
Or Weis
When AI Subagents Call MCP Tools, Who Owns the Permission Decision?
Subagents are delegated actors, not implementation details. This guide explains how to design MCP permission delegation, OAuth token brokering, approval routing, and audit trails to avoid silent stalls and privilege expansion.











