Capital · coordination · constructionCareers

Enterprise

What is a delegation chain, and why does an enterprise agent need one?

A role attaches permissions to a title. A chain attaches them to a provable line of authority that can only narrow.

The answer

A delegation chain is a record of authority running human → organisation → agent → sub-agent → session, where each link may carry only a subset of the link above it. An enterprise agent needs one because it makes "what may this agent do" a checkable question at every hop — including the hops the agent creates for itself — with a named person always at the root.

What the chain refuses

A child grant that carries a scope its parent lacks, a cap higher than its parent’s, or a later expiry is refused with a named reason — never clamped to the ceiling and never averaged. A silent clamp is the dangerous case, because the grant on paper still claims more than it was allowed and the extra authority is live the day the clamp has a bug.

A grant that names no enforcement endpoint is refused, because authority nothing checks is theatre; and a valid signature over somebody else’s chain authorises nothing, because the chain binds authority to a specific holder rather than to whoever can replay the bytes.

What it changes for governance

Revocation walks down the chain, so cutting a human’s authority cuts everything delegated beneath them. And because the root must be a person or an organisation and never a machine, there is always a name to put next to an action when a reviewer asks who authorised it.

The underlying concept is defined canonically at The delegation chain — FlashyOS. This page answers the build question; that page answers the “what is it” question.

Talk to the practice

Tell us what you are trying to build and what has to be true for it to work.

Contact