01
Agent Authority
The set of actions an AI agent is genuinely entitled to take on behalf of a human or an organisation, as distinct from the actions it happens to be technically capable of taking. These two things are rarely the same size, and the difference between them is where most of the real risk lives.
02
Technical Permission
What a system will actually allow an agent to do, based on its configuration. Technical permission tells you whether something is possible. It tells you nothing about whether it was ever meant to be allowed. An agent can have technical permission to do something no one ever intended to grant it, simply because a default was never tightened.
03
The Authority Gap
The space between what was declared, what was formally delegated, what the technical configuration actually permits, and what an agent has exercised in practice. When these four things align, an organisation can answer questions about its agents with confidence. When they diverge, and they usually do, that divergence is the authority gap.
04
Declared Authority
What a board, a CFO, or a senior decision maker has said an agent, or the person delegating to it, is allowed to do. This is usually the clearest of the four layers, because it exists somewhere in writing. It is also the layer most organisations mistake for the whole picture.
05
Delegated Authority
The specific handoff of that declared authority to a person, a team, or a system. A CFO approving a spending limit is declared authority. That limit being passed down to a finance agent, with a defined scope and an expiry, is delegated authority. A surprising number of organisations can describe the first step clearly and lose the thread by the second.
06
Technical Authority
What the underlying systems, the identity provider, the API, the payment rail, actually enforce, regardless of what was declared or delegated. This is often broader than intended, because permissions tend to accumulate over time and rarely get revisited once granted.
07
Exercised Authority
What an agent has actually done, as distinct from what it was permitted to do. This is the only layer most logging tools capture with any reliability, which is part of why it is so often mistaken for the full story.
08
Authority Reconstruction
The process of independently rebuilding the full chain from a human principal's original mandate through every delegation, credential, and system, to a specific action an agent took. Done properly, it should be possible without relying on the self reported logs of the platform that executed the action.
09
Independent Verification
Evidence of what happened that does not depend on the honesty or the completeness of the system being evaluated. A platform confirming its own agent behaved correctly is not independent verification, no matter how detailed the logs are. This is the same reason a company does not audit its own finances and call the result an independent audit.
10
Authority Exposure
The financial or organisational risk created by a gap between declared and exercised authority, expressed as a specific, quantified figure rather than a general sense of concern. A number a board member, a CFO, and a cyber insurer can all read from the same page and understand the same way.