic, per-session, per-resource decision [17], and Kashyap extends that to agents: do not trust one because it sits inside the enterprise, was spawned by a trusted application or holds a valid credential, but verify the authority for this action and expect it to be task-specific, time-bounded, observable and revocable [18].
How big the gap actually is remains outside the record. This is one practitioner's argument, and it contains no measurement of how many enterprises running agents have built delegation limits, provenance or revocation [2]. So the honest statement is that the shape of what's missing is visible, while the actual distribution stays unknown. The decision in front of an operator this quarter is the scope of autonomous spend inside a boundary the firm controls. The consequence next quarter is whether the logs can answer, on demand, whose authority a purchase was made under.
Ranked by verification strength, evidence, and original report placement.
The argument was written by Dr. Aditya V Kashyap, described as an AI and Innovation Leader working on enterprise transformation through strategy, governance and leadership, and published on Forbes' Tech Council channel.
The Forbes Tech Council piece carries a September 1, 2026 date.
Kashyap's worked example: a manufacturer's procurement agent discovers a supplier's agent, requests inventory and pricing, negotiates within preset parameters, then calls an internal purchasing system to place the order; every message can be encrypted, signed and logged, and the hard part is what each side must decide before the order clears.
The questions each side must settle before the order clears, per Kashyap: Who are you? Who sent you? What are you authorized to do, and how do I know that is real? Can you pass it on? What limits apply? Can it be withdrawn? Who is accountable?
Kashyap separates the functions: identity establishes the entity that is acting, authentication proves it, authorization determines what it may do, delegation determines what authority can be passed on, and provenance records where instructions, credentials or actions came from.
Trust, in Kashyap's framing, is the judgment that the evidence is sufficient for a consequential action; authentication answers 'Who are you?' while agents force the harder question 'Why should I accept that you are authorized to do this?'
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Agent protocols now share one landlord: A2A joins MCP and AGENTS.md at the Linux Foundation1 distinct publisher
build
Basic Auth becomes a gateway problem: AgentCore's Lambda interceptor keeps the password away from the model1 distinct publisher
product
Kubernetes Secrets are a distribution problem, and the database is where it shows1 distinct publisher
build
Six specifications decide whether an agent can move off the harness it was built on1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Firm citations, unaudited conclusion
Two different qualities of evidence sit in one piece. The descriptive half is precise and independently checkable — specific RFC numbers with the right semantics attached, NIST SP 800-207's per-session posture, Agent2Agent's governance and Agent Card schemes — and it would survive a fact-check line by line. The conclusion drawn from it, that nothing portable records how far a mandate extends across company lines, is a survey result with no survey shown: no working group, vendor attempt or failed pilot is named, so the reader has the author's reading of the standards landscape and nothing to weigh it against.
No deployments in evidence
We can measure nothing here. The proposed authority record has no implementations to count, and the piece offers no figure for how many enterprises running agents enforce delegation limits, provenance or mid-task revocation today. Adoption of the underlying OAuth specifications is real in the wider world, but this story supplies no usage disclosure, benchmark or deployment we could point to, so we decline to score it.
Premise assumed, remedy hedged
The remedy is unusually modest for this genre: the author twice flags his own constructs as proposals, says form matters less than principle, and volunteers that better provenance is not legal non-repudiation. The overreach is upstream of that, in the premise. Agents negotiating and committing purchase orders across company lines is treated as the settled near future — the thing standards must now catch up to — without a single instance of it happening at scale. Modest tilt toward overstatement, and it comes from the setup rather than the pitch.
Byline channel, author's own coinage
This is thought-leadership positioning, not a product pitch, and the distinction cuts both ways. Kashyap sells no tool and names no employer's software; the standards he credits are other people's. But the two terms the piece asks you to adopt — authority provenance and the authority envelope — are his own coinages, published on a channel where the currency is being the person who framed the problem first, under a byline advertising enterprise governance leadership. Read the specification citations as neutral and the vocabulary as promotional.
One voice, no second read
Our confidence is capped by arithmetic: one publisher, one author, zero independent checks. Where the piece quotes documents we can be fairly sure of it. Where it characterizes the state of the industry — what is broadly adopted, what remains unsolved in practice — we are trusting one person's vantage, and the absence claim at the center is the kind that only gets sturdier or collapses when a second source is asked.