AGENTS & MACHINE IDENTITIES

Machine trust needs identity, delegation, and an owner.

An agent is not a human account with a clever display name. It is a distinct software subject whose authority must be granted, narrowed, observed, and revoked.

01Register a subject and accountable sponsor
02Attest the runtime or execution context
03Issue short-lived, audience-bound authority
04Observe, revoke, and retire cleanly
01

More than agents

Applications, services, workloads, devices, automation, agents, and tools all need identities suited to their lifecycle. Some live for years; others should exist for a single task.

02

Delegation that cannot grow silently

Every handoff should preserve the owner, acting subject, intended audience, resource, permitted action, purpose, and expiry. Downstream tokens should narrow authority, never enlarge it.

03

Receipts for autonomous action

Sensitive actions should leave an inspectable record of the request, policy, evidence, delegation chain, outcome, and the point where a person can intervene.

Explore the security model