HomeConcepts › Authorization for multi-agent systems
Concept

Authorization for multi-agent systems

In a system where agents delegate to agents, the central risk is authority growing at each hop. Attenuable warrants make that impossible.

The delegation chain problem

Orchestrator → researcher → summarizer → tool: every arrow is a delegation, and every delegation is a chance to over-grant. Instructing agents to "only do X" doesn't bind, because the model choosing the action can be manipulated. You need authority that is structurally incapable of growing.

One chain, only narrowing

Each agent passes a attenuated warrant to the next. The chain is verifiable end to end; a sub-agent can never exceed its delegator; and revoking the root collapses the whole tree at once. Combined with spend caps and audit, a sprawling crew stays bounded and accountable.

Give your agents permission, not your keys.

Free to self-host. 10,000 free decisions on the hosted gateway — no card.

Get an API key Read the docs