AI UX PlaygroundNewsletterJoin 2K+ AI designers and PMs on Substack. New teardowns, patterns, and prompts as they drop.

Trust

Authentication Chains

Show the delegated identity path: which user, which agent, and which services authorized an action. People and admins can follow and revoke links in the trust chain.

Interactive demo

Settings → Agents

Ops Assistant

CRM is not connected yet.

Before the agent can write to CRM

CRM

Required to log renewal notes and updates.

Overview

How might we design authentication chains so people can trust and act on AI output?

When to use

  • Essential for enterprise AI agents, federated identity systems, and cross-organization automation where legible identity trails are required for audits, incident response, and precise revocation.

When to skip

  • Single-user local apps with no delegation.
  • Consumer features where OAuth detail would confuse more than help (show a simplified receipt instead).
  • Fully offline agents with no external identity providers.

Rules

  • Agent actions that appear as the human with no delegation marker.

  • Broken chain displays that hide intermediate services.

  • Re-using user tokens for agents without a distinct client identity.

  • No revoke path for a link in the chain.

Evidence

ProductImplementation
OAuth appsDelegated access with app name and scoped tokens.
OktaSession and impersonation trails for admins.
Google WorkspaceAudit logs for apps acting on user behalf.
AWS IAMRole assumption chains in CloudTrail.

FAQ

What is an authentication chain in agent UX?

It is the visible sequence of identities behind an action (user → agent → connector → target API), so “on whose behalf” is never ambiguous.

What should users see?

A short receipt: “Agent X used your Google Drive access to edit Doc Y.” Link to full chain for admins.

How does this relate to agent identity?

Agent identity names the actor. Authentication chains show the credentials and delegations that actor used.

Why do chains matter for compliance?

Regulators and security teams need to prove authorization paths. Opaque “the AI did it” is not enough.