Fine-Grained Permissions for AI Workers

Every large organisation already knows how to decide whether an employee may open a file. Almost none of them can express the thing an autonomous worker actually needs, which is permission to do one specific thing, for a bounded stretch of time, because a particular person asked for it.
A finance operations lead wants an Autonomous AI Worker to finish the part of month-end close that never fits inside the close: the small correcting entries that reconcile a subledger to the general ledger, each one obvious, each one currently keyed by hand at eleven at night by someone who would rather be doing analysis. She opens an access request. The form wants to know which system, which role, which entitlement group, and — in a field almost nobody fills in — an optional expiry. There is nowhere on that form to write the sentence she actually means, which is that this worker should be able to post a correcting entry, only against the entities inside her own remit, only until the close is filed, only in service of this reconciliation, and only because she is a controller who has the standing to make those entries herself. The form cannot hold that sentence, so the sentence gets rounded off to something the form can hold. Either she requests the role that permits journal entries, which the worker then holds indefinitely and across everything the role touches, or she requests nothing and the worker drafts entries for a human to retype, which means the human is still doing the work and the automation was theatre.
That rounding-off is the entire problem, and it is not a failure of anyone's identity platform. It is a category mismatch. The permission models running inside enterprises were designed with real care to answer one question extremely well — may this subject perform this operation on this object — and they answer it by consulting a durable fact about the subject. Roles, groups, entitlements, attribute policies: all of them resolve authorisation to something you are, evaluated at the instant of the request. That design assumes a workforce whose identities change on a joiner-mover-leaver cadence measured in quarters, and it deliberately declines to ask the one question that would make it unwieldy — why. Access control became decidable, auditable, and administrable precisely by refusing to care about intent. For human staff that refusal was not a weakness, because intent was being handled elsewhere.
The control that mattered was never in the access system
Consider what actually stops a competent employee with broad entitlements from doing the ninety-nine things their entitlements technically permit. It is not the access model, which would happily allow every one of them. It is that the person understands what they were asked to do this week, knows the difference between their job and their permissions, remembers that a colleague will read the audit log, and would find it strange and vaguely humiliating to touch a record that has nothing to do with them. Organisations run on a coarse outer envelope of granted access, inside which fine-grained judgement is exercised continuously and informally, carried by memory, culture, direct instruction, and the well-founded expectation of being asked about it afterwards. A manager saying "go ahead and issue that credit, just this once, for this customer" is a real authorisation event with a real scope and a real expiry, and the identity infrastructure never learns it happened.
The moment the actor is software, that informal layer evaporates and the coarse envelope is all that remains. This is why the debate about AI permissions so often ends up stuck: the envelope was never intended to be the control, only its outer bound, and now it is being asked to carry a load it was not shaped for. The consequence is a binary that operations leaders recognise immediately once it is named. Either an autonomous worker is confined to reading and drafting, in which case a human remains on the critical path for every action and the coordination cost is barely dented, or it is given an account with the standing role, in which case its blast radius on a bad day is the full width of that role for as long as the account exists. Neither option is a control regime. They are the two ends of a dial nobody wanted to be holding, and organisations keep landing on one end or the other because the primitive that lives between them has not been built.
It is worth being honest that this is a live reason serious programmes stall rather than a theoretical concern. When Gartner predicted that over forty percent of agentic AI projects will be canceled by the end of 2027, inadequate risk controls sat alongside cost and unclear value among the causes it named. A pilot that works beautifully in a sandbox and cannot be given production authority is not a technology failure. It is a project that ran into the fact that the enterprise has no vocabulary for the permission it needs to grant.
Delegation is a different primitive, with different parts
What an autonomous worker requires is not a finer-grained version of access control but a different construct sitting above it, and the difference shows up in four properties that entitlements simply do not have. The first is purpose: a delegated mandate is bound to a stated objective, so that an action falling outside the objective is not merely denied, it is incoherent — there is no reason for the worker to be reaching for it, and the attempt itself is a signal worth surfacing rather than a lookup that quietly returns false. The second is expiry, and it inverts the default that access control chose. An entitlement persists until someone deprovisions it, which is why access reviews exist and why they are dreaded; a mandate lapses unless something renews it, so the resting state of the system is that nothing is authorised and every open grant is a live, countable thing with a clock on it.
The third property is attenuation, and it is the one that most directly answers the question of legitimacy. A mandate is derived from the authority of a named human and can never exceed it, which means the worker's power is a strict subset of the delegator's, and it moves when theirs moves. If the controller's remit narrows, every mandate she has opened narrows with it, without anyone remembering to go and edit a group membership. This also determines what happens as work fans out: when a worker calls a specialist agent, or reaches a system through the Model Context Protocol, what it passes along should be a further-narrowed slice of its own mandate rather than a copy of it, so that authority weakens as it travels rather than propagating intact. The fourth property is the accountability chain that falls out of the other three. An audit record that says a service identity performed an operation tells an investigator almost nothing useful; a record that says this action was taken under mandate M, opened by this person, in service of this objective, expiring at this point, is a reconstruction of a decision rather than a log line — and it is the artefact that a regulator, an auditor, or an internal risk committee is actually asking for when they ask how the system is controlled.
Where the mandate has to live
The reason this is buildable now rather than an architectural wish is that autonomous systems, unlike people, have a chokepoint. Every consequential thing an AI worker does leaves through a tool interface, and MCP has made that boundary explicit and uniform in a way that no equivalent boundary exists for a human with a browser and a keyboard. A place where every action must pass is a place where a mandate can be checked, which means the enforcement point is available even in organisations whose underlying systems will never learn a new permission model. Above that boundary, the natural carrier for a mandate is the unit of work itself: an AI Mission already has an objective, a requester, and a definition of done, which is nearly a delegation record already — what it needs is for the objective to be load-bearing rather than descriptive, and for the mission's end to actually extinguish the authority it was granted. This also puts Human-in-the-Loop where it belongs. Approving every mechanical step trains people to click through; approving the opening or widening of a mandate is a decision a human is well suited to make, makes sense to be woken for, and only has to be made once per body of work.
Getting this right is one of the quieter conditions for the shift that the category's body of work on autonomous enterprise operations keeps circling: an organisation cannot hand real work to software it can only either cage or trust completely. It is why platforms in this space, StudioX among them, end up treating the mission, its human sponsor, and its expiry as first-class objects rather than metadata — not because delegation is a feature anyone shops for, but because without it the honest answer to "what can this worker do in production" is either nothing or too much.
The mental shift, then, is to stop maintaining an answer to the question the access model was built for. Asking what an AI worker has access to produces an inventory, and an inventory of standing capability is exactly the wrong object to be accumulating for an actor that is supposed to appear, do something specific, and stand down. The question worth being able to answer instantly is which mandates are open right now, whose authority stands behind each one, what objective closes it, and when it lapses if nothing does. An organisation that can answer that can let its workers act, because every grant it has made is small, attributable, and already dying. An organisation that can only answer the first question will keep discovering that its only two options are an agent that cannot help and an agent it cannot bound — and will keep concluding, wrongly, that the problem was the agent.
Discussion
No comments yet — start the conversation.