Role-based access control tells you whether an agent is allowed to run a tool. It does not tell you whether it should run that tool for the task at hand.
Databricks is proposing a fix. In a July 23 blog post, the company described intent-based authorization for its Omnigent agent framework. This “contextual policy” ties an agent’s session to a declared purpose and checks every tool call against it.
Each action gets one of three verdicts: allowed if it fits the stated purpose, escalated for human sign-off if sensitive, or denied if it falls outside scope. A single denial overrides other checks. As Databricks frames it, “Identity still decides what the agent may do; intent narrows that to what it may do for this task.”
The control includes a delegation safeguard. An agent can draft its own purpose statement, but a person must approve it, and the agent cannot rewrite or widen that scope at runtime. Databricks illustrates the payoff with a self-run demo in which a prompt-injection payload hidden in table data tricks an assistant into granting external access. Without the intent check, the company says, the agent complies and logs the grant as routine.
Treat this as an emerging control pattern, not a proven standard. The claims and the attack demo come only from Databricks, and the feature’s availability is not clearly stated.
Still, the shape is useful for governance teams. Purpose-scoped grants, human-locked delegation, and per-action verdicts give auditors a way to prove why an agent acted, not just who acted.
Source: Databricks Blog



Leave a Reply