Now that person can do it themselves, from the console, in five steps. Choose Give authority. Set it up with a short name for the organization. Add a passkey, the kind your phone, laptop or password manager already keeps. Write what the agent may do in a sentence. Read back the grant, and approve it with the passkey.
There's no DNS record, no key file and no command line.
Writing it in plain words#
The sentence is ordinary English, within a small grammar. Something like:
pay acme-supplies up to $250 per day until 31 December 2026
Delegus turns that into a grant, and then reads the grant back to you. The read-back is written from the grant itself, not from your sentence. So if the sentence said something you didn't mean, the read-back shows what will actually be signed. For the sentence above, two of the lines it gives are:
At most 250.00 USD per purchase.
At most 250.00 USD in each 24-hour period, counted from Oct 6, 2026, 12:00 UTC.
That first line is worth a second look. "$250 a day" also means no single purchase can go over $250, and the read-back says so plainly before anyone approves anything. If part of a sentence doesn't fit the grammar, it's refused. Delegus never guesses what you meant.
You approve the grant, never your words. The console keeps them apart on purpose.
What Delegus does with the key#
When you choose this path, Delegus creates a signing key for your organization in AWS KMS and publishes its public half in your organization's key document, next to any keys you add yourself. The key signs one thing, the exact grant a person approved with their passkey. An API key can't make it sign. A console session can't. Our own staff can't either. In production an organization-wide policy lets only the Delegus service use the key, and the service signs only after it has checked a passkey approval over those exact bytes.
That check is strict. The approval has to come from the console's own address, so a look-alike page fails. The device has to confirm a real person was there. A prepared grant has to be approved within ten minutes, and it can be approved once. A stolen console session can't quietly add its own passkey either, because every passkey after the first has to be vouched for by an approver who already has one. When someone leaves, an admin removes them as an approver on the Team page, for good. If a phone or laptop goes missing, that one passkey can be revoked while the person stays an approver.
Your fingerprint, face or PIN never reaches us. Neither does the passkey's private key. What arrives is a signature and a note from your device that it checked you. We keep that signature in a private approval record for seven years, with the approver's name and the fingerprint of the exact grant they approved, so there's lasting evidence of who approved what.
The grant itself is an ordinary Delegus grant. Anyone checking it, and every receipt it leads to, works exactly as before.
Your own key is still an option#
Some companies will want to hold their keys themselves, and they still can. Generate a key, sign grants with our command line tool or the SDK, and Delegus never sees the private key. If you start with a key Delegus holds and later want your own, you add your key and retire ours. A retired key stops signing but stays published, so every grant it already signed keeps checking out.
Developers get the plain words too. delegus grant compile --sentence turns a sentence into a grant's exact contents, and delegus grant explain reads any grant back in words. Both are in @delegus/sdk 0.3.2 and work offline.
What it doesn't cover yet#
Delegus can hold keys for identities it hosts, the ones that look like did:web:delegus.ai:org:your-name. A company that publishes its own key document on its own domain signs with its own keys, as before. Revoking a grant doesn't ask for a passkey yet. It still works in one step with an API key, the way it always has.
If you've been waiting for someone technical to set up your agent's limits, you can set it up in the console now.