Five Rules for Agent Identity
None of this is new. It's the same discipline identity and access management has applied to humans for decades, pointed at a new kind of actor. What's different here is that each rule below links straight to the actual control that enforces it — not a slide, a real gate in the product.
Every agent is provisioned its own identity at creation. Reusing an existing service account isn't a shortcut — it's the fastest way to destroy attribution the moment two agents share a credential.
An agent isn't accountable to itself. A specific person has to be willing to answer for why it exists and what it's permitted to do — not a team distribution list. A person.
An agent holds only the access its current task requires — reviewed against what it actually uses, not what it was granted on day one and never revisited.
What an agent actually did — not what it was asked to do — belongs in a log it cannot edit or delete. Prompts show intent. Actions show consequence.
If disabling one agent risks breaking three others, credentials were shared somewhere they shouldn't have been. Revocation should be immediate, surgical, and boring.
The same seven-step cycle behind every Agent Passport on this site — it closes, and starts again at recertification.
Curious what these five rules look like as a real record, not a rule of thumb?
See a worked Agent Passport →© 2026 Aseem Mohan · Control library · Methodology · Assessment