Surfaces
T2

Delegation & Authorization

13 surfaces
2.1
Interaction design

Fine-grained scope negotiation

Each authorized action is rendered as a single plain-language permission in a toggle list, with a standard bundle pre-selected by default that the user can narrow before granting.

User authorizing agent
City Digital Services

Authorize your assistant

Choose exactly what your assistant may do for your property tax relief application. You can narrow any of these now or change them later.

Standard bundle3 of 5 permissions granted
Make single payments on my behalf
One transaction at a time, up to $500. Each payment still needs my confirmation.
Read my income documents
Read-only, and only for this application. The assistant cannot change or share them.
Use my name and address
To pre-fill forms. Nothing sensitive beyond contact details.
Act without asking each timebroad
Ongoing authority, with no confirmation for each action. Rarely needed, and off by default.
Share my data with other servicesbroad
Pass your documents to third parties. Off unless you turn it on.
Or get in-person help at any service center.
2.2
Interaction design

Digital power of attorney

A delegation scoped to a category of affairs is turned into a 'generate access code for this organization' action, paired with a per-organization revocation list the donor controls.

User managing authority
City Digital ServicesB. Rus · benefit delegation

Manage your agent’s authority

Your agent acts for you on your benefit affairs. Give an organization a code to verify that authority. You can revoke it whenever you choose.

Give an organization access
City Housing Office
Access code for City Housing Office
A7K9–2M4X
Valid until 14 Jul 2026 · scoped to City Housing Office only
Organizations with access
City Housing Office
Access granted 14 Jun 2026 · active
City Housing Office
Code expired 2 Jun 2026
Generate new code
City Health Office
Revoked by you on 28 May 2026
History
System verifies authority
City Housing Office · agent authority desk
Verify an agent’s authority
A7K9–2M4X
Authority verified
Donor
B. Rus · City Digital Services ID · IP2
Attorney
AccountingCo Pty Ltd · registered agent #12345
Scope
Manage benefit payments & report changes
Valid until
14 Jul 2026 · not revoked

The code resolves against the City Digital Services register — scope, parties, currency — without City Housing Office contacting the donor. Revoke it on the left and this check fails immediately.

2.5
Service design

Delegation registries

Tiered delegation roles are presented as a ranked authorization list, with per-agent revocation and a notification to the user each time a delegation is used.

System verifies delegation
Outcomes the officer may see
City Digital Services · agent delegation verificationOfficer: T. Nguyen
Check an agent’s authority
DLG-2026-0Q47
Verified · authorized to submit

TaxBot (AccountingCo Pty Ltd) is authorized to submit the 2025 tax return for M. Thongsuk. Authority expires 30 Jun 2026.

Delegation levels
T1
Full representative
Acts on all tax affairs
T2
Submit and view
Lodge returns, view records
Held
T3
View only
See records, change nothing
T4
Discuss a single matter
One issue, no record access
User notified
City Digital Services18 Jun, 09:00
3 verification checks on your delegation this week
Routine checks of TaxBot’s authority to act for you, most recently 18 Jun, 10:42. A first use of the delegation is notified immediately.
View this delegation →

Channels: in-app + email by default, SMS on request

Routine checks batch into a digest; a first use or a scope-relevant check notifies the user at once. Every check still reaches them, without paging them each time.

2.6
Service design

Binding an agent to a verified identity

The separate representative and represented attributes are shown together, so a verifier can confirm both the agent's identity and the identity of the user it acts for before granting access.

User verifying identity
City Digital Services
Verify identity
2Confirm delegation
3Credential

Confirm the delegation

Check that the right person is authorizing the right agent. Once you confirm, the credential carries proof of both.

Represented: you
Y. Kumar
Verified by
City Digital Services ID
Assurance
IP2
Representative: the agent
AccountingCo Pty Ltd
Accreditation
Registered agent #12345
Operates
TaxBot
Can’t verify on your own? Get help from a trusted person. They set it up. You confirm before it activates.
System inspects credential
Relying agency · credential check
No credential to inspect yet

Waiting for the user to confirm the delegation.

2.7
Interaction design

Step-up re-authorization for sensitive actions

Each requested action is routed by its sensitivity into one of three branches: a low-risk action proceeds on the delegation token alone, a submission pauses for user confirmation, and an irreversible action requires step-up re-authentication.

User approving challenge
City Digital ServicesSensitive action

TaxBot wants to lodge an amended 2025 tax return on your behalf

This changes a return you have already lodged. It is classified as sensitive and needs your approval before it goes ahead.

You have until 20 Jun, 17:00 to respond. Nothing happens until you do.
User setting limits

Set when you set up the delegation. Sensitive actions can never be pre-approved.

View my tax return status
Download my notice of assessment
Lodge an amended returnAlways required
System routes by sensitivity
Sensitivity routing
Low
Proceeds on the token alone
View status, download notice
Medium
Pauses for user confirmation
Amend return · this request
High
Requires step-up re-authentication
Irreversible actions

Each service’s risk level is set in advance by the owning agency and can be read in the interface. It reflects the real-world stakes and stays the same for everyone.

2.8
Interaction design

Nominated-agent authorization

Typed levels of authority, from full representation through view-only to discussing a single return, are offered as a per-agent permission picker the user sets from their own dashboard.

User nominating agent
City Digital ServicesY. Kumar · agent management

Authorize an agent

You nominate the agent from your own account. It can never authorize itself.

Your agent provider
A
AccountingCo Pty Ltd
Registered tax agent #12345 · accredited
What can this agent do?
You are authorizing AccountingCo Pty Ltd at the Submit and view level. Exact permissions come next and can only narrow this level.
Record created when the user confirms
{
  represented: "Y. Kumar",
  operator: "AccountingCo #12345",
  level: "submit_and_view",
  service: "tax",
  initiated_by: "client"
}

Created only when the user confirms — this preview tracks the level they pick. Nomination, the registry, and later verification all use the same set of defined terms.

Your authorized agents
CarePlan Assist
View only · benefits
Change
2.9
Interaction design

User-defined access policies

Conditional rules such as access only during business hours and only for tax preparation are offered through a guided template picker the user can edit, rather than left as raw policy to author.

User setting policy
City Digital Services

Set rules for your agent

Start from a template and adjust it. Your agent can only act inside these rules.

1
Can access your tax records during business hours (Mon–Fri, 08:00–18:00)
Edit
2
Can view and submit tax returns only
Edit
3
Cannot access superannuation or health records
Edit
+ Add another rule

See what each rule would have done against your agent’s recent requests, before you turn it on.

System evaluates access
Policy evaluations
15 Jun, 10:32 · read income statements
Allowed by Rule 1
15 Jun, 10:33 · submit 2025 return
Allowed by Rule 2
15 Jun, 21:07 · read super balance
Denied by Rule 3

The user is notified on every denial. A denial with no notice would be read as the agent failing.

2.10
Interaction design

Healthcare delegation

Decisions the user placed off-limits become hard-disabled actions, shown and enforced wherever the delegation credential is read, so the delegate cannot take them at any point.

User delegating
City Digital ServicesB. Rus
Who can act2What it must never do3Confirm
Main agent
CarePlan Assist
Backup agent · fallback only
S. Rus’s assistant
S. Rus is B. Rus’s son, registered as backup decision-maker

What must your agent never do?

These actions are blocked. No agent, main or backup, can take them.

Next: confirm in writing or by video
System enforces credential
Service workflow · credential check
Permitted
Manage payments & report changes
Blocked
Debt repayment arrangement
Close account

Exclusions are enforced wherever the credential is read, not trusted to the agent’s own restraint. Weakening one later takes a step-up identity check.

2.11
Interaction design

Managed agent identity

The underlying provenance, attenuation, revocation, and audit are surfaced as a single panel answering what this agent can do, what it has done, and how to stop it.

City AssistantActive

Manage what this assistant can do, review what it has done, and stop it at any time.

What it can do
Read your property-tax records
File your rebate application · once per cycle
Ask you first before making any payment
What it has done
14:07Filed your rebate application
14:02Read two tax documents
13:58Asked you to approve a $180 paymentWaiting on you
How to stop it

Stops everything immediately. You can start it again at any time.

The panel answers three questions in plain language. The signed token beside it is the machinery underneath. The user never has to read it.

Stop is the most prominent control: full-width, and operable by keyboard and assistive tech.

2.12
Service design

Duress-resistant delegation

The stakes of the delegated action set the ceremony: none for a low-consequence grant, and an independent confirmation, a cooling-off window, and a notified trusted contact for a high-consequence one. A duress-revocation path is available to the user without the other party present.

User granting under pressure
Preview the grant at a different stakes level
Granted · takes effect now

No extra steps are needed for this permission.

System offers exit
Revoke an agent’s authority now

For a delegation you were pressured into. This route doesn’t notify the agent’s holder and doesn’t need the other person’s cooperation.

Agent: FamilyFinance, held by R. OseiDEL-2026-3390
Authority over: superannuation · payments

Revoking here also opens a private conversation with a caseworker, by a channel you choose.

You don’t have to prove you were pressured into this. Your statement here is enough to revoke it.
2.13
Service design

Containing a compromised agent

The agency's revocation propagates to every relying service in under a second and rejects a look-alike agent at presentation, while the user sees a plain-language pause with a route to re-authorize or continue without the agent — never a silent lockout.

System pauses agent
We paused your tax assistant as a precaution

Its recent activity was unusual, so we reduced its access while we check. Your entitlements, lodgment, refunds, and deadlines are unaffected.

Your ways forward
Re-authorize with a short confirmation
A supported step you can do here, by phone, or with a caseworker.
Carry on without the assistant
Do everything it did by form, phone, or in person.

A freeze with no explanation reads, to someone already wary of the system, as the system acting against them. Containment names what happened, leaves the entitlement intact, and keeps a route open.

System propagates revocation
TaxMate v3.2 · flagged for compromise
DEL-2026-1847 · held by Ledgerwise Ltd
Identity check at the moment of action
Authorized agent · key bound to DEL-2026-1847 · presentation valid
Look-alike agent · unbound key · rejected
Authority pulled at every relying service
Tax lodgment serviceauthority pulled120 ms
Payments serviceauthority pulled180 ms
Benefits serviceauthority pulled210 ms

Revocation confirmed by 3 of 3 relying services.

Tie the authority to a verifiable agent identity, and a spoofed agent fails the moment it presents itself. Revocation spreads in near real time, pulling a compromised agent before its next action. Neither case strands the user who relied on it.