Delegation creates chains of trust

When one system acts on behalf of another, which acts on behalf of a user, the question of whose authority is being used gets murky quickly.

Each link is reasonable. The chain as a whole often grants more than anybody intended, and when something goes wrong the logs record the last system in the sequence rather than the person who started it. The useful discipline is being able to answer, at the far end, whose authority this ultimately was.

More on Authorisation and privilege