top of page

When Agents Delegate to Agents: Chained Authority in the Agentic Economy

Writer: Zayon
Zayon
Sep 12
5 min read

Updated: 1 day ago

Tela preta com logo Zayon e texto Trustworthy AI Decision Infrastructure; círculos em radar vermelho e cinza.

The first wave of thinking about AI agents assumed a simple structure: a human delegates a task to an agent, and the agent acts. One principal, one agent, one line of authority.

That structure is already outdated.


In practice, agents increasingly act through other agents. A company's finance agent hands supplier payments to a specialized payments agent. A personal assistant agent asks a banking agent to move money, which asks a foreign exchange agent to convert it. A procurement agent negotiates with a supplier's sales agent, which commits on behalf of its own company.


Each of these handoffs is a delegation of authority. Together, they form a chain. And chains create a problem that single delegations don't: by the time an action reaches the system that executes it, who actually authorized it, and within what limits?


The problem with chains

Chained delegation introduces four risks that don't exist when one human delegates to one agent.

  • Authority inflation. An agent with limited authority delegates a task to another agent, but without passing its limits along. The second agent ends up acting with broader authority than anyone intended. Each link may look reasonable. The chain, as a whole, is not.

  • Lost provenance. When the executing system sees only the last agent in the chain, it can't tell whether that agent's authority traces back to a legitimate human principal, or to an agent that was never authorized to delegate.

  • Revocation that doesn't propagate. A human revokes the first agent's mandate. The downstream agents, holding delegated authority, keep acting, because nothing told them the root of their authority is gone.

  • Diffused accountability. When something goes wrong, every party in the chain can point to the next one. Without a record of the chain, there is no way to determine where authority was exceeded.


These risks compound as chains get longer and as agents from different organizations interact.


Principles for chained authority

A sound model of chained delegation rests on five principles.

1. Every chain has a human or institutional root

Every chain of agent authority must trace back to an accountable human or institution that granted the original mandate. An agent can't create authority. It can only pass on authority it received.


2. Authority can only narrow

When an agent delegates to another agent, the delegated authority must be equal to or narrower than its own, never broader. If the first agent may pay up to R$50,000 a day to registered suppliers, it can delegate R$20,000 a day to registered suppliers in one category. It can't delegate R$80,000, or payments to unregistered suppliers.


This is the single most important rule. Formally, each mandate in the chain must be a subset of the mandate above it, across every dimension: scope, amounts, counterparties, time window and conditions.


3. Delegation itself is a decision

The right to delegate is not automatic. A mandate must state explicitly whether the agent may delegate, to which types of agents, and how many levels deep. Each act of delegation is evaluated and recorded like any other decision, with its own ID, linked to the mandate it derives from.


4. Every action carries its full chain

When an action reaches the point of execution, it carries the complete chain of mandates behind it, from the executing agent back to the root. The decision layer evaluates the action against every mandate in the chain, not just the last one. If any link is invalid, expired, revoked or exceeded, the action doesn't proceed.


5. Revocation cascades

Revoking a mandate invalidates every mandate derived from it, immediately. Downstream agents don't need to be notified individually: their authority fails the check the next time they act, because their chain no longer traces to a valid root.


An illustrative chain

The following scenario is illustrative.

A company's CFO grants a mandate to the company's treasury agent: up to R$100,000 per day in payments to registered suppliers, with permission to delegate to specialized agents, one level deep.


The treasury agent delegates to a payments agent: up to R$40,000 per day, only to suppliers in the raw materials category, no further delegation.


Now consider four actions:

Action by the payments agent

Chain evaluation

Decision

R$15,000 to a registered raw materials supplier

Within both mandates

Execute

R$15,000 to a registered logistics supplier

Outside the payments agent's category

Block

R$45,000 to a registered raw materials supplier

Exceeds the payments agent's daily limit

Block or escalate, per policy

Delegates to a third agent

The payments agent has no right to delegate

Block

Then the CFO revokes the treasury agent's mandate. The next payment the payments agent attempts fails the chain check at its root and is blocked, even though the payments agent's own mandate was never directly revoked.


Why this must be designed in from the start

Chained delegation is notoriously difficult to retrofit. A system designed around a single principal and a single agent typically represents authority as a flat set of permissions attached to one identity. Adding chains later means changing how mandates are represented, how actions are evaluated, how revocation works and how records are structured, all at once.


That is why the mandate structure should support delegation chains from day one, even if the first deployments only use one level. The cost of including it at the start is small. The cost of adding it later is a redesign.


What the record must show

For chained authority to be auditable, the decision record of every action must include:

  • the full chain of mandates, from the executing agent to the human or institutional root;

  • the version of each mandate at the moment of the action;

  • the result of the check against each link;

  • the delegation decisions that created each link, with their own IDs;

  • any revocations affecting the chain, and when they took effect.


With that record, the question "who authorized this?" always has a precise answer, however many agents were involved.


Interoperability across organizations

The hardest version of the problem arises when chains cross organizational boundaries: when one company's agent acts on the authority of another company's agent, or when an agent from a fintech acts on a bank's rails on behalf of a customer.


For that to work safely, organizations will need a shared way to represent mandates and verify chains: a common format for describing who delegated what authority to whom, and verifiable proof that each link is genuine. That is one of the reasons regulated decisions will increasingly need common schemas, not just internal systems.


Accountability that scales with autonomy

The promise of the agentic economy is that agents can coordinate complex tasks among themselves, at a speed and scale humans can't match. That promise depends on one thing: that authority stays bounded and traceable no matter how many agents are involved.


However long the chain, authority only narrows, every link is recorded, and every action traces back to an accountable human.


Want to explore how chained agent authority can work in your institution? Talk to our team →


Related Posts

See All

Comments


The Zayon Briefing

Topics you're interested in:

A periodic briefing on AI decision infrastructure, governance and what it means for financial institutions. No noise.

STAY INFORMED 

bottom of page