D31
Field Notes

September 2026

Inference does not confer authority

Carlos Ocampo · Published: · Updated:

English translation of the original Spanish publication. Original dates, authorship and documentary images are preserved.

An agent finding an action beneficial does not mean it has permission to perform it.

Carlos Ocampo · Field Notes D31 · September 2026

An agent finding an action beneficial does not mean it has permission to perform it.

It may identify an opportunity, build a recommendation and anticipate an outcome. Turning that conclusion into action requires a mandate: who authorizes it, for what purpose, within what limits and until when.

This distinction has concrete consequences when agents use tools, access information or assign part of their work to other agents.

Consider a sales process. A company authorizes an agent to analyze prospects and prepare proposals. During the work, the agent identifies that a discount could accelerate a sale.

The recommendation may be relevant. Applying the discount, sending the proposal and committing to a delivery date are different decisions. Each must fall within the authorized scope.

A detected opportunity does not, by itself, expand the permission received.

Technical proposals address this boundary. MJWT, introduced by Tom Sato in its first version on May 24, 2026, proposes credentials that bind an agent's authority to bounded actions, specific resources and a responsible human. It also proposes that derived mandates remain within the limits of the original mandate. It is an individual working document, without formal IETF endorsement. Consult the MJWT proposal.

Meanwhile, the preprint Delegation Without Trust, by Panduranga Sai Varma Dantuluri and Jyotirmoy Sundi, studies authorization under a demanding condition: an agent whose model has been compromised should still be unable to exceed its delegated authority. Its authors propose and evaluate controls external to the model within their experimental environment. Consult the study.

At D31, we add the organizational question: who can grant that mandate, and what do they need to understand to do so?

The answer requires clarity about people's responsibilities, the company's commitments and the consequences each action can produce.

We propose describing each delegation through six elements: purpose, scope, duration, limits, responsible parties and revocation conditions. That framework must be accessible during execution and comparable with what actually happened.

If the task changes substantially, authorization must be reviewed. If another agent becomes involved, its permissions must remain within the received mandate. If the mandate is revoked, the operation needs an effective mechanism to enforce that decision.

This brings the 51/49 rule into an operational condition: people retain authority over what they delegate and the ability to modify or stop it.

This allows sets of actions to be delegated without requiring human approval at every step. Autonomy operates within an explicit framework; exceptions return to whoever has authority to resolve them.

The speed of inference can expand our options. The mandate determines which may become actions.

If an agent commits your organization tomorrow, can you reconstruct who authorized it, under what conditions and with what limits?

© 2026 D31. All rights reserved.

Before adding another layer of technology, it helps to see how ready the organization is to decide, coordinate and execute.

Take the Organizational Self Check-Up™ →

Keep exploring

Inference does not confer authority | D31