3.16.1.2 P-Agent-On-Behalf-Of Header

When a client endpoint makes a call on behalf of an identity, it MUST use the P-Agent-On-Behalf-Of header.

The server endpoint SHOULD validate that the user has the permission to make on-behalf-of requests.