Bind the delegation
Associate the initiating actor, purpose, intended receiver and permitted action with the delegation context.
Bind delegated work to its original purpose, intended recipient and final action before the receiving executor admits it.
RS256 · verified
A receiving agent may be authenticated without being authorised to carry out every request from another agent. Context can be lost or expanded as work passes between agents and tools.
Associate the initiating actor, purpose, intended receiver and permitted action with the delegation context.
At a supported receiving boundary, verify expiry, replay state, delegation and destination before allowing the side effect.
Preserve the action decision and source-labelled outcome evidence so a reviewer can follow the handoff to the executor.
The Action Passport model binds exact-action authority to a short-lived, single-use decision. Keep the receiver’s own identity and destination permissions authoritative, and reject a changed action rather than reusing approval for a different request.
Try a local scenario, then bring your workflow to a deployment review. Start with one agent and one tool, and see exactly where the action can be stopped.