Delegate authority without giving away the root
Authority is explicit, scoped, time-bounded and revocable. ENTITY does not infer authority from employment, custody, infrastructure ownership, a database role or an AI model deciding it wants to act.
Authority actions
ACT · SIGN · ACCESS_DATA · EXECUTE · PURCHASE · LICENSE · SETTLE · PUBLISH · RESOLVE · DELEGATE · CONTROL
1. Create grantor and grantee Entities
owner = identity.create("Data Owner", "organization")
operator = identity.create("Licensing Operator", "person")2. Delegate only the authority required
grant = fabric.delegate_authority(
subject_ref=object_id,
grantor_entity_id=owner["entity_id"],
grantee_entity_id=operator["entity_id"],
actions=["LICENSE", "PUBLISH"],
scope={"market":"research-data", "max_term_days":30},
expires_at_ms=EXPIRY_MS,
)The grant is signed by the grantor and records implicit_escalation_prohibited=true. LICENSE authority does not silently become CONTROL or SETTLE authority.
3. Check authority at the point of use
auth = fabric.active_authority(
object_id,
operator["entity_id"],
"LICENSE",
)
assert auth is not NoneApplications should evaluate authority before the operation they are about to perform. A UI role or cached session is not a substitute for the authoritative record.
4. Prove unauthorized escalation fails
assert fabric.active_authority(
object_id,
operator["entity_id"],
"SETTLE",
) is None5. Revoke the delegation
fabric.revoke_authority(
owner["entity_id"],
grant["authority_id"],
)
assert fabric.active_authority(
object_id,
operator["entity_id"],
"LICENSE",
) is NoneAI agents use the same rule
An AI agent can be represented as an ENTITY object/actor, but its model output does not create authority. The principal must delegate a bounded action such as PURCHASE, LICENSE or ACCESS_DATA, and the same expiry/revocation rules apply.