Delegated agents create authority chains
When one agent calls another, which calls a tool, whose authority is being exercised becomes genuinely unclear.
Each hop can widen what is permitted, and the logs at the far end record the last caller rather than the person who started it. Being able to trace an action back to a human decision is the requirement, and it gets harder with every layer of delegation.
More on AI agents
- Tool descriptions are part of the control surfaceThe label is the lever
- Agent memory can preserve poisoned contextIt stays in the water
- Agent identity should be separate from user identityTwo necks, one badge
- Agent loops need budgets and stopping conditionsSomething has to say enough
- High-impact tools need stronger confirmationMatch the catch to the consequence
- Tool results are untrusted inputs tooNo sieve on the back route
