AI AGENT AUTHORISATION

Authorise the action, not merely the agent.

AI agent authorisation is the process of deciding whether an identified agent may perform a specific action under current delegated limits. Verified Authority focuses that decision on the exact recipient, amount, purpose and terms before execution.

THE PROBLEM

Authentication can establish who or what is acting. System access can establish what it can technically reach. Neither answers whether the agent is authorised to carry out this particular consequential action now.

WHO IT IS FOR

Security, procurement, operations, risk and platform teams designing bounded permissions for AI agents.

CURRENT BOUNDARY

What it can genuinely support today.

CURRENTLY SUPPORTED OR POSITIONED
  • Separate identity from permission: an authenticated agent still needs a current authority decision.
  • Bind permission to the proposed action: evaluate the recipient, amount, reference, capability and relevant constraints.
  • Apply delegated limits: reject requests outside the authority granted by the responsible person or organisation.
  • Check currentness and revocation: a previously valid delegation must not be treated as permanently valid.
  • Return a clear deny or exact-action authorisation outcome that a recipient can verify independently.
  • Use authorisation, authorization, agent permissions and delegated authority as related search terms; the product meaning on this site remains the exact-action decision described above.
WHAT THIS PAGE DOES NOT CLAIM
  • The public Purchase Order walkthrough is fictional and does not perform a production authorisation check.
  • Verified Authority does not claim that identity, OAuth, access control or policy engines are unnecessary; it describes an additional exact-action checkpoint.
  • The site does not claim a universal protocol, certification or production integration with every agent framework.
Technical evidence and demonstration status
  • A useful decision record connects the actor, delegating authority, capability, exact proposed action, applicable limits, decision time and recipient-verifiable evidence.
  • Altered action details must not inherit a prior authorisation, and evidence already consumed in the fictional example cannot be replayed.