Incremental authorization is the process of granting an AI agent additional, narrowly scoped access after the fact, when it attempts an action outside what it was originally authorized for, rather than requesting broad access upfront. The customer is asked to approve only the new, specific permission at the moment it is actually needed, which keeps initial consent requests narrow and understandable.
Frequently asked questions
What happens when an AI agent needs access it wasn't originally granted?
The resource rejects the under-scoped request, the agent relays that back through the authorization flow, and the customer is asked to approve just the additional permission.
Why not just request every possible scope upfront to avoid interruptions?
Broad upfront requests are harder for customers to evaluate and increase the damage if the agent's credentials are ever misused, which defeats the purpose of scoped access.
.avif)