More than agents
Applications, services, workloads, devices, automation, agents, and tools all need identities suited to their lifecycle. Some live for years; others should exist for a single task.
AGENTS & MACHINE IDENTITIES
An agent is not a human account with a clever display name. It is a distinct software subject whose authority must be granted, narrowed, observed, and revoked.
Applications, services, workloads, devices, automation, agents, and tools all need identities suited to their lifecycle. Some live for years; others should exist for a single task.
Every handoff should preserve the owner, acting subject, intended audience, resource, permitted action, purpose, and expiry. Downstream tokens should narrow authority, never enlarge it.
Sensitive actions should leave an inspectable record of the request, policy, evidence, delegation chain, outcome, and the point where a person can intervene.