One page
Agent Authorization Document, on a single page
What it is, when to use it, and the one action it produces. v1.5, August 2026. The same text as this page, laid out to print or share.
GOVERNANCE RECORD
No platform ships this document. Every AI governance framework requires it. The Agent Authorization Document is the organizational record that answers the question no control plane can answer: who formally decided what this agent is authorized to do, and whose name is on that decision.
Published under CC BY 4.0. Free to reproduce, adapt, translate, and use commercially, including inside your own governance program, with attribution to Sougata Roy and a link to this page. Attribution is a condition of the license. Claiming authorship is not attribution. Full terms at sougataroy.com/rights
Cite this framework
Sougata Roy, "Agent Authorization Document", Version 1.5, August 2026, https://sougataroy.com/frameworks/agent-authorization-document
Document preview
Complete one record per deployed agent. Retain as a governance artifact.
AGENT NAME
The display name used in the agent registry, admin center, or internal inventory.
BUSINESS PURPOSE
One to three sentences explaining the problem this agent solves and the workflow it supports.
AUTHORIZED ACTIONS
List each action the agent is permitted to take, using precise language tied to specific systems or workflows.
EXPLICIT PROHIBITIONS
List what the agent must not do. If this field is blank, the authorization record is incomplete.
DATA ACCESS SCOPE
Name the systems, libraries, sites, datasets, or applications the agent can read from and write to.
BUSINESS SPONSOR
Full name and title of the named human the organization maps from the Sponsor role in Microsoft Entra Agent ID. The platform Sponsor can be a user or supported group accountable for purpose, lifecycle decisions, and access reviews; this record requires one named accountable human for the business authorization decision.
TECHNICAL OWNER
Full name and title of the administrator responsible for this agent's operational management, permissions, and identity configuration. Maps to the Owner role in Microsoft Entra Agent ID. Not the approving authority.
REVIEW TRIGGER CONDITIONS
Describe the events that require re-authorization, such as a change in purpose, data access, ownership, regulation, or an incident.
NEXT SCHEDULED REVIEW DATE
Set the date when the organization will confirm the record is still accurate and complete.
AUTHORIZATION SIGNATURE
Capture the approving person's name, title, and date. This should be the accountable business owner, not only the developer or IT administrator.
Type
Governance record
Version
v1.5
Published
August 2026
Time to use
20 min per agent
Audience
Agent owners, risk, security, and compliance teams
Output
One completed authorization record
Last verified
Not recorded
Re-verification cadence
Monthly, with urgent updates when cited primary sources change.
Use this first
Complete one record per deployed agent and retain it as governance evidence.
Primary object
Use as a working artifact
Primary object
Capture identity, authorized scope, accountability, review, and approval in one dated record.
Agent identity
Authorized purpose
Permitted actions
Named owner
Review cadence
Approval evidence
Standing trigger
Limitation
This object can record an authorization decision and its evidence. It cannot prove that the agent behaved within scope, that the record is complete for every deployment, or that the approval was substantively wise.
Revision history
v1.5, August 2026: Added the standing trigger clause as section 05 of the record, covering unattended runs started by timers, schedules, and external events. Introduced in the August 11, 2026 newsletter edition. Record fields 01 through 04 unchanged.
Copyable citation
Sougata Roy, "Agent Authorization Document," v1.5, August 2026, https://sougataroy.com/frameworks/agent-authorization-document
One page
What it is, when to use it, and the one action it produces. v1.5, August 2026. The same text as this page, laid out to print or share.
Why this document exists
The platform records identity, permissions, and activity. It does not record the organizational decision that authorized the agent to operate. That decision requires a separate document.
The document
Agent Authorization Record
Complete one record per deployed agent. Retain as a governance artifact.
01, IDENTIFICATION
AGENT NAME
The display name used in the agent registry, admin center, or internal inventory.
BUSINESS PURPOSE
One to three sentences explaining the problem this agent solves and the workflow it supports.
02, AUTHORIZATION SCOPE
AUTHORIZED ACTIONS
List each action the agent is permitted to take, using precise language tied to specific systems or workflows.
EXPLICIT PROHIBITIONS
List what the agent must not do. If this field is blank, the authorization record is incomplete.
DATA ACCESS SCOPE
Name the systems, libraries, sites, datasets, or applications the agent can read from and write to.
03, ACCOUNTABILITY
BUSINESS SPONSOR
Full name and title of the named human the organization maps from the Sponsor role in Microsoft Entra Agent ID. The platform Sponsor can be a user or supported group accountable for purpose, lifecycle decisions, and access reviews; this record requires one named accountable human for the business authorization decision.
TECHNICAL OWNER
Full name and title of the administrator responsible for this agent's operational management, permissions, and identity configuration. Maps to the Owner role in Microsoft Entra Agent ID. Not the approving authority.
04, REVIEW AND APPROVAL
REVIEW TRIGGER CONDITIONS
Describe the events that require re-authorization, such as a change in purpose, data access, ownership, regulation, or an incident.
NEXT SCHEDULED REVIEW DATE
Set the date when the organization will confirm the record is still accurate and complete.
AUTHORIZATION SIGNATURE
Capture the approving person's name, title, and date. This should be the accountable business owner, not only the developer or IT administrator.
05, STANDING TRIGGERS
An agent that runs on a schedule was authorized once. The schedule that wakes it was not.
Most authorization records approve an agent and stop there. When that agent runs unattended on a timer, a cron schedule, or an external event, a second decision exists and is almost never written down: who decided the run should happen, why it must happen without a person present, and when anyone will ask whether it still should. Complete this section once per standing trigger attached to the agent.
TRIGGER DEFINITION
The timer, schedule, or external event that starts an unattended run, recorded in the form the platform stores it, together with the action it starts.
CONSEQUENCE OWNER
Full name and title of the person accountable for what the unattended runs cause. Distinct from the Technical Owner who configured the trigger and from the Business Sponsor who approved the agent.
ACTIVATION JUSTIFICATION
One sentence stating why this run must occur without a person present, and what fails if it does not.
TRIGGER REVIEW DATE
The date the organization will confirm the run still needs to exist. Separate from the agent's Next Scheduled Review Date, because an agent can remain justified while a schedule attached to it no longer is.
Two operating rules
Orphaned triggers. A standing trigger whose Consequence Owner has left the organization is treated as an unauthorized deployment from the date of departure, suspended until a new owner signs. Reassigning the agent does not carry the trigger. Authority to run and authority to begin running are separate grants, and this section records the second one.
Offboarding. The offboarding checklist lists every standing trigger the departing person configured and reassigns each by name before final-day access is removed. A trigger that reaches the departure date unassigned is suspended, not inherited.
Limitation
This section records who authorized a run to begin and when that authorization expires. It cannot prove the run still serves the purpose stated, and it does not surface triggers the organization has never enumerated.
The standing trigger clause was introduced in The Governance Gap, "The Agent Was Authorized. The Schedule Never Was.", August 11, 2026.
ROLE MAPPING
RECORD INTEGRITY
AGENT AUTHORIZATION SEQUENCE
How to use this document
Complete one record for every agent currently deployed in your environment, starting with agents that can reach sensitive data, customer records, or financial systems.
Download the document
The template is a base, meant to be adapted into the organization's own GRC forms, not adopted verbatim. No gate. No form. Published under CC BY 4.0. Free to reproduce, adapt, translate, and use commercially, including inside your own governance program, with attribution to Sougata Roy and a link to this page. Attribution is a condition of the license. Claiming authorship is not attribution. Full terms at sougataroy.com/rights
This template is informed by accountability and oversight expectations in NIST AI RMF, OMB M-25-21, FINRA's 2026 Regulatory Oversight Report, and Article 26 of the EU AI Act. Published under CC BY 4.0. Free to reproduce, adapt, translate, and use commercially, including inside your own governance program, with attribution to Sougata Roy and a link to this page. Attribution is a condition of the license. Claiming authorship is not attribution. Full terms at sougataroy.com/rights
REVISION HISTORY
COPYABLE CITATION