PLATFORM · PROVE

Prove every hop only tightens authority.

When one agent hands work to another, prove the delegated authority only got smaller — never broader — and get a signed receipt either way. Grounded in the IETF Delegation-Receipt model.

verifiable trust receiptNARROWED
Delegation Receipt
W3C VERIFIABLE CREDENTIAL
fromagent-orchestrator
toagent-billing-01
scoperead ⊂ read+write
resultauthority reduced
proofIETF receipt · signed
siged25519:9f3a·c71e·b042·8d6f·a915·2c80·e7b3·14df
signed · offline-verifiable · /trust-receipt/…
The problem

Agentic systems pass work down a chain — an orchestrator delegates to a worker, which delegates again. Every hop is an opportunity for authority to quietly widen, and a widened delegation is exactly how a scoped agent ends up with reach nobody granted. Delegation Provenance checks each mediated hop so authority can only narrow, and leaves a signed receipt whether the hop is allowed or refused.

What you get

Outcomes you can take to a skeptical security team.

  • Every mediated delegation hop checked: authority may narrow, never broaden
  • A signed receipt for each hop — whether it was allowed or refused
  • Built on the IETF Delegation-Receipt model, an open and inspectable format
  • An honest boundary: hops that route through the mediated path are the ones attested
How it works

Three steps, no surprises.

01
Route the hand-off

When one agent delegates to another through the mediated path, the hop is evaluated.

02
Confirm it narrows

The hop is allowed only if the delegated authority is a subset of what was held.

03
Keep the receipt

Each hop emits a signed Delegation Receipt — allowed or refused — for the record.

Continue the platform
Prove · proof anyone can verify

See Delegation Provenance on your own estate.

Read-only to start, human-approved for every fix. Bring your clouds and code hosts; we map what’s there and hand you proof you can verify yourself.

Book a demoSee it live →All 20 features
Delegation Provenance — Prove | TrustFix