---
title: "Workload identity"
description: "The attributable identity a workload such as an agent carries across every hop, under which its actions are logged and its access is revoked, typically a short-lived, attested credential such as an…"
canonical: https://aigovernanceengineer.com/glossary/workload-identity
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Workload identity

The attributable identity a workload such as an agent carries across every hop, under which its actions are logged and its access is revoked, typically a short-lived, attested credential such as an SVID [1]. It differs from channel authentication, which secures a single hop, such as a client talking to an MCP server.

- Developed in: [ch. 23, Channel authentication is not agent identity](https://aigovernanceengineer.com/bok/governing-agents#channel-authentication-is-not-agent-identity); [ch. 04, Layer 04: Runtime Controls & Observability](https://aigovernanceengineer.com/bok/the-stack#layer-04-runtime-controls--observability)
- Chapters: [ch. 03, Values & Principles](https://aigovernanceengineer.com/bok/values-and-principles) · [ch. 04, The Stack](https://aigovernanceengineer.com/bok/the-stack) · [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [NHI](https://aigovernanceengineer.com/glossary/nhi) · [SVID](https://aigovernanceengineer.com/glossary/svid)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-workload-identity

## Sources

[1] SPIFFE overview (short-lived cryptographic identity documents called SVIDs, as X.509 certificates or JWTs; the Workload API issues and rotates them; SPIRE implementation). SPIFFE project. 2026. https://spiffe.io/docs/latest/spiffe-about/overview/ (verified: primary)
