Share
AI Agent Governance

Traceable Is Not Legitimate

Twelve vendors just agreed that AI agent delegation chains must be traceable. Good principle. I cheered, and then I noticed the verb: a chain can be perfectly traceable and every link in it illegitimately granted, and nothing in the standards behind the Blueprint decides which.

Twelve vendors just agreed that AI agent delegation chains must be traceable - Okta, AWS, Google Cloud, CrowdStrike, ServiceNow, Salesforce and more, in one shared reference architecture. Good principle, wrong verb. Every standard the Blueprint names moves signals about what happened or what changed. None of them decides whether the actor who delegated held the authority to do so. A traceable chain of illegitimate grants is not governance - it is a well-documented problem.

Martin Gee 6 min read

In response to Industry leaders form the Blueprint Alliance to advance a shared architecture for securing AI agents, Okta Newsroom · September 2026.

authority-governance delegation-chains blueprint-alliance agent-authorization oktane
Martin Gee

"A traceable chain of illegitimate grants is not governance. It is a well-documented problem."

— Martin Gee, Founder & CEO, IdentityRM

Oktane week. I read the Blueprint Alliance release the way I read most of them, looking for the one sentence that tells you what the authors think the problem is. Twelve vendors, Okta, AWS, Google Cloud, CrowdStrike, ServiceNow, Salesforce, Databricks, Zscaler and the rest, one shared reference architecture for securing AI agents, six principles. Principle three, in their words: keeping delegation traceable. Their architecture page spells it out: when a human delegates to an agent and that agent spawns a sub-agent, the chain of accountability must survive each hop.

I cheered. Then I noticed the verb.

Credit first, because it is earned. This is the biggest vocabulary convergence the agent-security space has had. Delegation legitimacy has been a technical-brief topic for a handful of us for years. Delegation itself is now a principle endorsed across identity, cloud, endpoint and data platforms in a single press release. The four questions the architecture is built on, where are my agents, what can they do, what are they doing, how do I respond, are the right four. The coalition is real.

And the principle is good. It has the wrong verb.

What traceable buys you

A traceable chain answers attribution. Who handed authority to whom, hop by hop, from the human at the root to the agent that acted. When something goes wrong you walk it backwards and name every party. That is worth having. An untraceable chain is strictly worse.

Now look at what each hop actually is. A grant. Somebody, a person, a service, an agent, conferred authority on the next link. Traceability records that the handoff happened. It says nothing about the only question that makes the chain worth trusting:

Was each grantor entitled to make the grant it made?

A chain can be perfectly traceable and rotten at every link. The contractor bot whose window closed two weeks ago hands authority to a sub-agent. Traceable. A manager who was never allowed to assign a role assigns it, and an agent inherits it. Traceable. A platform team gives an agent global reach, and it delegates a neat, narrowed slice of authority it should never have held. Traceable, auditable, and illegitimate from the root.

A traceable chain of illegitimate grants is not governance. It is a well-documented problem.

The standards underneath stop short

This is not a knock on the Blueprint. It is a property of the standards it names, and you can read it in their specifications. MCP carries agent-to-tool calls. OCSF normalizes security telemetry so vendors can share it. SSF and CAEP carry security events and session changes between control planes. Every one of them moves signals, about what happened, what changed, who did it. All useful. None of them is a decision. Nothing in that stack computes whether the actor at hop N held legitimate authority for the thing it passed to hop N+1. The signals assume the decision was made somewhere.

I wrote up this pattern across the whole field back in August, before the Blueprint existed: everybody attenuates, nobody roots. Token-exchange delegation rests on a static assertion configured in advance. The most formal frameworks in the literature treat root adequacy as a prerequisite for soundness, not a runtime check. The standards track roots chains in a human, which answers who is accountable and never whether they held the authority they passed on. The Blueprint does not fix this. It elevates it to a twelve-vendor principle.

What legitimate would mean

Legitimacy is computable, if something holds the model to compute it against. For every link in the chain I want four factual answers. Was the grantor entitled to grant? Who may confer which authority, at which position in the organization, is itself governed, with history, so a grant made by someone never allowed to make it is caught rather than inherited. Was the grant alive? Every grant carries its own window, and an expired one does not become legitimate because the account behind it still resolves. Was it in scope? Authority attaches to a position in the organization, not a flat identity, so a link whose reach exceeds its position is illegitimate however cleanly it narrows downstream. And is the accountability chain intact? The owner who left on Friday cannot be the living root of a delegation on Monday.

Your identity provider cannot answer those at the moment of decision. Not because it is deficient. Its schema has no place for them. An IdP sees an assignment edge: it exists or it does not, and sometimes when it expires. An access certification, which Okta just made available for agents, catches a stale edge on a cadence. Neither knows what stood at the instant the agent acted, or whether the person who created the edge was entitled to. Only a system of record for authority, consulted at the moment of decision rather than reconciled on a schedule, knows the decision behind the edge: who granted it, under what authority, why, and until when.

The chain records the handoffs. The record knows the decisions. Different layers, and the second one is the one the Blueprint just made every enterprise ask for.

What it looks like when it is computed

I do not want to ask you to take that on faith, so here is the beat from last week’s post that answers the first question on camera. Jordan Lee grants the Release Pusher role to an engineer for seven days. Jordan is a support analyst who cannot assign roles in general. The grant goes through anyway, and the record says why.

Receiptframe four from last week · the grant, executed, with its authority sources
Claude Code showing the executed grant: the assignment id, the seven-day expiry, and the authority path in Claude's words

Two authority sources are written into that grant. One is a permission assignment, which let Jordan see the role. The other is role ownership at the Engineering node, which is what entitled Jordan to grant it. Neither alone was enough. The server says so in fields, not adjectives, and it seals the answer. That is the first link of a chain with its legitimacy computed rather than assumed. When Jordan later asks to push, the same model refuses: owning a role is the authority to grant it, not the permission itself. Traceable would have recorded both events. Legitimate is what decided them.

The timestamp

Worth being precise here, because the convergence makes this look newer than it is.

Delegation legitimacy was never an AI problem. It is the oldest ungoverned layer in enterprise identity. It is why custom admin portals exist, why “who approved this” is answered by archaeology, why access reviews certify edges nobody can attribute. Agents did not create the problem. Agents removed the humans who papered over it, the people who knew, tribally, who was really allowed to grant what. At machine speed that knowledge stops scaling and the missing layer becomes load-bearing.

That is why the architecture behind IdentityRM was filed as a patent in December 2021, before GPT-4, before MCP, before “agentic” had appeared in a press release, and granted as US 12,549,558. Not because we predicted agents. Because the question was the grantor entitled to grant already had no system of record, and every delegation mechanism the industry shipped assumed someone, somewhere, had answered it.

Twelve vendors just agreed the chain matters. The layer that decides whether each link belongs in it has been under construction here for nearly five years.

For everyone who was not in the room

The Alliance made one choice that matters more than any product in the release. It left the governance layer vendor-neutral. Nobody in the coalition owns it, and the architecture names a requirement for it without naming a supplier. That is an open seat, and it is as open to the identity, governance and security vendors who were not on that stage as to the twelve who were.

A decision layer is standards-neutral by construction. It sits behind any identity provider, computes legitimacy against an authority model the customer already has to keep somewhere, and hands back its verdicts in the event shapes the Alliance just agreed to carry. A vendor that plugs into it does not join a camp. It answers the question the architecture asks and its own products cannot, for every customer on every IdP.

To be equally clear about the boundaries: IdentityRM is not affiliated with the Blueprint Alliance. Traceability is necessary and belongs everywhere the Blueprint says it does. And computing the legitimacy of each link does not replace runtime monitoring or containment. It is the layer beneath them, deciding what should have had standing in the first place.

The next convergence

Traceable is how you reconstruct what happened. Legitimate is how you decide what may happen. Only one of those is a control.

The industry converged on the chain in a single press release. The next convergence will arrive the same way, suddenly and all at once, on the question underneath it. Not can we trace who delegated, but did each link in the chain have the right to be there at all.

That one has been our whole product from the start.


IdentityRM is the system of record for authority: who may do what, where, until when, granted by whom, consulted at the moment of decision. Start with what Authority Governance actually is, the field survey behind this argument in Everybody Attenuates. Nobody Roots., or the platform.


Share
All Posts

More from the Blog

AI Agent Governance

Then I Told It Who to Ask Instead

The practical follow-on to I Told Claude Code to Stop Asking Me. We modeled git push as a permission, gave a delegated owner the authority to grant it, and put a hook in Claude Code that asks IdentityRM before the shell runs. Refused with a reason, fixed by someone whose authority to fix it was recorded, allowed with no prompt, refused again from a different position. Seven real frames, the server records for each, and a plain statement of what a courtesy hook does not enforce.

Read more →
AI Agent Governance

I Told Claude Code to Stop Asking Me

Coding agents like Claude Code and Codex stop and ask for permission constantly. That prompt is not a guardian - it is what an agent does when there is no authority model to consult, so the question gets routed to the only authority it can find: you. Allow once is an ungoverned grant. Allow always is a standing entitlement with no receipt. Here is what happens when the tools the agent calls carry their own authority model: the prompts disappear for governed operations and every governed act leaves a record instead of a click. And here is the catch I walked into: on the client side, that is still a moved click.

Read more →
AI Agent Governance

Ask. Act. Prove.

Authentication, authorization, and accounting answered the questions of the login era - all about the actor, all at the door. Agents broke the door model: a fully credentialed agent is still un-asked about the act it is taking right now. Ask. Act. Prove. is the per-operation contract for the agentic era - a bounded answer before the act, independent enforcement during it, and evidence with lineage after it.

Read more →