Delegated access gives the agent direct possession of a credential, while mediated credential use keeps the secret behind a proxy or gateway and only allows the agent to request approved actions. That difference matters because exposed credentials expand abuse potential, whereas mediation preserves control at the point of use.
What makes delegated access different from mediated credential use?
delegated access and mediated credential use both let an agent act on a user or system’s behalf, but they are not the same control pattern. Delegation gives the agent the credential or token needed to act directly. Mediation keeps the secret in a trusted intermediary, so the agent asks for an approved action rather than handling the credential itself.
Why the control boundary matters
The practical difference is where authority lives. With delegated access, the agent becomes a direct bearer of the credential, so compromise, overuse, or session replay can expose the full privilege set attached to that secret. With mediation, the secret stays behind a boundary and the intermediary can enforce scope, logging, approval, and revocation at the point of use.
That is why agent design choices should be treated as an access-control decision, not just an integration detail. When the agent holds the credential, blast radius expands to whatever the credential can reach. When a proxy or gateway mediates use, the security question shifts to whether the intermediary correctly constrains each request and whether it can be audited or disabled quickly.
For a broader view of how human and non-human actors intersect in these patterns, see Human vs Non-Human Identity. The same boundary issue shows up in consented agent workflows, where the agent acts with approved scope but should not inherit unrestricted possession of the user’s secret.
Where each model is usually appropriate
Delegated access is usually chosen when the agent must execute independently for a period of time, such as service-to-service automation, scheduled tasks, or workflows that need direct authenticated calls without a live approval step. It is convenient, but the trade-off is that the credential itself becomes an asset that must be protected, rotated, and bounded very carefully.
Mediated credential use is usually better when the action set is limited, sensitive, or variable. A gateway can translate a high-level request into a narrow operation, such as “create report”, “read this mailbox”, or “submit this transaction”, without exposing the underlying secret to the agent. That model is stronger when you need human review, policy checks, or rapid revocation.
For delegation standards and on-behalf-of flows, RFC 8693: OAuth 2.0 Token Exchange is the clearest reference point. For implementation patterns where mediation reduces secret exposure, the Secrets Management Guide is a useful companion because it frames secretless and proxy-mediated approaches as operational controls, not just storage choices.
Risk and Threat Considerations
The main risk is that delegated access turns the agent into a direct credential holder, which means any compromise of the agent, its runtime, or its memory can expose the secret and all the access attached to it. Mediated use lowers that exposure, but the intermediary becomes a high-value enforcement point, so misconfiguration or weak policy logic there can still create abuse paths.
Failure mechanism: An attacker, buggy tool chain, or over-permissive agent action can misuse a directly held credential for unintended access, lateral movement, or persistence, while a mediation layer can fail if it overgrants actions, caches secrets unsafely, or fails open.
Impact: The difference shows up in blast radius, revocation speed, and auditability. Direct possession typically raises the cost of containment because the credential may have to be rotated everywhere it was exposed, while mediation can often be cut off centrally if the gateway is the only enforcement point.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Direct credential possession raises the impact of secret exposure for agents. |
| NHI-05 — Overprivileged NHI | Delegated agent access becomes risky when the credential carries excess privilege. | |
| Recommendation — Keep secrets out of agent runtimes and rotate exposed credentials quickly. Minimise agent privileges to the smallest approved scope. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credentials used by agents need lifecycle and revocation control. |
| Recommendation — Apply lifecycle controls so agent credentials are issued, rotated, and revoked cleanly. | ||
Practitioner Guidance
What to verify: Confirm whether the agent truly needs a reusable secret or whether a narrower mediated action is sufficient. If the agent can complete the task without ever seeing the underlying credential, prefer mediation and treat direct possession as an exception.
Decision rule: If the agent’s action can be expressed as a bounded operation with policy checks, use mediation; if the workflow needs autonomous authenticated calls across multiple steps, use delegation only with tight scope, short lifetime, and explicit revocation paths.
What good looks like: The agent can complete the business task, but the secret remains outside the agent’s control, the action trail is attributable, and any approval boundary can be removed without redesigning the whole workflow.
Practitioner takeaway: The safest design is the one that keeps credentials out of the agent unless direct possession is truly required, because control at the point of use is usually easier to contain than control after the secret has been handed over.
Related resources from NHI Mgmt Group
- What is the difference between JIT access and Zero Trust for NHIs?
- What is the difference between delegated user access and machine authority for AI agents?
- What is the difference between delegated access and app-only access for AI agents?
- What is the difference between static credential sharing and runtime secret access for AI agents?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org