On this page

Pattern: Agent Identity & Scoped Credentials

Every agent gets its own identity, owner, bounded scope and expiry before it acts, so its actions are attributable and its access revocable.

Layer 04 · Runtime Controls & Observability In the chapter 05 catalogue

Summary: Give every agent its own identity, an owner, a bounded scope and an expiry, established before it acts, so that its actions can be attributed, its access revoked precisely and its scope contained. Identity is the precondition of accountability; scope is the precondition of containment.

Agent Identity & Scoped Credentials A sequence diagram generated by Archify. register at deploy owner, scope, expiry issue scoped credential call with credential verify scope, respond log attribution expires with entry Register at deploy Issue scoped credential Call and verify scope Attribute and expiry Deploy pipeline · registers at deploy · Sequence participant Deploy pipeline registers at deploy Agent registry · owner, scope, expiry · Sequence participant Agent registry owner, scope, expiry Identity issuer · workload identity · Sequence participant Identity issuer workload identity Agent · scoped credential · Sequence participant Agent scoped credential Downstream tool · channel auth · Sequence participant Downstream tool channel auth Audit log · signed per identity · Sequence participant Audit log signed per identity Legend request return async trace default message
Agent Identity and Scoped CredentialsAn agent receives a short-lived, scoped credential from its registry entry at deploy time, and every downstream call is verified and attributed in the audit log. No registry entry, no credential, no access. Generated from the Body of Knowledge.Open interactive diagram (opens in a new tab)

Objectives

Make every non-human actor governable by construction: attributable, scopable, revocable, expiring.

Target users

AI governance engineer, security engineer, IAM/platform team.

Impacted stakeholders

Model owners, security operations, auditors, affected third parties.

Relevant principles

Register and bound every actor before it acts; start from a named failure mode or harm.

Context

Agents that act under delegated authority (calling APIs, tools and other agents), where the default is a shared service account or a static key.

Problem

An agent on borrowed credentials cannot be attributed, contained or revoked. NIST’s NCCoE frames the open question directly: how do identification, authentication and authorization apply so each agent is “known, trusted, and properly governed”, with non-repudiation and tamper-proof logging1.

Solution

Issue each agent a distinct workload identity with a declared scope, an owner and an expiry, recorded in the Agent Registry. Keep two questions separate. Channel authentication secures one hop: how a client authenticates to a tool server; the MCP specification of 2026-07-28 tightened exactly this, deprecating Dynamic Client Registration in favour of Client ID Metadata Documents and binding credentials to their issuer2. That hardens the MCP connection but is not the agent’s identity. Agent workload identity is the durable, attributable identity the agent carries across every hop and protocol, under which its actions are logged and its access revoked: the job of a workload-identity system (SPIFFE/SPIRE) or a first-class agent identity from an enterprise provider (for example Microsoft Entra Agent ID 3 or Okta Agent SSO4; illustrative), recorded in the registry, not of the transport protocol. Secure the channel and issue the workload identity; scope its credentials to the least privilege the agent’s declared function needs.

Consequences

Attribution, containment and precise revocation become possible, and the kill switch has something to act on. The cost is IAM integration and managing non-human identities at scale.

Agent Registry; Kill Switch / Circuit Breaker; Policy Card; Human-in-the-loop Gate.

Maps to: EU AI Act Art. 12, Art. 14, Art. 15 · ISO/IEC 42001 · NIST AI RMF (Manage) · CSA AICM · OWASP Agentic ASI03 · Layer 04 Runtime Controls & Observability.

Threat IDs follow the OWASP Top 10 for Agentic Applications 2026 5 and function labels the NIST AI RMF6. Mappings are illustrative, not a claim of conformity.

Sources

  1. [1] “Accelerating the Adoption of Software and AI Agent Identity and Authorization” (concept paper; “known, trusted, and properly governed”; non-repudiation, tamper-proof logging). NIST NCCoE. 2026-02-05. https://www.nccoe.nist.gov/news-insights/new-concept-paper-identity-and-authority-software-agents (verified: primary)
  2. [2] Model Context Protocol specification 2026-07-28 (DCR deprecated in favour of CIMD; issuer-bound credentials). MCP. 2026-07-28. https://blog.modelcontextprotocol.io/posts/2026-07-28/ (verified: primary)
  3. [3] Microsoft Entra Agent ID (first-class agent identity; OAuth 2.0, MCP, A2A). Microsoft Learn. 2026-04. https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id (verified: primary)
  4. [4] “Okta brings first-class identity to AI agents with Agent SSO” (GA 24 Aug 2026; Cross App Access as MCP EMA extension). Okta. 2026-08-24. https://www.okta.com/newsroom/press-releases/okta-brings-first-class-identity-to-ai-agents-with-agent-sso/ (verified: primary)
  5. [5] Top 10 for Agentic Applications 2026 (ASI IDs). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
  6. [6] AI Risk Management Framework (AI RMF 1.0; Govern, Map, Measure, Manage). NIST. 2023-01-26. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
Edit this page on GitHub
Cite this pattern

García Aibar, J. (2026). Pattern: Agent Identity & Scoped Credentials. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), chapter 05, Patterns. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials. CC BY 4.0

BibTeX

@misc{aige2026bok,
  author  = {Jorge García Aibar},
  title   = {{AI Governance Engineering: The Thesis \& Body of Knowledge}},
  chapter = {05. Patterns: Agent Identity \& Scoped Credentials},
  year    = {2026},
  version = {0.5.0},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials},
  note    = {Version 0.5.0}
}
Share on LinkedIn