Service providers increasingly need to authorize human users, services, and workloads across customer-controlled identity domains, and to distinguish a principal acting for itself from one acting on behalf of another, including multi-hop actor chains. The standards response should not be a separate end-to-end protocol for every combination of principal, issuer, delegation model, and topology. The recommended architecture:
- Use OAuth Identity and Authorization Chaining Across Domains as the optional cross-domain choreography around the grant profiles.
- Align the Identity Assertion JWT Authorization Grant (ID-JAG) and the Workload Authorization Grant (WAG) on the RFC 7523 redemption invariants they genuinely share; a common JWT Authorization Grant core is a candidate extraction from that demonstrated overlap, not a foundation designed up front.
- Keep ID-JAG the human-subject profile for Cross-App Access (XAA), includ