Authority through steps
A delegation chain records how authority moves from an originating human or service through an agent, intermediary service, tool server, and target resource. Each step must preserve the subject whose interests are represented, the current actor, the target audience, the permitted resource and action, the purpose or task context, the lifetime, and any approval condition.
Delegation differs from impersonation. Delegation keeps the actor visible while the action is performed for a subject. Impersonation makes the actor act as the subject under an explicit policy. Erasing this distinction creates weak audit and confused-deputy risk.
Attenuate each hop
Validate the incoming identity and authority before a hop issues or selects the next credential. Bind the result to the next target. Reduce scope, resource set, action set, and lifetime. Never add authority because an intermediary has a more privileged service credential.
Keep a chain identifier and actor information in protected request context or evidence. Do not forward the original bearer token to every downstream service. Use token exchange, a brokered credential, or another explicit mechanism when the next audience needs a different credential.
Failure and residual risk
A chain fails when a service drops the human actor, reuses one broad token, changes audience without exchange, turns user consent into administrator authority, or allows an agent to delegate beyond its own grant. Long chains can outlive source revocation. Logs can show the last service but not who caused the action.
Even a correct chain does not prove that the action matched the human's actual intent. Untrusted content can influence the agent after delegation. Use action-level policy and approval at the point where concrete effects are known.
Pomerium boundary
Pomerium can authenticate callers, protect MCP and application routes, and preserve documented request identity. Operators and tool applications own the end-to-end delegation model, downstream credential exchange, action permission, and actor evidence. Do not claim that one Pomerium session automatically authorizes every downstream tool.
Evaluation checklist
- Are originating subject and current actor distinct at every hop?
- Does each credential name or bind its intended audience and resource?
- Can no hop create more authority or lifetime than it received?
- Can one action be traced through the full chain without storing bearer credentials?
- Does source revocation stop future delegated actions within a measured bound?
