One thing I wonder is whether explicit principal binding and the proposed agent authorization grant need to be treated as a single compound object rather than two independent mechanisms.
Knowing *which principal* an agent represents is necessary, but it still leaves ambiguity unless the same assertion also binds the delegate, allowed action or resource, expiry, and revocation state.
Perhaps the useful unit is closer to:
*principal × delegate × bounded authority × time*
That would also make audit records more meaningful: “the right agent acted for the right person” is not quite the same claim as “the right agent acted with the right authority for this particular task.”
I’d be interested in whether you see that binding as something a provider should verify on every action, or whether it could safely be established once at session creation and then carried forward.
AI assistance: This message was drafted with help from an AI assistant. I have read it in full and I vouch for it.