Actor
Who or what is requesting power.
Authority Cloud · Delegation origin
Authority Cloud models where machine power came from, what it covers, how far it may be delegated, when it expires, and what becomes invalid when authority is revoked. It gives ActionGate a current, attributable authority lineage instead of asking identity, credentials, or agent intent to impersonate permission.
Principal: finance authority · purpose: approved supplier payments · ceiling: $100k · validity: 30d · redelegation depth: 1
The child grant is narrower than its parent. It may establish eligibility for an ActionGate decision, but it does not issue an Action Permit or release a credential.
Synthetic architecture illustration. No customer delegation, live authority, production action, external proof, or realized customer result is represented.
Product definition
Authority Cloud is StableMind's system for explicit delegated machine authority. It represents the accountable source of power and the boundaries that travel with that power: grantor, grantee, purpose, action scope, resources, destinations, financial or operational ceilings, validity, delegation depth, inherited denies, approvals, separation-of-duties conditions, and revocation lineage. Its job is not to decide an action or execute one. Its job is to make the authority facts current, inspectable, and attributable before a consequential request reaches ActionGate.
Authority origin
01 / DELEGATION
An authenticated agent may possess credentials, tools, memory, a business purpose, and a human sponsor while still lacking authority to perform a particular consequential action. Authority Cloud keeps those facts separate. Power must trace to an accountable principal through an explicit grant rather than being inferred from technical reach, organizational ownership, a prompt, or the machine's own confidence.
Who or what is requesting power.
What the current agent version can technically attempt.
Who granted which bounded power, for what purpose, and for how long.
How the effective authority derives from every valid ancestor right now.
Authority lineage
02 / PROVENANCE
Authority Cloud does not flatten delegation into a role label. It preserves the chain so an evaluator can identify which principal granted the power, what narrowed at each hop, which denies survived, how much delegation depth remains, and whether any ancestor has expired or been revoked.
Identify the accountable human or organizational authority from which the power originates.
Bind purpose, actions, resources, environments, destinations, ceilings, validity, and delegation rights.
Require every child scope and limit to remain equal to or narrower than every ancestor.
Carry denies, approval requirements, separation of duties, and other non-removable boundaries down the chain.
Re-evaluate expiry, revocation, signatures, lifecycle state, parent evidence, and reserved shared budgets.
Produce the exact current authority facts ActionGate may use when evaluating one semantic action request.
Authority lineage establishes what may be considered. ActionGate still owns the independent decision for an exact requested consequence.
The attenuation invariant
03 / NO AMPLIFICATION
A child may receive fewer actions than its parent, never a new action the parent did not possess.
Named systems, accounts, environments, data classes, and destinations stay inside ancestral boundaries.
Financial, cost, concurrency, and shared budgets cannot be copied into children to manufacture more aggregate power.
Validity and remaining redelegation depth can shrink at each hop and can never outlive the parent grant.
Recursive and multi-agent delegation
04 / COMPOSITION
An agent may delegate only authority it actually possesses and only when the parent grant explicitly permits another hop. Every signed child grant must remain inside every ancestor.
Ten child agents cannot each inherit the parent's full economic or concurrency ceiling. Active reservations are evaluated together so delegation cannot multiply consequence capacity.
Collaborating agents do not gain the union of one another's privileges. Joint work requires a governed mandate, exact roles, participant lineages, purpose, target, quorum, and validity.
The action scope of one independent grant cannot be quietly combined with the resource scope of another unless policy explicitly authorizes that composition.
Revocation
05 / CURRENT POWER
Authority is evaluated as current state, not historical possession. If a parent grant is revoked, expires, fails signature validation, is quarantined, or is superseded by lifecycle state, descendants that depend on it become ineffective. The leaf cannot keep power merely because its own record still exists.
Active principal authority establishes the maximum possible boundary.
Narrower delegated authority depends on the continuing validity of its parent.
A governed revocation changes current authority state instead of waiting for credentials to expire naturally.
Dependent leaf authority stops contributing eligibility to later ActionGate decisions.
An agent must return to current authority facts. Historical access or a previous permit cannot restore revoked power. Guardian carries revocation toward the runtime boundary.
Constitutional boundaries
06 / WHAT IT DOES NOT DO
A valid lineage makes an action eligible for independent evaluation. ActionGate still decides the exact request.
Credentials remain downstream execution material and cannot be used as proof that delegated authority existed.
An authenticated principal, agent owner, human sponsor, or commercial customer state is never substituted for a grant.
Policy can narrow, condition, or deny already delegated power. It cannot manufacture authority that no principal granted.
Prompts, retrieved documents, tool output, emails, and model-generated instructions cannot impersonate delegated authority.
Evidence can establish history and provenance. It cannot retroactively authorize an action that lacked power beforehand.
From institutional intent to machine-evaluable authority
07 / TRANSLATION
A grant should retain why the authority exists, not only which API method happens to implement it. Purpose provides a governed boundary for actions that may be technically similar but institutionally different, such as paying an approved supplier versus moving funds to a newly introduced destination.
Authority should resolve to the accounts, environments, services, data classes, regions, destinations, or counterparties the principal actually intended. Broad technical reach is never used as a shortcut for missing resource scope.
Amounts, aggregate exposure, concurrency, duration, autonomy, and other consequential ceilings remain first-class authority facts. Delegation can reserve or narrow those limits, but cannot clone them across children until the organization accidentally authorizes more aggregate power than the parent possessed.
Human approval, quorum, separation of duties, geographic restrictions, data-handling requirements, and explicit denies remain attached to the lineage. A child grant cannot become easier to exercise merely because authority traveled through another machine.
Every decision should use the authority that is valid now. Expiry, revocation, quarantine, supersession, signature failure, or missing ancestor evidence can make a once-valid lineage ineffective even if an agent still remembers an old grant or retains technical access.
An evaluator should be able to reconstruct the source grants, grantors and grantees, attenuation at each hop, inherited denies, effective limits, expiration, and remaining delegation depth. If the system cannot explain where effective power came from, it should not quietly infer that power.
Evaluator questions
08 / BUYER CLARITY
Public truth boundary
This page describes StableMind architecture and product behavior. Its lineage examples are synthetic. It does not claim a named legal customer, live customer authority, governed production action, external production proof, recognized revenue, or realized customer value.
Read the Public Truth ContractFrom authority to decision
Authority Cloud answers where the power came from and what its current limits are. ActionGate answers whether the exact requested consequence is inside those limits now. Public account onboarding remains inactive until SIO19, and this website surface creates no delegation, permit, credential, or machine authority.
website_session_creates_authority=false