Autonomous AI agents increasingly act on behalf of users and of one another, passing tasks, documents, tool access, and authority across chains of delegation. Existing delegation-token systems express and verify attenuated authority, but they assume the delegation evidence and the task content are visible to the infrastructure that carries them. This document specifies a capability grant format, delegation-chain construction and verification rules, a caveat processing model, and a hash-linked audit record format designed to bind authority to end-to-end encrypted task capsules, so that authority can be verified and delegation lineage can be checked relative to an authenticated chain head without exposing task or context plaintext to brokers, queues, gateways, or orchestration services. It further specifies scoped context disclosure: a model in which a delegatee receives cryptographic access to only the subset of task context that its capability names. This mechanism complements, and is intended to be reconcilable with, the delegation chains defined in draft-asor-wimse-agent-delegation-chain.
评论