Agent Architecture · Principal
The parent agent can read one case. Why can its subagent search the whole tenant?
The question
Interview question
A parent support agent is authorized for case 418. It delegates “find the related incident” to a research subagent. The subagent starts with a platform service credential that can search every case in the tenant. It returns a relevant-looking incident from a different customer's account. The parent never requested broader access. Who widened the scope?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
The delegation boundary did. A parent cannot confer authority it does not hold. The child may need fewer capabilities than the parent, perhaps only read access to documents attached to case 418, with a short expiry and no write tools. OAuth token exchange distinguishes delegation and impersonation and describes actor and subject claims. It provides a vocabulary and protocol mechanism, not an automatic policy that all child tokens are attenuated. The authorization service must decide the effective subject, actor, audience, scope and resource constraints.
I would trace the caller's identity, case-level grant, task handoff, child credential minting, tool catalog and the exact search request. Did the child receive an unscoped service token because the agent runtime starts all subagents with the same environment? Or did the search API ignore the scoped claim? Fix both the issuance and enforcement boundaries. A delegated token should be no broader than the parent's grant and the child task, bound to an audience and expiry. The tool still checks object-level access, including account and case relationship, on each read. Tool output cannot authorize a follow-up search outside scope.
Nested delegation makes this easy to miss. A child that spawns another child must pass along an equal or narrower capability, not regain the platform default. Keep the actor chain in audit, and make the parent see when a child was denied rather than quietly falling back to a privileged credential. Test a case with a plausible related incident in a forbidden account, plus a permitted incident, and verify the child only returns the permitted one. If the answer truly needs broader scope, ask the authorized human to grant it through an explicit path.
What if the platform credential is needed for operational access? It can exist behind the tool service, but the service must enforce the delegated user and resource scope. Do not put broad credentials into the model's runtime and trust the prompt to behave. An investigation subagent wants to issue a credit asks whether an investigation subagent may issue a credit. The agent used a valid tool. Why did a retrieved tenant ID expose another customer's data? asks whether a retrieved tenant ID can control a tool read. This question starts at delegation: a child received a stronger read capability than its parent before it made any decision.
Continue reading
Related questions
Read beyond the question
Explore more agent architecture
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →