"David E. Smith" writes:
That's more of what I was looking for. I suppose that (I'm still using PGP as my example) there could be a shared PGP key, signed by Helen and myself, where only the two of us know the passphrase, with a keyid of "David Smith <dsmith@midwest.net> on behalf of Helen Jones <helen@devnull.org>" or something similar. The obvious problem is that in sharing the pass phrase the security is weakened. (Paranoid threat model: at some point we have to decide on the pass phrase, and we are videotaped/bugged/spied upon while this takes place.)
Why bother with the shared key? You need a message from Helen describing the powers with which you are invested, signed by her key. The wonderful thing about data is that copying it is virtually free. When you issue an order on her behalf, include a copy of the signed PoA, and sign the whole thing with your key.