Confused deputy · Highflame Glossary

Confused deputy

An attack where a low-privilege agent tricks a higher-privilege one into acting on its behalf. Scope attenuation prevents it: a sub-agent provably cannot exceed its parent's authority.

Learn more: Agent Authorization

Part of the Agent Control Fabric: Highflame's identity, policy, and enforcement substrate for AI agents.

Keep exploring the glossary.

[**Delegated authority**
The model where an agent acts on behalf of a human or another agent, holding strictly less authority than the principal that authorized it, and provably distinct from that principal.
Read →](/content/glossary/delegated-authority/index.html) [**Delegation depth**
How many on-behalf-of hops a credential sits from its original human authorizer. Highflame enforces depth as a first-class policy primitive.
Read →](/content/glossary/delegation-depth/index.html) [**DPoP**
Demonstrating Proof-of-Possession (RFC 9449): binds a token to a proof key so a stolen token is inert without it.
Read →](/content/glossary/dpop/index.html) [**Enterprise Managed Authorization (EMA)**
An MCP extension that lets a company's identity provider decide, through corporate SSO, which MCP servers an agent may connect to. It governs admission, not what the agent does once inside.
Read →](/content/glossary/ema/index.html) [**Guardrails**
Inline detection and enforcement on an agent's prompts, tool calls, and responses: blocking unsafe actions in real time.
Read →](/content/glossary/guardrails/index.html) [**ID-JAG**
Identity Assertion JWT Authorization Grant. After SSO, the identity provider evaluates policy and issues an ID-JAG, which an MCP client exchanges for a server access token: the mechanism behind Enterprise Managed Authorization.
Read →](/content/glossary/id-jag/index.html)