IDY-OBS-01Tier IIIIdentity & Least-Privilege

Delegation-Chain Tracking

When an agent invokes another agent, maintain an auditable chain-of-delegation that preserves the original principal and intermediate authority.

Runtime: ObserveAgentOps: Operate & MonitorSee on the matrix →
DELEGATION CHAIN TRACKING Original Principal · Userlives at top of chain Supervisor Agenton behalf of user ↓ chain header Worker Agenton behalf of sup. ↓ chain header Tool · Specialistfull chain inrequest [user → sup → worker]Every hop appends identity + timestamp. Authorisation considers the full chain.
In Plain English

This page is the complete instruction page for one pattern called "Delegation-Chain Tracking." It explains the problem this pattern solves, the idea behind the solution, when you should (and should not) use it, and what happens afterward — both the good effects and the costs.

This matters because building AI agents is not just about making them clever. It is also about making them safe and predictable. Following a well-tested pattern like this one helps avoid common mistakes, and shows you exactly which safety rules and regulations it connects to, listed under "Standards Mesh" on this page.

Context

Multi-agent workflows can obscure "on whose behalf" an action is taken. A specialist agent acting on a supervisor's delegation, itself acting for a user, produces three layers of authority. Without tracking, the audit trail collapses.

Problem

Agent-to-agent delegation without chain-tracking loses the principal of record.

Forces

  • Clean agent boundaries vs end-to-end accountability
  • Chain depth vs metadata overhead

Solution

Propagate a delegation chain header with every inter-agent call: [original principal → supervising agent → worker agent → ... ]. Each hop appends its identity and timestamp. Authorisation decisions consider the full chain, not just the immediate caller. Observability reconstructs the chain end-to-end.

Applicability

  • Hierarchical multi-agent systems
  • Agent-as-Tool compositions
  • Cross-organisation agent invocation (A2A/MCP)

Anti-Patterns

  • Each agent hop re-authenticating as itself, losing principal context
  • Chains that grow unbounded without audit

Consequences

  • +End-to-end accountability
  • +Supports principal-aware authorisation
  • Header-propagation discipline required
  • Adds audit-record volume