User-delegated agent authority tracker
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 152
- Forks
- 16
- Avg merge
- 14h 48m
- Merged PRs (30d)
- 536
Description
Mecatl already has the foundations for durable user ownership and no-wider authority. This tracker follows the remaining user and operator outcomes for agents acting with delegated authority. Each linked issue owns one observable result; detailed design and implementation live in its ADR and acceptance plan.
- #478 — Operators can enable verifiable agent identity safely
- #1564 — A named agent can use a user's connected external integration without receiving credentials
- #1562 — Integrate the remote protected-operation broker on current main
- #1563 — Enforce user, agent, and exact-target authority for the first ToolHive integration
- #373 — Scheduled tasks run with bounded, revocable user authority
- #1565 — Protected user operations remain safe through broker replacement
Closed foundation: #372 established the original interactive acting-for-user direction.
Related, tracked separately (not children of this tracker): #377 (the original agent-identity tracker and its closed sub-issues) and #375 (the shell/key-reachability spike that gates #478's payoff).
The tracker is not a specification. It intentionally does not choose direct remote broker access versus a future local sidecar client proxy for the external-action work. Both must meet the same authority and credential-custody contract.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
This is a tracker rather than an implementation specification. Choose a child issue such as #1564 or #373, then read its ADR and acceptance plan before locating the relevant entry points. Done means the selected issue's observable result and acceptance criteria are satisfied; this tracker is complete when all listed outcomes are closed.
Written by the indexing model from the issue text.
Assessment
- Domain
- authorization, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100