Topic · Agentic Systems

Agentic Systems and Machine Authority

When an agent stops being a tool and starts committing value others must honor, and what has to exist before it can.

What has to be true before a piece of software can commit value that another organization is obliged to honor?

The binding constraint is authority, not intelligence. Once software holds standing authority to commit value across an organizational boundary, it needs a machine-readable mandate binding principal, scope, expiry, revocation, accountability, and spend semantics into one portable object. Neutral settlement is a narrower requirement: it earns its cost only when that authority record is economically operative and no participant can be accepted as its keeper.

The mistake here is structural rather than careless. For thirty years the primary user layer was a person in front of an application. Capability and authority appeared fused because a human remained the commit step. Delegation separates them, and much of the surrounding machinery was not designed to carry authority across that gap. An agent that suggests and an agent that acts are not the same system, even when the model inside them is identical.

So I classify by authority, not capability. An assistant produces output a human commits. An orchestrator commits effects inside one trust domain. An operator holds standing authority over time inside a domain it controls. An economic actor commits value across an organizational boundary on a standing mandate. The conventional enterprise stack is sufficient for the first two classes, strained for the third, and structurally broken for the fourth. The expensive error is quiet: an integration reaches a partner's system, the scope of a standing credential widens, and nobody re-runs the classification. The system changed class; its control plane did not.

The stack is not primitive-poor. It is fragmented. SPIFFE supplies workload identity; OpenFGA and OPA express authorization policy; RFC 7009 invalidates OAuth tokens; OpenTelemetry traces execution. Each solves a real fragment, but the resulting authority state is still interpreted and enforced by individual administrative domains. A trace can show what executed; it does not by itself prove that the actor held authority a counterparty was obliged to recognize.

A mandate is a snapshot; an economic actor is a process. Internal governance can manage that process because authority and adjudication sit under one roof. Cross-organizational counterparties do not share that roof. So the on-chain question becomes answerable. The class needs a mutually accepted record of its authority over time. When no mutually trusted keeper exists, storing that record inside one participant's system simply recreates the trust problem. Signed attestations carry an evidentiary record without trusting whoever stores it. The keeper problem turns severe only when the record is operative, meaning accepting it moves state and value. A consortium with known membership and agreed governance can usually solve the problem without a public chain. The residue is narrow: value transfer inseparable from the authority record, and enforcement that must bite at the asset layer rather than be promised in a policy engine. Name the party that cannot be accepted as the keeper. If you cannot, the substrate is decoration.

Spend is the one field of the six with an early enforceable form at the asset layer. ERC-4337 supports programmable smart accounts, while wallet-specific session-key and delegation modules can grant narrow, revocable, time-bounded rights to act. EIP-7702 brings delegation to ordinary externally owned accounts, and its own security guidance warns that a badly drawn delegate can hand over near-complete control of an account. That warning is specific to the mechanism. My architectural reading, as interpretation rather than result: the field furthest ahead is also the one where a design error produces direct monetary loss that may already be irreversible when it surfaces.

What would change my mind

The claim worth testing is not that delegated authority needs bounds; that is definitional. It is my ranking: authority scope and boundary explain the operational risk better than model capability, and neutral rails matter only where no accepted keeper can settle an operative authority record.

I would revise the first claim if comparable production systems showed that improvements in model capability, with the authority model and control plane unchanged, reduced mis-scoped actions more reliably than tighter scope, delegation, and revocation controls. I would revise the second if cross-organizational economic actors repeatedly handled standing authority, revocation, disputed scope, and value settlement through accepted processors, consortium governance, or contractual recourse, without needing neutral shared state or asset-layer enforcement. That would make the Web3 residue commercially smaller than I currently think it is.

Writing on this topic

5 essays, newest first. Pulled from the content directory — never a hand-maintained list.

DateRubricEssayRead
Jun 23, 2026Agentic Systems

Where Web3 Rails Become Material in Agentic Systems

Most agentic systems do not need Web3 rails. The subclass that does is the one where authority, value transfer, and settlement can no longer be separated, and no operator can be the accepted keeper.
13 min
Jun 20, 2026Agentic Systems

A Mandate Is Not Governance

The mandate is the grant. Governing it over time and across organizations is a different problem, and audit inside your own walls is not accountability across someone else's.
11 min
Jun 16, 2026Agentic Systems

Not Every Agent Is an Economic Actor

Same model, four very different system classes. The classifier is authority, not capability, and only one of the four actually breaks the conventional stack.
12 min
Jun 12, 2026Agentic Systems

The Missing Primitive in Agentic Systems Is Not Intelligence. It's Mandates

Most of the stack already exists in fragments. What is missing is one object that makes machine authority portable, provable, and revocable across boundaries.
13 min
Jun 8, 2026Agentic Systems

Web4 Is Not a New Frontend. It Is a Shift in the Primary User Layer

The shift isn't a new interface. It's a change in who initiates a digital action, and on what authority. That is a control problem, not a model problem.
10 min
Published elsewhere

Third-party publications on this topic — the part a reader can check without taking this site’s word for it.