malik/personal directoryContact
~/thinking/context-minimal-delegation.md

Context-Minimal Delegation

Website: 9 Oct 2026 · Original post: 7 Oct 2026

AWS recently showed a clean pattern for AI agents: the user's token stays out of the model, is exchanged server-side, and the destination enforces the user's permissions. That covers how identity travels. My question is how much of the user should travel with it. My answer is what I call Context-Minimal Delegation. The agent keeps its own identity. The user delegates only what a specific purpose requires: minimum permissions, needed attributes, allowed resources, and an expiry. Each task gets an even narrower token derived from that delegation, and the destination enforces both the user's permissions and those limits. Tokens only narrow, never widen. The delegation chain remains attributable to both the user and the agent. The credentials themselves never enter the model. Least privilege limits what an agent can do. Context minimization also limits how much of the user it carries into every system it touches. As agents reach deeper into enterprise systems, identity must evolve from "this agent acts as this user" to "this agent acts for this user, for this purpose, with only the context and authority it needs."
Back to Thinking