Agent Identity & Scoped Credentials

Agent Identity & Scoped Credentials A sequence diagram generated by Archify. register at deploy owner, scope, expiry issue scoped credential call with credential verify scope, respond log attribution expires with entry Register at deploy Issue scoped credential Call and verify scope Attribute and expiry Deploy pipeline · registers at deploy · Sequence participant Deploy pipeline registers at deploy Agent registry · owner, scope, expiry · Sequence participant Agent registry owner, scope, expiry Identity issuer · workload identity · Sequence participant Identity issuer workload identity Agent · scoped credential · Sequence participant Agent scoped credential Downstream tool · channel auth · Sequence participant Downstream tool channel auth Audit log · signed per identity · Sequence participant Audit log signed per identity Legend request return async trace default message

Identity before action

  • • Each agent carries a distinct workload identity, not a shared account
  • • The registry entry sets its owner, scope and expiry
  • • No registry entry, no credential, no access

Scope and channel kept apart

  • • Channel authentication secures one hop to a tool
  • • Workload identity is the durable identity carried across every hop
  • • Credentials are scoped to the least privilege the agent's function needs

Attributable and expiring

  • • Every call is logged under the agent's own identity
  • • Credentials are short-lived and expire with the registry entry
  • • The kill switch then has something to act on