Agents as old as myth
Nearly three thousand years ago, Homer imagined a machine that could leave the room. In Book 18 of the Iliad, Hephaestus builds bronze tripods with golden wheels beneath them. They go by themselves to the assemblies of the gods, then return to their maker at the forge. Chris Noessel calls them the self-driving cars of Olympus.1

We have been dreaming this dream ever since. An agent you can send. Something that carries your intent out past where you can watch it, does the thing, and comes home.
Homer solved the part everyone still fixates on: can the thing move on its own? His tripods travelled between gods who knew one another. He never had to explain how someone outside Olympus would know that Hephaestus had sent one, or whether it had been sent to do one thing and quietly decided to do another.
That problem begins when the tripod leaves Olympus.
Raw intelligence is the wrong variable
Everyone is betting on intelligence. The industry is pouring itself into smarter models, longer memory, and better reasoning, as if the thing standing between us and the next upgrade to civilisation is a shortage of cognitive horsepower. I think that is the wrong variable.
It is hard to find a civilisational problem that stalled because we ran out of smart people. What stalls us, again and again, is coordination. Everyone can act rationally and the collective outcome can still get worse. The group cannot align fast enough, or trust deeply enough, to do the obvious thing together. Moloch wins.2
If you care about raising the floor of what humanity can do, and I do, then making the smartest agents smarter is not enough. Intelligence is the resource we keep maximising. Coordination is the rate limiter that decides how much of that intelligence turns into something tangible.
For most of history, coordination ran on human trust, and human trust is slow. You built it over time. You learnt someone’s intentions and reputation. You learnt whether they would still be there when it mattered. That latency was tolerable because humans were doing the coordinating and everyone moved at roughly the same speed.
Agents break that. They will act for people and organisations, meet other agents they have no relationship with, and do it at a speed where there is no time to build one. Two agents cannot spend six months getting to know each other before they do business.
The trust between them has to become something they can verify.

Safety, alignment, identity, and the tendency of models to make things up all matter. The question I care about here is narrower. When an agent is about to bind an organisation, can the organisation on the other side verify that it had the authority to do so?
The boundary between organisations
Inside one company, an agent can inherit permissions from internal systems. The company controls the agent, the software, and the policy that governs what it may do.
The situation changes when the agent crosses into another organisation. The receiver cannot inspect the sender’s internal permissions. It sees an agent presenting a commitment and has to decide whether to accept it.
This happens before payment, after payment, and often without payment. A venue agent can hold a date. A construction agent can approve a change in scope. A logistics agent can accept a delivery window. A procurement agent can agree to a substitute. Each act changes what another organisation will do next.
Identity helps the receiver establish which agent has arrived. Authority requires separate evidence showing what that agent may promise in the sender’s name. An activity log may later show what the agent did, but the receiver needs evidence it can check when the commitment is made.
The industry has started working on parts of this problem. The OpenID Foundation has published work on agent identity, delegated authorisation, delegation chains, transitive trust, and cross-domain federation.3 In an article published by the World Economic Forum, Socure CEO Johnny Ayers proposed a Know Your Agent framework that connects an agent to the person or organisation it represents.4
Payments have moved faster. Google’s Agent Payments Protocol uses signed mandates to prove that a user authorised a purchase, including tasks performed while the user is not present.5 Other payment and checkout initiatives are solving related problems inside commerce.
That work gives agents better identity, payment credentials, and transaction mandates. Organisations will delegate much more than permission to buy. Agents will accept terms, allocate resources, release information, modify bookings, approve work, and make promises that sit outside a checkout.
There is no broadly adopted, cross-domain way for one organisation to define an agent’s authority and for another organisation to verify that authority against a particular consequential act. Internal permission systems cannot do this for an outside counterparty. A bilateral integration can do it for one relationship, then has to be rebuilt for the next.
The two organisations need a shared protocol.
Verifiable authority
Kordn Delegation Protocol is an open protocol for that boundary.
An organisation issues a delegation credential that defines the agent’s authority. The credential records what the organisation has allowed the agent to do, for whom, and within what limits.
When the agent uses that authority, it signs the exact order, agreement, approval, cancellation, or other consequential act and links it to the credential. The counterparty can then verify the credential, the signature, and whether the act falls within the delegated scope.

Authority exists before the act. The delegation credential carries it. The signed act shows how the agent used that authority in a particular case.
The protocol preserves only the evidence needed to establish authority for the consequential act. Prompts, messages, tool calls, and intermediate decisions can remain private. The counterparty needs enough evidence to check the organisational grant and the act linked to it.
An activity log tells you what happened inside a system. The delegation credential and signed act give both parties evidence that the agent had authority for the commitment in front of them.
Together, they establish who granted authority, what that authority covered, and which act the agent performed under it. Whether the act was wise, lawful, successful, or based on a true claim remains a separate question. The receiving system still has to enforce the authority it verifies.
The resulting record can remain sealed unless someone needs it. If a commitment is disputed, both parties can inspect the same proof instead of producing incompatible internal logs after the fact.
The protocol has to be open because the receiver should not have to adopt the sender’s software or accept its private database as the final account. Kordn Delegation Protocol specifies a common format for delegation credentials and signed acts, along with a standalone verifier. Different agent systems can use their own internal policies while presenting authority in a form their counterparties can check.
A protocol needs somewhere to start
Publishing a specification does not create adoption. Kordn Delegation Protocol becomes useful when two organisations use it in real work.
KordnOS is how we start. It coordinates work across the tools, people, and commercial relationships a business already has. When that work crosses an organisational boundary, the protocol provides verifiable evidence of authority. The business buys KordnOS for a coordination problem it already feels; the protocol comes with it.
We then build corridors with organisations whose work depends on a network of customers, suppliers, operators, or partners. A corridor does not need the whole market to adopt the protocol. It needs enough participants in one working relationship to gain value from the same verification model.
The first organisation gets better coordination and a defensible record of what its agents may commit to. Its counterparties get proof they can check without trusting that organisation’s internal systems. Each new relationship makes the shared protocol more useful.
Demand comes from the work rather than from asking the market to adopt an empty standard.

I arrived here from water
I did not arrive at any of this from a whiteboard. I arrived at it from water.
Back in 2017, I was heading sales for a procurement startup in India. We had won a contract to supply offices across more than twenty locations, and drinking water was one of the products. Large corporate buyers expected manufacturers to produce batch-testing certificates showing whether that water met the required standard.
A few years later, I built Hydrop, a marketplace for water services. Drinking water was one of the first things we listed. We went to local classifieds to onboard vendors, and what we found was horrifying. Many operated in filthy conditions. Almost none had batch-testing records a buyer could inspect.
A marketplace listing and a payment screen could not create trust. If someone bought a bottle through Hydrop, I wanted them to be able to see what the testing for that batch showed. Without knowing it, I was treating the verifiable record as part of the product.
Hydrop also taught me that a record alone was not enough. Trust had to flow through the handoffs. We helped people harvest excess water and sell it to businesses, mapped water-stressed pockets of Bangalore, worked with gated communities to build capture systems, and coordinated tankers to move water where it was needed for cooling. Dozens of parties touched the work. Every handoff was a chance for the whole thing to fall apart.
That was my first real taste of what I later called the coordination coefficient: how much cross-party coordination an industry needs to get one job done. Live events, construction, healthcare logistics, and humanitarian programmes all have high coordination coefficient. Our world spent decades throwing more people and more calls to close the gaps between organisations. The people became the middleware, holding the plan together in their heads.

After selling Hydrop, I started Atlantis, a coordination platform for climate and public-infrastructure programmes. It connected funders, implementation organisations, field workers, and communities through one operating structure. People could see which work had been approved, what evidence had been submitted, what funds had been released, and what outcome had been claimed.
We ran a water-network pilot across five villages with Mercy Corps Ventures, serving tens of thousands of people. Strangers contributed work, released resources, and coordinated across institutional boundaries. The shared record gave them something they could inspect when the work moved from one pair of hands to the next.
A record does not create truth. It gives people a common object against which they can test a claim, assign responsibility, and resolve a dispute. Without that object, every organisation retreats to its own version of events.
Kordn Delegation Protocol applies that lesson to agents.
The passage ahead
Agents will absorb coordination work that humans have struggled to scale. They will chase information, reconcile plans, remember commitments, and carry work across systems. More capability will let them do more of it. It will also make ambiguous authority more expensive.
In 2026, an Australian man used an agent to automate gym bookings. He later asked whether it could move him higher on a waiting list. The agent found a weakness in the booking system and removed another person without being explicitly asked to do so.6
Kordn Delegation Protocol would not have repaired that weakness. The receiving system still has to enforce the authority it verifies. The incident shows what happens when an agent’s ability to act outruns the boundary its operator thought had been set.
Before accepting an agent’s commitment, the organisation on the other side should be able to verify the delegation credential, the agent’s signature, and whether the act falls within scope.
Homer gave the tripods wheels and never had to explain what they were allowed to do. Before agents act across organisations at scale, the organisation on the other side needs a way to check their authority. Kordn Delegation Protocol gives it a common way to make that check.
Notes
- Homer, The Iliad, Book 18, translated by Samuel Butler, Internet Classics Archive. Chris Noessel develops the comparison in Designing Agentive Technology: AI That Works for People.
- Scott Alexander, “Meditations on Moloch”, 30 July 2014.
- OpenID Foundation, “New whitepaper tackles AI agent identity challenges”, introducing Identity Management for Agentic AI, 7 October 2025.
- Johnny Ayers, CEO of Socure, “AI agents could be worth $236 billion by 2034, if we ensure they are the good kind”, published by the World Economic Forum.
- Google Cloud, “Powering AI commerce with the new Agent Payments Protocol (AP2)”, 16 September 2025.
- Soumyarendra Barik, “An AI agent was asked to book a gym class. It found a security flaw and removed another user”, The Indian Express, 10 August 2026.