What struck me was that the public agent never needed the privileged token. It only had to create an event the trusted workflow would accept.
That moves the authorisation boundary to the handoff between agents. The receiving workflow has to verify who produced the trigger and whether they were allowed to invoke that action. I have been thinking about that as delegated authority here: https://petermccannstrain.substack.com/p/when-an-agent-acts-who-acted
Yes, as agents become more mainstream, so does the handoff between them, which as you rightly pointed out, is via delegated authority. Cases such as this call for making that delegation and handoff more secure.
What struck me was that the public agent never needed the privileged token. It only had to create an event the trusted workflow would accept.
That moves the authorisation boundary to the handoff between agents. The receiving workflow has to verify who produced the trigger and whether they were allowed to invoke that action. I have been thinking about that as delegated authority here: https://petermccannstrain.substack.com/p/when-an-agent-acts-who-acted
Yes, as agents become more mainstream, so does the handoff between them, which as you rightly pointed out, is via delegated authority. Cases such as this call for making that delegation and handoff more secure.