Skip to content
Pre-Launch · Wyoming · 2026

The Authority Wall

Healthcare solved delegated authority decades ago. The agents merely have to catch up.

Mitchell McLennan

Founder · Wavestar Holdings · August 25, 2026 · 2 min read

Everyone in health technology is shipping agents that act on a patient's behalf. Almost none of them can answer the only question that will matter the first time one goes wrong: who authorized this, and can you prove it?

The easy half was solved while nobody was looking. Patient identity has federal standards and functioning infrastructure: TEFCA for exchange, FHIR for access, UDAP for credentials, and information-blocking rules with genuine penalties attached. CMS-0057 obliges the large payers to expose patient access, provider access, and prior authorization through APIs by 2026 and 2027. If your agent needs to establish who the patient is and read the chart, the rails exist. They are slow, bureaucratic, and faintly ugly, but they are real.

The hard half is different in kind. An agent that reads a record is a query. An agent that acts, that renews a prescription, books the procedure, files the claim, is exercising delegated authority. American healthcare already possesses a mature model of delegated authority. It is called the prescription.

Consider what a prescription actually carries:

A scoped grant. This drug, this dose, this many refills. Never "access to my health."

A named authorizer. The prescriber, NPI attached, license on the line.

A complete audit trail. Written, transmitted, dispensed; every hop logged.

Revocability. The prescriber can cancel, and the pharmacy checks again before filling.

One accountable human at the end of the trail, the one who gets woken when something goes wrong.

That is the entire shape of agent authorization: scoped grant, named authorizer, revocable, logged, one accountable human. The clinic solved this problem with paper and signatures decades ago. Software agents require the same five properties, plus a machine that verifies them at speed.

Why, then, is half the industry rebuilding identity? Because identity is fundable. It demonstrates well in a pitch deck. Authorization is legal work, and legal work does not screenshot. Nearly every "verify the patient" pitch you will sit through this year is the easy half wearing the hard half's clothes.

The working version is a consent ledger: boring, append-only, no blockchain required. Each entry binds five fields: the agent, the scope, the human who signed, the expiry, and the revocation handle. When the agent acts, the counterparty, be it pharmacy, payer, or clinic, consults the ledger exactly as a pharmacist consults a prescription. No entry, no action. Grants expire on schedule; the signer can kill one from a phone.

This ceased to be theoretical in the spring. Utah's Department of Commerce signed an agreement permitting Legion Health's AI to renew certain psychiatric prescriptions under state supervision, with audit requirements attached. Read that again: a software agent exercising clinical delegated authority while a regulator watches. The prescription model, extended deliberately to software. Meanwhile the identity crowd debates the lock while Utah tests the door.

None of this requires new technology. Scoped tokens, signed consents, append-only logs: all of it sits on the shelf. What it requires is a party willing to put its name on the grant and carry the liability. That is the actual moat. The builders who matter over the next two years will not be the ones with the cleanest identity stack. They will be the ones who made authorization boring: scoped, signed, logged, revocable, and owned by one human who answers the phone.

The technology is trivial. The liability is the product. Whoever renders the liability legible climbs the wall first.

Originally published on

mitchellmclennan.substack.com

Subscribe

Get the next essay in your inbox.

Delivered via Substack. Unsubscribe from the first message if it isn't for you.