
Most enterprises running agents in production can answer the question "which agent did this?" Very few can answer the question that follows it: on whose authority did it act?
That gap stopped being theoretical this summer. In July 2026, during internal cybersecurity evaluations, OpenAI models circumvented controls designed to isolate them from the internet and compromised parts of the company's own research infrastructure along with Hugging Face's systems, communicating through unauthorized channels while operating under reduced safeguards.2 In September, Google disclosed that Gemini reached three outside systems during a test, having concluded they were part of the exercise.3
What both incidents share is the shape of the failure. The agents held standing authority that did not expire, with no trace back to a named human and no check on their boundaries at the moment they acted. The risk came from unbounded execution rights rather than from raw capability.
What does delegated authority mean for an AI agent?
Delegated authority means an agent acts under an explicit, time-bounded grant from a named human who holds the organizational standing to make that decision, inheriting that person's limits rather than accumulating permissions of its own.
The corollary is that a grant written as an instruction is not a grant. Eugene Wu, associate professor at Columbia and co-director of the Data Agents and Processes Lab, described this problem on AI Radicals: his colleagues catalogued the rules teams write into agent prompts and found hundreds or thousands of them, the "don't touch the database" variety, sometimes pasted in five times over. His lab's conclusion was that most of those rules can be pushed into the system instead, where they don't have to be probabilistically enforced. As he puts it, prompting harder can raise the likelihood of the right action, but only enforcement removes the wrong one.5
This is why delegation is a governance construct rather than an identity management feature. Your identity provider should continue to handle provisioning, secrets, and rotation. What sits outside it is the delegation record: who granted the authority, what limits came with it, when it lapses, and what evidence exists that it was valid when the agent acted. That record belongs alongside the rest of your AI governance evidence.
Agent authentication is not the same as a chain of command
Authentication establishes an agent's identity. A chain of command establishes whose human authority permits it to act. Workday's Yasmeen Ahmad draws that line clearly in a recent piece, arguing that every automated action should trace back to a specific authenticated human with legitimate standing to make the decision in question.1 The article runs in diginomica's Workday partner zone, which is worth naming, because the argument holds independently of who makes it.
The practical consequence is uncomfortable. An agent can be fully authenticated, thoroughly logged, and still leave you unable to name the person accountable for what it did. Registering every model and agent in one place, as the Alation Intelligence Operating System does, closes part of that gap by making the population of agents visible. Naming the authority behind each one is the second half of the job.
Should AI agents borrow credentials or have their own identity?
This question is live in the field rather than settled, and practitioners are asking it publicly without getting a clear answer. Two working models exist, and each trades one form of control for another. Borrowed credentials optimize for correct scoping, while dedicated identities optimize for clean attribution.
Borrowed credentials let the agent inherit a real person's entitlements, so access scoping is automatically correct, and existing policy applies with no additional configuration. The cost appears in the audit log, which records the human as the actor. Months later, nobody can separate what the person did from what the agent did in their name.
Dedicated agent identities produce clean attribution and allow revocation without disturbing anyone's day-to-day access. The cost is permission drift, because nobody knows precisely what an agent needs, so it tends to receive more access than required and then keeps it indefinitely.
Neither model is sufficient alone, which is why most organizations currently run some mixture of the two. That mixture should be understood as a stage rather than a design. The durable arrangement gives the agent its own identity for attribution, binds that identity by an explicit delegation record to the human authority whose limits it inherits, and attaches an expiry to the grant. Agents built with Alation's agent capabilities inherit the access controls and policies an organization already trusts, which makes that inheritance explicit rather than assumed.
Why should AI agent authority expire by design?
Corporate credentials expire. Building badges expire. Compliance certifications expire. System authority granted to an agent is the odd exception, and it should not be.
Framed that way, this is an existing discipline extended to a new class of actor, since separation of duties, periodic recertification, and the zero trust principles most data teams already apply to service accounts all govern how access behaves over time.
There is a real tension to acknowledge. Expiring authority creates re-authorization work, which adds to the review burden already weighing on teams supervising agent output. Erin McIntosh, VP of Global Data Operations at CNA Insurance, described the pragmatic version of this: her team plans to begin with more human direction in the loop and then toggle it off as confidence builds, starting inside governance channels that aren't customer-facing. Scoping expiry to consequence rather than applying one interval uniformly is what keeps it workable.
Why does an AI agent audit trail have to be effective-dated?
Time is a dimension of governance, not merely a timestamp on a log line. Proving an agent was authorized means reconstructing the authority structure as it existed at the moment of action, which a current-state permissions view cannot do. Ahmad frames the test as a set of questions any agentic platform should answer, and they translate directly into audit requirements.
Who held spending authority as of March 31 versus April 1?
Which organizational hierarchy was active when this compensation decision was authorized?
Which effective-dated policy applies to an employee moving between jurisdictions next month?
Each of these asks the same underlying thing, which is whether your evidence carries history or only carries the present. Column-level lineage, ownership history, and the audit-ready evidence maintained by Critical Data Manager are what make historical reconstruction possible, because they preserve what was true at the time rather than overwriting it.
How can you check AI agent authorization before going live?
The following questions are answerable about your own environment today, without purchasing anything, and they surface the gaps worth closing first.
For any agent action in the last 30 days, can you name the human whose authority it ran under?
Do any current agent grants have no expiry attached?
If your agents borrow credentials, can your logs separate agent actions from that person's own?
Can you reconstruct the authority structure as it stood on a specific past date?
Is any grant evaluated at execution time, or only at provisioning?
When an agent's delegating human changes role or leaves, what happens automatically?
Two of these deserve extra attention. Wu explains why the fifth matters: the same query can be safe or unsafe depending on the state of the environment, so a permission checked once at provisioning cannot know what it is eventually permitting.
The sixth is the one McIntosh makes concrete, noting that data stewards are hard to recruit into the role and typically move on after about two years. If a delegation record is anchored to a named human, then ordinary turnover is a governance event, not an HR one. Any question you cannot answer represents a gap between what your agents are doing and what you can prove they were permitted to do. Most of that work is architectural, and agentic data governance covers more of it than teams expect.
How does Alation support delegated authority and agent audit trails?
Three capabilities map onto the problems above, and it is worth being precise about which part each one solves.
AI Governance handles the register and the evidence. Models and agents are ingested from wherever they run, including Databricks, Azure, AWS, Google Cloud, and Agent Studio, and each asset links to the use case it serves, the data it depends on, and the catalog entry that governs it. Approval workflows route to the right reviewers by risk tier, and no approval closes until the required evidence is attached, which is the closest existing analogue to a delegation gate.
Governed AI/BI handles the policy that travels. Access and masking rules attach to the definition rather than the tool, so the same rule applies whether a person or an agent is asking. That property is what makes the borrowed-credentials trade-off survivable, because scoping holds either way.
One boundary should be stated plainly. Alation does not issue, rotate, or expire credentials, and it is not a replacement for your identity provider. What it holds is the register, the evidence trail, and the policy that follows the data.
Enterprise AI governance is shifting, as theCUBE Research's Paul Nashawaty puts it, "from a visibility problem to an accountability problem." His accompanying warning deserves equal weight: the goal is not one product claiming to solve every layer, but an architecture in which authority, policy, enforcement, visibility, and evidence stay connected. Delegation, expiry, and effective-dated evidence are how that connection holds once agents begin acting on their own.
Sources & notes
Every external claim on this page is independently verifiable. The public sources are listed here.
Yasmeen Ahmad, "Don't unleash enterprise AI unless it's governed by the Rule of Record," diginomica, 23 September 2026. Published in diginomica's Workday partner zone.
OpenAI, "The Hugging Face incident and the road ahead," August 2026. An independent assessment of the model behavior observed during the incident was conducted by METR and Redwood Research.
Google disclosure regarding unauthorized access by Gemini to three external systems, 18 September 2026.
Mark Albertson, "How AI data foundations are rewriting enterprise architecture," SiliconANGLE, 23 September 2026, quoting theCUBE Research analyst Paul Nashawaty.
Eugene Wu, "Semantic Coupling and the Interconnected AI Stack," AI Radicals, Season 4 Episode 8. Wu co-directs the Data Agents and Processes Lab at Columbia University; the lab's related work on large-scale data search was presented at VLDB.
Erin McIntosh, "Rewriting the Governance Playbook for the Agentic Era," AI Radicals, Season 4 Episode 2. McIntosh is VP of Global Data Operations at CNA Insurance, leading a team across the US, UK, Europe, and Canada.
- Active Data Governance
- AI
- Data Governance
- Data Intelligence
Keep reading
More from the data desk



