On-behalf-of identity at machine speed: what AI agents change about delegated access

AI agents have made on-behalf-of identity the foundational delegated access problem for the next decade. The IETF specified the protocol answer in 2020 as RFC 8693. Anthropic's MCP authorization model, AWS AgentCore Identity, Uber's published agent architecture, and the Coalition for Secure AI's enterprise guidance all converge on the same primitive.

Smiling man wearing glasses and a navy blazer over a white shirt, outdoors with blurred background.
by
 
Jagadeesh Kunda
June 6, 2026
 
 
 
RFC
Key Takeaways
  • AI agents operating on behalf of users require delegated credentials that are scoped, time-bound, and distinct from the principal identity, a requirement that RFC 8693 (OAuth 2.0 Token Exchange) addresses at the protocol level.
  • On-behalf-of identity is now a production concern, not a forward-looking concept: Anthropic MCP, AWS AgentCore, Uber's published agent architecture, and the Coalition for Secure AI all reference token exchange as the mechanism for governed delegation.
  • Enterprises that provision agents with inherited user permissions rather than explicit delegated tokens cannot distinguish agent actions from human actions in audit logs, eliminating accountability and complicating incident response.
  • Redesigning access architecture around on-behalf-of patterns requires identity infrastructure changes at the provisioning, token issuance, and logging layers, not just policy updates to existing IAM configurations.

This summary was created with AI and reviewed by an editor.

Thick black downward-pointing chevron arrow with rounded ends.
Media contact
For media inquiries, contact pr@oleria.com

See adaptive, automated
identity security in action