Task-scoped authority
A temporary authorization envelope for one AI-agent task, limited by allowed action, resource, consequence, duration and recovery conditions rather than broad standing role permissions.
Task-scoped authority is an authorization pattern for AI agents in which a stable identity does not automatically carry broad standing permissions into every run. Instead, the system issues a narrower grant for the work being performed now.
A useful task authority envelope answers five questions: which action may be taken, which resource may be affected, what amount or consequence limit applies, when the grant expires, and what recovery or reversibility condition is required. A role can still define the maximum eligible permission surface, but the active grant is smaller and temporary.
This matters because agents can select tools dynamically and chain actions across systems. Broad credentials increase blast radius even when the current task needs only one small part of that access. Task-scoped authority makes capability is not authority enforceable at runtime rather than leaving it as a prompt instruction.
Use it with deterministic authorization checks, short-lived credentials, guardrails, audit evidence and explicit elevation for boundary-crossing actions.
Read more in An AI agent should get authority per task, not permissions per role.
Related terms
Capability is not authority
A design principle for AI agents: being technically able to perform an action does not mean the agent should be permitted to perform it. Delegation needs gradients of authority.
Blast radius
How far the damage of a failure can spread: which data, systems, people and money an AI action can affect if it goes wrong. Smaller radius means safer delegation.
Guardrails
Controls placed around an AI system — input and output checks, permission limits, review steps and escalation rules — that keep its behaviour within acceptable bounds.
Persistent delegation
Handing an AI agent a goal it keeps carrying over time — remembering context, noticing relevant events and acting across applications — rather than completing a single prompted task.