{"uid":"cap_wPNP8wwULQ2mvMJQZzPDo","slug":"delegation-scope-guard-254d663a","name":"Delegation Scope Guard","description":"Validate least-privilege capabilities, data scope, destinations, budget and expiry before agent-to-agent delegation","url":"https://phion.systems/v1/paid/trust/delegation-scope-guard","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema"},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_1jGYcKOKbxjDbLlo54qMG","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates least-privilege capabilities, data scope, destinations, budget, and expiry constraints before one agent delegates to another agent","exampleAgentPrompt":"Before handing this task off to the summarization sub-agent, check that it only has read access to the customer data scope, can only send results back to my orchestrator endpoint, is capped at $0.50 budget, and expires in 30 minutes.","exampleUseCases":[{"title":"Least-privilege check before sub-agent spawn","prompt":"I'm about to delegate a data extraction task to a sub-agent — can you verify that it's only authorized for read-only access to the billing records scope, destinations are restricted to our internal API, the budget cap is $1.00, and the delegation expires in 1 hour?"},{"title":"Multi-hop delegation chain safety","prompt":"We're passing a task through three agents — check that none of them are being granted more capabilities than they declared upfront, the data scope stays within EU customer records only, and no agent in the chain can exceed a $2.00 total spend."},{"title":"Time-bounded autonomous agent task","prompt":"Before my research agent starts working overnight, validate that its delegation only allows web search and document summarization capabilities, it can't send data anywhere except my Slack webhook, the budget is capped at $5, and it automatically expires at 6am tomorrow."}],"resultDescription":"Returns a structured validation result indicating whether the proposed delegation is approved or rejected, along with a list of any policy violations found (e.g. over-privileged capabilities, out-of-scope destinations, exceeded budget, expired or missing expiry), and the validated scope parameters that were approved.","failureModes":["Missing required delegation parameters returns a validation error listing absent fields","Budget value exceeds policy ceiling causes rejection with budget violation detail","Destination not in allowed list triggers destination scope violation","Capabilities requested exceed declared least-privilege set returns over-privilege error","Expired or missing expiry timestamp causes delegation rejection with expiry violation","Malformed input schema returns 400-level error","Service unavailable returns 503 with no validation result"],"whenToPreferThis":"Choose this endpoint when you need to enforce structured, policy-driven constraints on agent-to-agent delegation before execution — particularly when budget caps, expiry windows, data scope boundaries, and destination allowlists must all be validated together in a single preflight check. Prefer this over ad hoc in-agent logic when operating in multi-agent orchestration environments where least-privilege delegation is a security requirement, or when audit trails of delegation approval decisions are needed.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:50:26.210Z","isFirstParty":false}