Principal (delegation)
The person or organization an agent acts for. In delegation the principal's authority passes to the agent, which still acts under its own identity.
In delegation, the principal is the person or organization whose authority an agent exercises and on whose behalf the agent acts.
Where the word comes from. Security vocabulary uses “principal” for an identity that a system authenticates. RFC 4949, the internet security glossary, defines it as a specific identity a user claims when accessing a system. OAuth 2.0 Token Exchange (RFC 8693) applies the word to both sides of delegation: when principal B delegates some of its rights to principal A, A keeps its own identity, and its actions are understood as A acting for B. The RFC observes that A is, in that sense, an agent for B.
The parties in an agent exchange. Illustrative:
| Party | Example |
|---|---|
| Principal | A customer who wants a refund |
| Agent | The customer’s AI assistant |
| Agent provider | The company that runs the assistant |
| Counterparty | The retailer’s service agent |
In A2A. The specification describes an A2A client as acting for a user or another system. A2A payloads carry no identity fields: the enterprise guidance says identity is established at the transport and HTTP layer, through the credentials a server asks for in its Agent Card. How a server learns who the principal is, and what the principal approved, depends on the credentials and extensions in use.
Why the distinction matters. A request can come from a well-behaved agent run by a reputable provider and still lack the principal’s approval for that specific action. Proof of the agent’s identity and proof of the principal’s authorization are separate checks. In a JWT that records delegation, RFC 8693 keeps the subject the token is about in the top-level sub claim and names the party currently acting in an act claim.
Neighbouring terms. Delegation is the act of passing authority from principal to agent. A mandate is one way to record exactly what the principal approved.