Intelligence

The Agent Has Authority. GLEIF Asks Whether the Person Who Granted It Had Authority Too.

On 1 September 2026, GLEIF chief executive Alexandre Kech published a blog post arguing that an AI agent transacting on an organization's behalf needs machine readable proof of the organization's legal identity, the authority delegated to the agent, and the boundaries of that authority, drawing on a new GLEIF working paper, Agentic AI in Payments. Moona Intelligence reads GLEIF's own material against the same strict Authority Provenance standard applied to every architecture in this corpus, and separates a decade old, ISO standardized identity foundation from a 2026 design proposal built on top of it.

Event analysed: . This analysis was published on 2 September 2026.

When GLEIF proposes verifying an AI agent's authority through a vLEI backed trust chain to a verified individual inside a verified organization, does that verification establish that the individual was actually entitled to grant the agent the authority being exercised?

It establishes who the person is and what organizational role a trusted issuer certified them as holding. It does not establish, on anything in GLEIF's own material this record could verify, that holding the role entitled that person to grant this specific agent's authority. On 1 September 2026, GLEIF chief executive Alexandre Kech published a blog post, drawing on a new GLEIF working paper titled Agentic AI in Payments, Establishing Interoperable Trust and Control, arguing that a counterparty transacting with an AI agent needs machine readable proof of three distinct things, the legal identity of the organization the agent acts for, the authority delegated to the agent, and the boundaries of that authority. GLEIF's own language, corroborated across repeated, independently phrased search passes because gleif.org is blocked to direct fetch in this session's tooling environment, describes a cryptographic trust chain, built on the verifiable Legal Entity Identifier, vLEI, that traces back to a verified individual acting within a verified organization, and a partitioned authority model controlling which agent may do what, under whose mandate, for how long, and subject to what limitations. That architecture rests on a real, independently confirmable foundation. The International Organization for Standardization published ISO 17442-3 in October 2024, standardizing the vLEI as a digitally signed, tamper resistant credential built on Key Event Receipt Infrastructure, KERI, and Authentic Chained Data Container, ACDC, technology, with built in mechanisms for issuance, revocation and cryptographic key pre rotation. That is roughly two years of standardized, operating organizational identity infrastructure, not a proposal. What sits on top of it is materially newer and less settled. The 2026 working paper, whose own public release date this record could not independently confirm through direct inspection of file or publication metadata because gleif.org is blocked to this session, proposes extending that foundation to agent specific mandates, with authority that can be issued, monitored and revoked frequently and, GLEIF states, sometimes near immediately, verified at the moment a transaction is initiated rather than reconstructed afterward. Nothing in the material available to this record establishes a formally defined Agent Mandate Credential distinct from GLEIF's existing role credential types, so this record does not adopt that term as GLEIF's own canonical terminology. Nor does anything available to this record establish that a certified vLEI role, an officer, a signatory, an authorized representative, by itself carries defined authority semantics for a specific delegated action; a role credential can be independently verified to belong to a real person inside a real, LEI identified organization without that verification saying whether the organization's own governance actually permitted that person to authorize the specific agent mandate in question. Identity of the grantor is the layer vLEI was built to prove, and does so on a standardized, independently reviewable basis. Legitimacy of the specific grant, whether the role holder's authority extended to this delegation, is a separate question GLEIF's own material, as far as this record could verify it, does not resolve. Revocation, challenge and recovery mechanisms specific to an agent mandate are correspondingly thin in what this record could confirm: GLEIF states authority should be revocable quickly, but no formal channel by which a party other than the original grantor can contest an already accepted delegation, and no rollback or compensation mechanism for a consequential action taken under authority later found illegitimate, appears in anything this record located. ISO 20022 is described by GLEIF as a future transport that could carry richer organizational identity data as adoption continues, not as a payment messaging standard that already carries normative fields for an agent mandate today.

GLEIF chief executive Alexandre Kech published a blog post on 1 September 2026, drawing on a new GLEIF working paper, Agentic AI in Payments, Establishing Interoperable Trust and Control. Moona Intelligence verifies it now, against the same standard this desk applies to every proposed agent authority architecture: what does the evidence actually establish about where an agent's authority came from, and what does it leave open.

Several dates matter here and this record keeps them separate throughout. GLEIF's chief executive published the blog post this record verifies on 1 September 2026. The working paper it draws on carries a filename reported to contain a 13 August 2026 date. This record could not independently confirm that as the paper's actual public release date through direct inspection of working paper metadata, GLEIF publication metadata, or file timestamps, because gleif.org is blocked to direct fetch in this session's tooling environment, and search results returned an inconsistent, unsourced later date rather than a confirmable one. This record treats the working paper's own public date as unconfirmed and anchors its analysis on the confirmed 1 September 2026 blog date instead. The current Radar date this record was verified against is 2 September 2026.

Three things GLEIF says a counterparty needs proof of

GLEIF's own material, corroborated across repeated, independently phrased search passes rather than a direct fetch, argues that an AI agent transacting on an organization's behalf needs machine readable proof of three distinct things: the legal identity of whatever organization the agent acts for, the authority that has been delegated to the agent, and the boundaries of that authority. That is a more specific claim than an ordinary agent identity check. GLEIF's own framing asks who should give an organization's agent authority to act, and how a counterparty can verify that authority has actually been granted, going beyond confirming which agent is calling to asking whether a relying party can establish not only which person authorized the agent, but whether that person held a role in a verified organization carrying the authority being exercised.

GLEIF's language for the resulting control is partitioned authority, described in material attributed directly to Kech as controlling which agent may do what, under whose mandate, for how long, and according to what limitations, and characterized as more efficient than issuing every agent its own distinct identity from scratch. A separate quoted line attributed to Kech states that when those things can be verified computationally, accountability stops depending on trust and starts depending on evidence. This record treats both as GLEIF's own stated design goal, not as an independently demonstrated property of a running system, because nothing available to this record shows partitioned authority operating in a production deployment.

vLEI: a standardized foundation, not a finished agent mandate architecture

The claim's credibility rests substantially on how mature its foundation actually is, and here the evidence is genuinely stronger than for most proposals this desk verifies. The International Organization for Standardization published ISO 17442-3 in October 2024, extending the ISO based Legal Entity Identifier standard to formally standardize the vLEI as a digitally signed, tamper resistant credential for decentralized authentication of legal entities and the people who represent them. That standardization, corroborated across GLEIF's own press material, the ISO catalogue listing and independent coverage from Biometric Update, Finadium and LexisNexis, describes vLEI credentials as built using Authentic Chained Data Container, ACDC, credentials chained together and secured by Key Event Receipt Infrastructure, KERI, a protocol that separately handles credential issuance, revocation and the pre rotation of cryptographic keys. This is roughly two years old, operating within an existing ecosystem of Qualified vLEI Issuers and, more recently, GLEIF authorized Validation Agents, not a 2026 proposal.

The working paper this record verifies sits on top of that foundation rather than replacing it, and this record keeps the two layers separate throughout. The standardized layer is organizational and individual identity: an LEI identifies a legal entity, and a vLEI credential can certify that a named individual holds a stated role, such as an officer or an authorized representative, within that entity, with the resulting credential independently verifiable through the KERI protocol without contacting GLEIF for each check. The newer, unsettled layer is agent specific mandate architecture: extending that same trust chain to name which AI agent a verified individual has authorized, for what purpose, within what limits, and for how long. GLEIF's own material, as far as this record could verify it, treats the second layer as a working paper level design proposal, not as a published, ISO reviewed standard, and this record does not describe agent mandate semantics as standardized on the strength of vLEI's own ISO 17442-3 status. The standard covers the identity credential. It does not, on anything this record could confirm, itself define agent mandate fields, scope semantics or a required delegation record format.

What a certified role proves, and what it does not

This is the distinction this record exists to hold apart from an easier, weaker reading of GLEIF's own material. A vLEI role credential, independently verifiable through a chain running back to GLEIF as the root of trust, can establish that a named individual is who they claim to be and that a trusted issuer certified them as holding a specific role inside a specific, LEI identified legal entity. That is a genuinely stronger claim than an unverified self declared identity, and it is more specific than most agent identity architectures this desk has verified, because it ties an identity claim to an organization's own formal legal registration rather than to a platform account.

What GLEIF's own material, as far as this record could independently verify it, does not establish is whether holding a certified role by itself carries defined authority semantics for a specific delegated action. Confirming that a person is a genuine officer of a genuine, LEI identified company is not the same fact as confirming that company's own internal governance, a board resolution, a signing authority policy, a contractual limit, actually permitted that officer to authorize this particular agent mandate. Identity of the grantor is the layer vLEI was built to prove, and its ISO standardized foundation does that on a genuinely independently reviewable basis. Legitimacy of the specific grant, whether the role holder's own authority extended to the delegation in question, is a separate question this record found no mechanism in GLEIF's own material resolving.

This is not a defect unique to GLEIF. It is the same gap this desk has already documented in every comparable architecture it has verified this year. Draft wei aic identity cert 00 certifies that a certificate authority attested a principal's grant set, without constraining that certificate authority's own issuance policy or proving its underlying organizational determination was correct. Proof's implementation behind x401 verifies a human to an IAL2 identity standard without establishing that the verified human held a corporate office or account ownership right entitling them to sign the mandate they signed. Nuggets documents that an agent's authority traces to a specific human and organization without documenting how that human's own mandate to grant it is established or checked. GLEIF's proposal is a genuine advance on identity, because a certified organizational role is a stronger anchor than a bare human identity check or a platform administrator's own say so. It is not, on anything this record could verify, an advance on mandate legitimacy, the harder question underneath.

Agent Mandate Credential: a term this record could not confirm

Some web indexing around GLEIF's publication refers to a proposed Agent Mandate Credential. This record searched specifically for that term, and for the abbreviation AMC, across GLEIF's own material as corroborated through repeated search passes, and found no confirmed instance of GLEIF's own text defining a distinct credential type by that name, its field structure, or its relationship to GLEIF's existing vLEI role credential types. This record does not adopt Agent Mandate Credential as confirmed GLEIF terminology on the strength of secondary indexing alone, and does not describe any such credential as a new, defined, or standardized artifact. If GLEIF's working paper does define such a credential formally, its exact field structure, issuer, and status remain unconfirmed by this record's own verification, and an editor with direct access to the working paper's full text should confirm or correct this before the term is used as though GLEIF had standardized it.

Delegated scope, limits, and what remains machine readable rather than merely described

GLEIF's own material, corroborated through search, states that ecosystems supporting agentic payments require mechanisms to establish verifiable organizational identity, express and manage delegated authority, enforce machine readable policies at runtime, generate auditable records, and support privacy preserving yet compliant execution across multiple platforms. The partitioned authority model names which agent, under whose mandate, for how long, and subject to what limitations as the dimensions that model controls. This record treats those as GLEIF's own stated design dimensions rather than as a demonstrated field schema, because nothing available to this record shows a specific mandate object's exact fields, whether limits are expressed as a transaction ceiling, a merchant category, a counterparty allowlist, or a time window, or whether those limits are cryptographically bound to the credential itself, referenced externally, or left to a relying party's own policy engine to define. This record does not invent a field schema GLEIF's own material, as verified here, does not specify.

Revocation, monitoring, and what remains unknown

GLEIF's own material states that agent authority often needs to be issued, monitored and revoked frequently and, in some cases, almost immediately, and that authority should be verifiable at the moment a transaction is initiated rather than reconstructed after the fact. The underlying vLEI credential mechanism, through KERI, does carry a real, ISO documented technical capability for revocation and key rotation, distinct from the agent specific proposal built on top of it. What this record could not confirm is how quickly a revoked agent specific mandate propagates to a relying party checking it at transaction time, whether a revocation invalidates a pending transaction already in flight or only future ones, and whether any already issued child credential or delegated sub mandate is automatically invalidated when the credential above it is revoked. This record does not infer immediate, cascading revocation from GLEIF's stated design goal, because a stated goal is not the same fact as a documented mechanism, and treats the specific propagation behavior as unknown.

Transaction time verification and cross border checks

GLEIF states that for cross border agent payments, a system needs to determine whether the transaction corridor is permitted, whether the counterparty is permitted, whether the mandate is still valid, and whether the organization standing behind the payment can be independently verified, checked at the moment a transaction is initiated rather than reconstructed afterward. This record reads that as a genuine design principle worth taking seriously, distinguishing an identity verification question, confirming who the organization and the agent are, from an authorization decision, whether a specific payment provider or counterparty chooses to execute the transaction on the strength of that verification. Nothing available to this record establishes that GLEIF's own architecture makes that authorization decision itself, rather than supplying evidence a payment provider's own separate decision engine would still need to weigh, and this record does not conflate GLEIF's proposed identity and mandate verification layer with the final decision to execute a payment, which appears to remain with the payment provider or counterparty on anything this record could verify.

ISO 20022: described as a future transport, not a current one

GLEIF discusses ISO 20022 as a payment messaging standard that could carry richer organizational identity data as adoption of the standard continues, building on GLEIF's long standing advocacy for including the LEI as a data element in cross border payment messages. This record narrows that claim to what it could verify: ISO 20022 already supports LEI as a data attribute in payment messages, corroborated by GLEIF's own long running published advocacy on that point, but nothing available to this record establishes that ISO 20022 currently carries normative fields for an agent mandate, a delegated scope, or a partitioned authority record specifically. GLEIF's own framing, as far as this record could verify it, describes future compatibility and a direction of travel, not a current, adopted messaging capability for agent authority data, and this record does not claim otherwise.

The Authority Provenance ledger

This is the part a CEO blog is never built to state on its own, so Moona Intelligence separates it out deliberately, distinguishing what GLEIF's material establishes from what it leaves open, and marking what this record could not confirm as unknown rather than inferring a mechanism that was not found.

Authority grantor. A named individual, verified through a vLEI credential chain running back to GLEIF as the ultimate root of trust, certified as holding a specific role inside a specific, LEI identified legal entity. This is documented, and it rests on an ISO standardized credential mechanism this record could independently corroborate across multiple sources, a stronger evidentiary basis than a bare identity check.

Mandate or basis. This is where GLEIF's own material, as far as this record could verify it, stops. A certified role establishes who the person is and what an issuer certified them as holding. It does not, on anything this record found, establish that the underlying organization's own governance, a corporate resolution, a signing policy, a contractual delegation, actually entitled that role holder to grant the specific agent authority in question. This record records mandate legitimacy as unknown, the same gap already documented for AIC, x401 and Nuggets, rather than assuming a certified role closes it.

Delegated scope. Documented at the level of GLEIF's own stated dimensions, which agent, under whose mandate, for how long, and subject to what limitations, and undocumented at the level of a specific field schema. This record found no confirmed exact structure for a mandate object's amount, merchant, counterparty or duration fields in the material it could verify.

Explicit limits. GLEIF's own language names limitations as a dimension partitioned authority controls, without this record confirming whether those limits are cryptographically bound to a credential, expressed as machine readable policy evaluated by a relying party, or left to deployment specific implementation. Recorded as documented in principle and unconfirmed in mechanism.

Inherited permissions and assumptions. This record found no statement in GLEIF's own material claiming that a verified organizational role automatically confers unlimited or inherited authority beyond what a specific mandate grants, and no statement ruling that out either. This record does not assume GLEIF's architecture avoids the inheritance failure this desk has documented elsewhere; it records the question as open pending direct inspection of the working paper's own field level design.

Revocation or modification. GLEIF states authority should be revocable quickly, in some cases near immediately, and verifiable at the moment of transaction rather than reconstructed afterward. The underlying vLEI credential mechanism carries a real, ISO documented technical revocation capability through KERI. This record could not confirm the specific propagation latency, whether an in flight transaction is affected by a revocation issued during it, or whether revoking a credential automatically invalidates a delegated sub mandate issued under it, and records each as unknown.

Challenge authority. Undocumented. This record searched the material available to it for a formal channel by which a party other than the original grantor, an auditor, a counterparty, a regulator, could contest or invalidate an already accepted delegation, and found none. This record does not treat a relying party's own transaction time verification check as a formal challenge process; it is a check performed before acceptance, not a channel for disputing a delegation already accepted.

Recovery. Undocumented. This record searched for rollback, reversal, compensation or dispute mechanisms addressing a consequential payment already executed under authority later found illegitimate, and found none in the material available to it. Revocation, on GLEIF's own stated design goal, prevents future use. Nothing this record could verify says it reverses a payment that already settled.

Provenance evidence quality. Layered, and this record does not collapse the layers into one claim that GLEIF's proposal proves legitimate agent authority end to end. Organizational identity is strong and independently corroborated, resting on an ISO standardized, roughly two year old credential mechanism. Individual role identity within that organization is documented the same way. Mandate legitimacy, the entitlement question underneath a certified role, is undocumented. Delegated scope and explicit limits are documented as design principles and unconfirmed as field level mechanisms. Revocation is documented as a design goal with an unconfirmed propagation mechanism. Challenge authority and recovery are both undocumented. Transaction time verification is a stated design principle this record could not confirm as a demonstrated, running capability.

Where this sits against what Moona Intelligence has already verified

Draft wei aic identity cert 00 already owns a certificate based architecture where a certificate authority's own issuance policy, left unconstrained by the draft, decides whether a principal's certified authority was legitimate. x401 already owns a generic, credential neutral HTTP mechanism where Proof's own implementation verifies a human to an IAL2 standard without establishing that human's corporate or account holding entitlement. Nuggets' Authority Control Plane already owns a vendor enforcement layer that signs a receipt for its own decision without documenting how a grantor's own mandate is established. Ping Identity's Agent IAM Core, already verified in this corpus, names which human subject and which agent actor a downscoped token names without establishing that the named human held organizational entitlement to authorize the underlying action, the same gap this record documents for GLEIF. None of them, on the material this record could verify, brings what GLEIF brings: an organizational identity foundation that is not a fresh proposal but an ISO standardized credential mechanism already operating across a real ecosystem of licensed issuers, extended toward, rather than already solving, the specific question of agent mandate legitimacy. That is GLEIF's distinct contribution, an unusually mature identity foundation applied to an unusually hard, still open problem, and it is why this record treats it as its own canonical rather than folding it into any of the above.

It is also why this record refuses to let that distinct contribution round up into more than GLEIF's own material claims. A relying party building on a mature vLEI trust chain can verify, with real cryptographic assurance, that a named individual holds a certified role inside a real, LEI identified organization, and can verify an agent's claimed identity against that chain. What that relying party still cannot verify, on anything this record could confirm, is whether the organization's own internal governance actually entitled that role holder to grant the specific agent authority being exercised, whether an accepted delegation can be formally challenged after the fact, and what happens to a payment already executed if the authority behind it is later found illegitimate. The agent has authority. GLEIF has built genuinely strong infrastructure for proving who granted it. Whether that person was entitled to grant it is a question this record found GLEIF's own material, as far as it could verify it, still leaves for a relying party's own governance, not GLEIF's credential chain, to answer.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

[2]
Research and Publications
GLEIF · Primary source
[3]
The verifiable LEI (vLEI)
GLEIF · Technical documentation
[5]
ISO 17442-3:2024, Financial services, Legal entity identifier (LEI), Part 3: Verifiable LEIs (vLEIs)
International Organization for Standardization · 1 October 2024 · Regulatory source

Protocol evidence

This record does not assess these architectures. The connection runs through the Risk Registry requirement each one bears on, and these published authority architectures are what the evidence says about that requirement.

Protocol evidence related through AEW-007 Claimed authorization accepted without verification

  • Supports requirement

    vLEI and GLEIF's proposed partitioned authority architecture for agentic payments

    GLEIF (Global Legal Entity Identifier Foundation)

    Requirement A vLEI role credential can establish that a named individual holds a specific certified role inside a specific, LEI identified organization

    vLEI's ISO standardized trust chain grounds a claim of authority in a role a trusted issuer certified inside a real, LEI identified organization, rather than in a bare, unverifiable assertion. That is a genuine narrowing of the gap this weakness describes, an agent accepting a claim of authorization with no channel establishing whether it is true, even though it does not close the gap entirely.

    This record is the cited evidence for this relationship.

    View protocol evidence

  • Missing requirement

    vLEI and GLEIF's proposed partitioned authority architecture for agentic payments

    GLEIF (Global Legal Entity Identifier Foundation)

    Requirement Nothing found establishes that holding a certified vLEI role by itself entitles its holder to grant a specific agent's authority

    A certified vLEI role proves who the grantor is, not that the grantor's own organization actually entitled them to grant the specific agent authority in question. This is the same missing requirement AIC's certificate authority issuance policy and Ping Identity's own act and may_act claims already leave open in this dataset, now documented a third time in an architecture built on materially more mature identity infrastructure.

    This record is the cited evidence for this relationship.

    View protocol evidence

Related Intelligence

All Intelligence Records →