Overview
How might we design authentication chains so people can trust and act on AI output?
When to use
- Essential for enterprise AI agents, federated identity systems, and cross-organization automation where legible identity trails are required for audits, incident response, and precise revocation.
When to skip
- Single-user local apps with no delegation.
- Consumer features where OAuth detail would confuse more than help (show a simplified receipt instead).
- Fully offline agents with no external identity providers.
Rules
Agent actions that appear as the human with no delegation marker.
Broken chain displays that hide intermediate services.
Re-using user tokens for agents without a distinct client identity.
No revoke path for a link in the chain.
Evidence
| Product | Implementation |
|---|---|
| OAuth apps | Delegated access with app name and scoped tokens. |
| Okta | Session and impersonation trails for admins. |
| Google Workspace | Audit logs for apps acting on user behalf. |
| AWS IAM | Role assumption chains in CloudTrail. |