The agent that hired another agent
When one agent delegates to another, and that one to a third, authority flows down a chain no one drew and responsibility drains out of the bottom — and by the time an action is taken, the party who authorized it is four hops away and cannot be found.
Delegation is the oldest trick in the organization of work. A person who cannot do everything hands part of it to someone else, who may hand part of that to a third, and so on down until the task is small enough to be finished by whoever holds it. It is how armies move and how firms function, and there is nothing new or alarming about it. What is new is that the parties in the chain are now software, that the handoffs happen in seconds rather than memos, and that a chain four links long can assemble itself and complete before any human has read a word of it. An agent, given a goal, calls another agent to handle a piece of it; that one calls a third to handle a piece of that; and an action gets taken at the end of a line no single mind ever laid out.
None of the individual steps is unreasonable. Each is a sensible division of labor — a specialist agent for search, another for drafting, another for execution — and each handoff is exactly the kind of decomposition that makes the whole system capable. The problem is not that the work is divided. The problem is what happens to accountability as it travels down the division. Delegation moves a task cleanly. It does not move the answer to the question that matters when something goes wrong: on whose authority was this done, and who can be made to answer for it. That question does not decompose. It has one true answer, and every hop makes it harder to reach.
Authority down a chain no one drew
Consider what actually passes across a handoff between agents. The first agent has a goal and some authority — a scope of things it is permitted to do to accomplish that goal. When it delegates a subtask, it passes along an instruction: do this part. What it rarely passes along, and what most systems have no mechanism to pass along, is the authority that instruction rests on — the bound within which the subtask is legitimate, and the identity of the party the whole effort answers to. The instruction travels. The warrant behind it does not.
So at each hop the scope silently widens or blurs. The parent agent was authorized to, say, resolve a customer's billing question. The child agent it calls is told to adjust the account, which is narrower in intent but wider in capability, and the grandchild it calls to execute the adjustment is operating with no visible tie to the original, modest purpose. Nobody expanded the authority on purpose. It expanded by attenuation — each agent inferring a slightly larger permission from a slightly vaguer instruction, because the instruction arrived without the boundary that would have contained it. The chain of authority is real, in the sense that the actions did happen and someone did set them in motion. But no one drew it as a whole. It exists only as a sequence of local handoffs, each locally reasonable, adding up to a reach that no one authorized and no one can see.
Delegation does not divide responsibility; it hides it — unless the chain that passed the authority down can be walked back up.
Responsibility that drains out the bottom
The action, when it finally lands, is taken by the agent at the end of the chain — the fourth one, the one furthest from anyone who intended anything. Ask that agent on whose authority it acted, and the honest answer is: on the instruction of the agent above it. Ask that one, and it points up again. Follow the pointers and, in most systems built today, they run out before they reach a person. The lineage is not recorded, or it is recorded in fragments that do not join, and somewhere in the middle the trail from actor back to authorizer simply breaks.
This is the specific failure worth naming, because it is easy to mistake for a different, more comfortable one. The comfortable version is that no one is responsible — that autonomy has produced an orphan act with no parent. That is almost never true. Someone set the goal; someone deployed the agents; someone is responsible. The real failure is worse in a quieter way: responsibility exists but cannot be located. The accountable party is out there, four hops up, but the chain that would lead you to them has been cut, and so a question that has an answer becomes a question no one can answer. "Someone is responsible" is not a finding you can act on. It is the shape of a finding with the content missing. What a wronged party, an auditor, or a court needs is not the assurance that a responsible person exists somewhere; it is the name, and the path that proves it.
An action you cannot trace back to an authorizer is, for every practical purpose that accountability serves, an action no one authored — not because it was unauthorized, but because the authorization left no trail. The reach outran the record. And a reach that outruns its record is precisely the condition under which harm happens and no one can be assigned to it.
Recording the chain of delegation
The fix is not to forbid agents from delegating; delegation is what makes them useful, and the ban would simply push the same attenuation into a longer single agent that is even harder to read. The fix is to make delegation carry its own provenance. Every handoff should record who authorized whom, for what, and within what scope — a link in an explicit chain, written at the moment the authority is passed rather than reconstructed after the fact. Then the chain that assembled itself out of local handoffs also exists as a whole, as a thing you can hold, because each hop left a receipt of the grant it made.
With that in place, the action taken by the fourth agent stops being an orphan. You can walk it back: this act rested on this grant, which rested on that one, which rested on the scope the first agent held, which rested on the human who set the goal in motion. Each step names its authorizer and its bound, so the walk terminates — reliably — at an accountable party, and the widening of scope becomes visible at the exact hop where it happened rather than invisible across all of them. This is the difference between delegation that merely forwards an instruction and delegation that forwards its authority with it. The first passes the work and loses the warrant. The second keeps the two together, so that anywhere the action ends up, the reason it was permitted travels alongside and can be read back.
Least privilege has always insisted that authority be narrow and explicit. The frontier adds a second demand: that authority be traceable — that it not only be scoped at each grant but recorded as a chain, so the scope of the last act can be walked back to the standing of the first authorizer. An autonomous system that delegates without preserving that chain has not distributed responsibility. It has arranged for responsibility to disappear at the seams, quietly, one reasonable handoff at a time. The chain of custody for authority is not a technicality of multi-agent design. It is the whole of whether an action four hops deep can still be answered for by the party who set it in motion.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.