Discussion about this post

User's avatar
Dr Peter McCann Strain's avatar

What struck me was that the public agent never needed the privileged token. It only had to create an event the trusted workflow would accept.

That moves the authorisation boundary to the handoff between agents. The receiving workflow has to verify who produced the trigger and whether they were allowed to invoke that action. I have been thinking about that as delegated authority here: https://petermccannstrain.substack.com/p/when-an-agent-acts-who-acted

1 more comment...

No posts

Ready for more?