Inspiration

AI agents are getting better at handing work to other agents.

That creates a subtle problem: consent is not transitive.

If I authorize one AI to use my calendar, budget, travel preferences, or sensitive constraints, that does not automatically mean I intended every downstream AI it calls to inherit the same access.

That is the gap RelayPass explores.

Egoist's AI Passport gives the user a way to control what context an application or agent can access. RelayPass asks the next question:

What happens to that permission when the authorized AI delegates the task?

Our answer is simple:

Every handoff can get narrower. Never broader.


What it does

RelayPass is a consent-preserving authorization layer for multi-agent AI.

A user first approves a scoped permission for a primary agent. If that agent delegates part of the task, RelayPass creates a narrower permission for the downstream agent.

The core invariant is:

$$ Context(child) \subseteq Context(parent) $$

$$ Authority(child) \subseteq Authority(parent) $$

$$ Expiry(child) \leq Expiry(parent) $$

A downstream agent can receive less context, fewer actions, a lower spending limit, a shorter lifetime, or fewer delegation rights.

It can never receive more.

Example

Maya has an AI Passport containing 42 pieces of personal context.

She tells her personal AI, Nova:

"Get me to San Francisco tomorrow in time for dinner and handle the trip."

Nova receives only 7 approved pieces of context and authority for that task.

Nova then delegates:

  • FlightAgent gets 5 scoped permissions and a maximum flight spend of $650.
  • StayAgent gets 3 scoped permissions and a maximum hotel spend of $220.
  • DinnerAgent gets only the dinner timing and nut_free_required = true.

DinnerAgent needs to know the meal must be nut-free.

It does not need to know Maya's medical diagnosis.

Share the constraint, not the diagnosis.


The key idea: consent survives the handoff

RelayPass does not rely on the model behaving correctly.

If FlightAgent suddenly asks for Maya's home address, the request is:

BLOCKED BEFORE DISCLOSURE

The address value is never fetched or returned.

If StayAgent attempts to book a $260 hotel while its delegated maximum is $220:

ACTION REFUSED

No purchase occurs.

The policy layer enforces the boundary deterministically, outside the model.

That distinction matters because a prompt-injected or confused agent can still ask for something it should not have.

RelayPass does not need to detect why the agent asked.

The credential simply cannot authorize it.


Independent verification

A downstream service should not have to trust an agent's claim that it has permission.

In our demo, FlightAgent presents its RelayPass to a simulated airline verifier.

The verifier checks:

  • the signature and parent chain
  • the presenting agent's identity
  • the intended audience
  • the task and purpose
  • allowed actions
  • price constraints
  • expiry
  • live revocation status

Only then is the booking authorized.

The verifier sees the permission that survived the handoff, not Maya's full Passport.


Receipts and revocation

Every meaningful handoff produces provenance.

RelayPass records receipts for events such as:

  • delegated permissions
  • authorized reads
  • allowed actions
  • denied context requests
  • refused actions
  • revocation

Maya can revoke Nova once and invalidate the entire descendant tree.

A previously valid FlightAgent pass may still physically exist, but after revocation the verifier returns:

relay_pass_revoked

The signed pass still exists. Its authority doesn't.


How we built it

RelayPass is built as a deterministic authorization system rather than an LLM-driven security layer.

The prototype includes:

  • signed root and child RelayPasses using Ed25519 / EdDSA
  • parent-child cryptographic linkage
  • monotonic attenuation checks
  • deterministic policy evaluation
  • audience and purpose binding
  • spending and action constraints
  • replay protection
  • minimum-context disclosure
  • receipts
  • cascading revocation
  • isolated browser sessions
  • durable Supabase-backed production state
  • a Next.js presentation experience deployed on Vercel

The demo agents and airline/hotel/restaurant services are intentionally deterministic simulations.

The enforcement layer is real.

No LLM makes an authorization decision.

We also kept the AI Passport integration behind a PassportAdapter. RelayPass is a prototype proposal for consent-preserving agent handoffs, not a claim that Egoist currently supports derived child passes exactly this way.


Challenges we faced

The hardest part was not signing a token.

It was defining what "narrower" actually means.

A child permission must not be able to:

  • add a context field
  • add an action
  • increase a spending limit
  • broaden an audience
  • broaden a purpose
  • extend its expiry
  • remove inherited restrictions
  • increase delegation rights

We also had to make revocation work across a serverless deployment. Production state is isolated per browser session and persisted through Supabase rather than relying on unsafe process-local memory.

Another challenge was making the idea understandable without turning the demo into a security dashboard.

The final visual metaphor became:

42 → 7 → 5 / 3 / 2

As work moves farther from Maya, the visible context and authority physically shrink.


What we learned

The biggest lesson was that agent security is not only about deciding which tools an agent can call.

It is also about preserving the human's original intent as work moves between systems.

OAuth, MCP, A2A, and capability systems provide important pieces of the stack.

RelayPass explores the layer between them:

What happens to a human's approved context and authority when AI delegates?

Capability attenuation itself is not new.

Our contribution is applying that principle to user-owned AI Passport context, delegated action authority, minimum disclosure, receipts, and revocation in a product experience a normal user can understand.


What's next

A production version would connect RelayPass to a live AI Passport implementation and standardized agent-to-agent authorization infrastructure.

If AI Passport requires every downstream agent to obtain a fresh direct permission instead of accepting a derived pass, the PassportAdapter and consent flow can change while preserving the same core verifier and least-privilege model.

The long-term goal is simple:

A2A moves the task. RelayPass makes sure your consent moves with it.

Your consent survives the handoff.

Built With

Share this project:

Updates

Submission history