Agent authorization
Agent authorization is the explicit grant under which an AI agent acts on someone’s funds: which operations it may perform, on which accounts, up to what amounts. It is scoped per relationship — a platform’s agent serving many customers holds a separate grant from each — and it is revocable at any time without touching anything else the agent does. Authentication proves which agent is calling; authorization defines what that agent is allowed to do. The two together are what make “the agent did it” an accountable statement.
By Krisan Nichani, Chief Compliance OfficerLast updated August 2026
The pattern that has emerged is invite-and-approve: the party whose money will move is asked, sees exactly what is being requested — permissions, per-transaction caps, duration — and grants or declines. The grant is recorded, and every later payment traces back to it, which is what an auditor will ask for when software moved customer funds. Broad, standing, implicit authority is the anti-pattern; it turns the first bug into a question about every payment the agent ever made.
This is the agentic version of a problem payments has solved before — direct debit mandates and open-banking consents are authorization records for earlier kinds of automated money movement. On Infinite, moving money for customers is the third-party funds flow: customers are onboarded and verified, and the authority a platform or its agent acts under is documented as part of the flow.
Frequently asked questions
What is the difference between authentication and authorization for an AI agent?
Authentication is identity: the credential proves which agent is calling. Authorization is permission: the recorded grant saying what that agent may do with whose money, and up to what limits. A stolen credential fails at authorization if the grant is scoped tightly.
Can a customer revoke an agent’s authorization?
Yes — revocability is the point. A grant is per-relationship, so a customer can withdraw their agent’s authority without affecting other customers, and the platform can do the same from its side. Payments after revocation simply fail authorization.
What should an agent authorization specify?
Four things at minimum: the operations permitted, the accounts in scope, the amount caps per transaction and period, and how it ends — expiry or revocation. Anything the grant doesn’t name, the agent shouldn’t be able to do.
See how it works on the network.
Book a 30-minute demo and see how Infinite moves money — instant, compliant, and global.