Delegation & Authorization
Fine-grained scope negotiation
Each authorized action is rendered as a single plain-language permission in a toggle list, with a standard bundle pre-selected by default that the user can narrow before granting.
Authorize your assistant
Choose exactly what your assistant may do for your property tax relief application. You can narrow any of these now or change them later.
Digital power of attorney
A delegation scoped to a category of affairs is turned into a 'generate access code for this organization' action, paired with a per-organization revocation list the donor controls.
Manage your agent’s authority
Your agent acts for you on your benefit affairs. Give an organization a code to verify that authority. You can revoke it whenever you choose.
- Donor
- B. Rus · City Digital Services ID · IP2
- Attorney
- AccountingCo Pty Ltd · registered agent #12345
- Scope
- Manage benefit payments & report changes
- Valid until
- 14 Jul 2026 · not revoked
The code resolves against the City Digital Services register — scope, parties, currency — without City Housing Office contacting the donor. Revoke it on the left and this check fails immediately.
Consumer data rights consent flows
Delegations that only view data are separated from those that act, with a higher-ceremony confirmation step required to authorize an action and a separate dashboard toggle the user can use to manage each permission.
HealthMate is requesting access to your health records
You are signed in to City Digital Services, not to the agent. Approve only what it needs to complete your application.
To allow access, first acknowledge the statement above.
Every consent the user grants is kept here as a standing record. They can review or revoke it long after the redirect.
Consent receipts and records
The consent lifecycle, from collection through to withdrawal, is rendered as a timeline the user can read, with a 'download record' action that produces the receipt in several formats.
Delegation record · TaxBot
Operated by AccountingCo Pty Ltd · reference DLG-2026-0Q47
The same record, machine-verifiable. The agency checks what was authorized against what was done. It is the user’s evidence if they dispute it later.
Delegation registries
Tiered delegation roles are presented as a ranked authorization list, with per-agent revocation and a notification to the user each time a delegation is used.
TaxBot (AccountingCo Pty Ltd) is authorized to submit the 2025 tax return for M. Thongsuk. Authority expires 30 Jun 2026.
Channels: in-app + email by default, SMS on request
Routine checks batch into a digest; a first use or a scope-relevant check notifies the user at once. Every check still reaches them, without paging them each time.
Binding an agent to a verified identity
The separate representative and represented attributes are shown together, so a verifier can confirm both the agent's identity and the identity of the user it acts for before granting access.
Confirm the delegation
Check that the right person is authorizing the right agent. Once you confirm, the credential carries proof of both.
Waiting for the user to confirm the delegation.
Step-up re-authorization for sensitive actions
Each requested action is routed by its sensitivity into one of three branches: a low-risk action proceeds on the delegation token alone, a submission pauses for user confirmation, and an irreversible action requires step-up re-authentication.
TaxBot wants to lodge an amended 2025 tax return on your behalf
This changes a return you have already lodged. It is classified as sensitive and needs your approval before it goes ahead.
Set when you set up the delegation. Sensitive actions can never be pre-approved.
Each service’s risk level is set in advance by the owning agency and can be read in the interface. It reflects the real-world stakes and stays the same for everyone.
Nominated-agent authorization
Typed levels of authority, from full representation through view-only to discussing a single return, are offered as a per-agent permission picker the user sets from their own dashboard.
Authorize an agent
You nominate the agent from your own account. It can never authorize itself.
{
represented: "Y. Kumar",
operator: "AccountingCo #12345",
level: "submit_and_view",
service: "tax",
initiated_by: "client"
}Created only when the user confirms — this preview tracks the level they pick. Nomination, the registry, and later verification all use the same set of defined terms.
User-defined access policies
Conditional rules such as access only during business hours and only for tax preparation are offered through a guided template picker the user can edit, rather than left as raw policy to author.
Set rules for your agent
Start from a template and adjust it. Your agent can only act inside these rules.
See what each rule would have done against your agent’s recent requests, before you turn it on.
The user is notified on every denial. A denial with no notice would be read as the agent failing.
Healthcare delegation
Decisions the user placed off-limits become hard-disabled actions, shown and enforced wherever the delegation credential is read, so the delegate cannot take them at any point.
What must your agent never do?
These actions are blocked. No agent, main or backup, can take them.
Exclusions are enforced wherever the credential is read, not trusted to the agent’s own restraint. Weakening one later takes a step-up identity check.
Managed agent identity
The underlying provenance, attenuation, revocation, and audit are surfaced as a single panel answering what this agent can do, what it has done, and how to stop it.
Manage what this assistant can do, review what it has done, and stop it at any time.
Stops everything immediately. You can start it again at any time.
The panel answers three questions in plain language. The signed token beside it is the machinery underneath. The user never has to read it.
Stop is the most prominent control: full-width, and operable by keyboard and assistive tech.
Duress-resistant delegation
The stakes of the delegated action set the ceremony: none for a low-consequence grant, and an independent confirmation, a cooling-off window, and a notified trusted contact for a high-consequence one. A duress-revocation path is available to the user without the other party present.
No extra steps are needed for this permission.
For a delegation you were pressured into. This route doesn’t notify the agent’s holder and doesn’t need the other person’s cooperation.
Revoking here also opens a private conversation with a caseworker, by a channel you choose.
Containing a compromised agent
The agency's revocation propagates to every relying service in under a second and rejects a look-alike agent at presentation, while the user sees a plain-language pause with a route to re-authorize or continue without the agent — never a silent lockout.
Its recent activity was unusual, so we reduced its access while we check. Your entitlements, lodgment, refunds, and deadlines are unaffected.
A freeze with no explanation reads, to someone already wary of the system, as the system acting against them. Containment names what happened, leaves the entitlement intact, and keeps a route open.
Revocation confirmed by 3 of 3 relying services.
Tie the authority to a verifiable agent identity, and a spoofed agent fails the moment it presents itself. Revocation spreads in near real time, pulling a compromised agent before its next action. Neither case strands the user who relied on it.
No surfaces match this filter.