
What is AI agent identity?
An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.
5 posts

An AI agent that borrows a person's token or a shared API key cannot be limited, audited or stopped on its own. Here is what an identity for an agent consists of.

An agent will try whatever its input tells it to. A boundary limits what it can reach, for how long, and where the limit is enforced so the agent cannot argue with it.

Where authentication sits in an agent's tool call, how OAuth-based authorisation works for MCP, and why a token must never be passed through to the API behind a tool.

Some actions should not be an agent's decision alone. How to pick them, and how to design approval requests that people actually read before they answer.

An audit record should answer who did what, on whose behalf, from where and with what outcome. How to design the fields, make it tamper-evident and keep it searchable.