Architecture · plane 5

Agent identity: the plane that bounds autonomy

An agent touching production needs answers to questions we solved for humans decades ago — and never solved for software acting on its own behalf. Identity is what turns 'an agent did something' into 'this agent, authorized by this principal, executed this scoped action, and here is the evidence.'

The short answer

Every agent operating in the platform carries a first-class identity: attributable (we know who acted), scoped (we know what it may touch), time-bounded (authority expires), delegable with attenuation (it can never grant what it does not hold), and auditable (every action joins its trace). Identity is the difference between autonomy and chaos.

The eight questions every agent must answer

Who are you?
A named, registered agent identity — not a shared service account, not a human's token, not "default".
What can you access?
An explicit permission set scoped to the action classes this agent is authorized for — nothing broader.
On whose behalf are you acting?
A delegated principal. The trace shows both: the agent that acted and the human or system whose intent it executed.
What environment can you modify?
Bounded scope: staging but not prod, this tenant but not that one, this region but not everywhere.
How long does your authority last?
Time-bounded, purpose-bound credentials. Long-lived agent API keys are a design failure.
Can you delegate?
Delegation chains with attenuating permissions — an agent can never grant more authority than it holds.
What action did you perform?
Every action attributed to the identity that took it, joinable to its decision trace.
Can it be audited?
Yes — retroactively, from evidence the platform recorded at action time, not from reconstructing chat logs.

Why is identity its own plane now?

Because for the first time, software acts on its own initiative inside engineering platforms. Workload identity (the SPIFFE family of ideas) solved "this service is who it says it is" for service-to-service calls. Human IAM solved "this person may do these things." Agent identity combines both and adds a third dimension: delegation from an intent-holder. The agent is not the principal — it executes the principal's intent, and the platform must be able to reconstruct that chain months later, when an auditor or an incident review asks who authorized what.

The industry conversation agrees: as platform teams absorb responsibility for agent infrastructure, identity, credentials, and auditability are consistently named as expanded platform duties. This page exists because the four-layer sense-think-act models — including earlier versions of our own — left identity implicit. Implicit identity is how you end up with an agent holding a human's long-lived token doing things nobody can explain.

What does good agent identity look like in practice?

  • →Registration: agents are onboarded like employees — named, owned, purpose-declared, revocable.
  • →Short-lived credentials: tokens minted per task or per session from an identity authority; nothing reusable sleeping in config files.
  • →Least-privilege per action class: the agent that proposes refactors does not automatically hold deploy-to-prod.
  • →Separation from human identity: an agent never authenticates as a person; delegation is explicit, not borrowed.
  • →Joinable records: identity events, policy decisions, and action traces share keys, so the whole story assembles from one query.

What happens without it?

Every subsequent control degrades. Policy cannot bind rules to "this agent class" if agents are anonymous. Observability records "something acted." Approval workflows approve a request with no verified requester. Rollback works but accountability doesn't. And the first security review ends the program. Identity is not a feature of an agentic platform; it is the precondition for being allowed to have one.

Ready for the leap?

Partner with Adventure On The Wave to build governed, agentic platform capability — architecture, guardrails, and the human authority model to match.

A strategic initiative by Adventure On The Wave