Delegated consent is the customer's explicit, informed approval for a specific AI agent to take specific actions on their account, typically captured during login through a consent screen that names the agent and the scopes it is requesting. It is the agentic-era equivalent of an OAuth consent prompt, adapted to describe what an autonomous agent, rather than a simple application, will be allowed to do.
Frequently asked questions
Can a customer revoke delegated consent after granting it?
Yes, and giving customers a self-service way to see and revoke active agent permissions is a core expectation of agentic CIAM.
Is delegated consent captured once, or every time an agent acts?
Once at the initial grant, with additional prompts only when the agent needs new scopes it wasn't originally granted. See incremental authorization.
What must a delegated consent screen show, at minimum?
The identity of the specific agent and the specific scopes it's requesting, so the customer can make an informed decision rather than approving broad, undefined access.
.avif)