Agent Identity
Fleeting- tl;dr
- two definitions differ in kind — a relation between declared and observed behaviour, and a credential identifying an instance; one is written from agents running transactions without continuous supervision; what it must settle runs from metadata to accountability for a bodiless entity.
- authorship
- this note is edited using Claude/default, governed by the note how to write a literature note
The subject
- what
- agent identity.
- what: what the term names.
- what: who defines it, and why.
- what: what problems its definition is meant to answer.
- what: what is proposed for doing it, and what one shipping system does.
What the term names
- what
- Otsuka, Toyoda and Leung define it as the continuous relationship between what an agent
is declared to be and what it is observed to do.1
- what: they bound that relationship by the confidence that the two correspond at any given moment.1
- therefore: on their definition identity is time-indexed and bounded by a confidence, not a fixed attribute.
- what
- Sharif, in an IETF Internet-Draft, defines it as a cryptographically verifiable credential
that uniquely identifies a specific agent instance, non-transferable and distinct from the
principal’s identity.2
- scope: that draft says of itself that it is inappropriate to cite it other than as work in progress.3
- therefore
- the two answers differ in kind — one names a relation that holds over time, the other a credential that identifies an instance.
- what
- a report prepared for the OpenID Foundation calls the concept multifaceted, reaching beyond simple user impersonation, and critical to authentication, authorization and auditability.4
- what
- Posta has it that at runtime, when an agent decides how to accomplish a task and executes
calls, a stable verifiable principal is needed.5
- scope: Posta writes for Solo.io, which sells in this market.
Whether there is a continuing thing to name
- what
- Hu and Rong hold that a corrective signal needs a body — a boundary, a locus where it
accumulates, consolidation into durable update, a substrate that alters future
action.6
- what: they hold that LLM agents, composites freely swapped, copied, reset and reassembled, meet none of those.6
- therefore
- the two accounts pull apart — one identifies a specific instance, the other has the composite freely swapped and reassembled.
- what
- they call pairing each agent with an identifiable human or organizational principal the thin response.7
- what
- they hold that until architectures coupling consequence to agency exist, high-stakes deployment should stay tethered to accountable human principals.9
- scope
- they write from Oxford and New York University Shanghai, not from a vendor in this market, and the paper is an arXiv preprint.
Whether it is a layer of its own
- what
- Posta asks whether agent identity is a new thing on top of workload identity or just workload identity, and answers yes to both.10
- what
- Posta holds that agents are not human, a human identity giving them human standing without the constraints that come with it.11
- what
- Chowdhury and Rajashekariah call it a live debate, not a settled point, turning on three invariants.12
- what
- they say that where the three hold, agent identity collapses into workload identity and no extra layer earns its place.14
- what
- they say that where the three break, it becomes a layer on top, and that they break often.14
- scope
- Posta writes for Solo.io and Chowdhury and Rajashekariah for DataRobot, both selling in this market.
Who defines it, and why
- what
- Otsuka, Toyoda and Leung give their definition writing from agents already running real transactions, workflows and sub-agent chains across organizational boundaries without continuous human supervision.15
- what
- Sharif gives the credential definition in an Internet-Draft, which addresses what identity and trust primitives the Internet requires to make agent actions safe, auditable and accountable.16
- what
- Kasselman, Lombardo, Rosomakho, Campbell, Steele and Parecki define a neighbouring term,
an Agent Identity Management System — the functions that establish, maintain and evaluate an
agent workload’s identity and permissions.17
- what: they report that efforts develop in isolation, reinventing existing mechanisms, and that the fragmentation risks incompatible implementations and duplicated effort.18
- scope: their text is an Internet-Draft too.
- scope: those six write from Defakto Security, AWS, Zscaler, Ping Identity, OpenAI and Okta, all selling into this market.
What problems its definition is meant to answer
- what
- a NIST NCCoE concept paper says the scale and autonomy of agents bring new opportunities
and new risks.19
- what: it says enterprises and individuals need to understand how identification, authentication and authorization can be applied so that agents are known, trusted and properly governed.19
- what
- Booth, Fisher, Galluzzo and Roberts ask in it how agents might be identified in an enterprise architecture.20
- scope
- it is a draft whose comment period closed on 2 April 2026, and whether another NIST document defines the term is unchecked here.
- what
- a report prepared for the OpenID Foundation says the traditional service account is
insufficient for the lifecycle and governance needs of agents.21
- what: it says identity vendors have started, on that recognition, to treat agents as first-class entities.21
- what
- « Know Your Agent » names a neighbouring practice; what problem its users say it solves, and whether an agent can be known at all, are treated in know your agent.
- what
- Otsuka, Toyoda and Leung put the difficulty as identifying, verifying and holding accountable an entity with no body, no persistent memory and no legal standing.22
What Otsuka, Toyoda and Leung find missing
- what
- they evaluate current technical and regulatory documents against the identity requirements of autonomous agents.23
- what
- they find none adequately addresses governing nondeterministic, boundary-crossing entities.23
- what
- they identify five critical gaps, among them recursive delegation accountability and agent identity integrity.24
What the identity is asked to carry
- what
- the concept paper asks what metadata an agent’s identity needs, whether that metadata should be ephemeral or fixed, and whether identities should be tied to hardware, software or organizational boundaries.25
- what
- Posta says the runtime principal is used to make authorization decisions, attribute actions to the agent, and revoke it.26
- what
- a report prepared for the OpenID Foundation says a traditional workload’s identity
confirms what it is, where an agent’s behaviour matters too.27
- what: it says the identity must be enriched with metadata about the model, version and capabilities, to enable risk-based access control.27
- what: it says the identity must be portable and verifiable to a third party with no visibility into the agent’s host environment.28
- scope: what that report is and what it is worth are set out in identity management for agentic ai.
- what
- Otsuka, Toyoda and Leung compare human and AI identity on substrate, persistence,
verifiability and legal standing, and report the asymmetry as fundamental.29
- what: they report that extending a human framework to an agent without structural change produces systematic failures.29
- scope
- Posta writes for Solo.io, which sells in this market.
The path argued as the central object
- what
- Kaptein, Khan and Podstavnychy formalize a compliance policy as a deterministic function from agent identity, partial path, proposed next action and organizational state to a violation probability.30
- what
- they argue the execution path is the central object for effective runtime governance.31
- therefore
- on their account identity is one input to that function, not the central object for effective runtime governance.
- what
- on their account static access control ignores the path, and so accounts only for a subset of all possible paths.32
What is proposed for doing it, and what one shipping system does
- what
- Kasselman, Lombardo, Rosomakho, Campbell, Steele and Parecki stack the components of their management system, each layer depending on guarantees the one below it gives.33
- what
- Sharif stacks five layers of agent trust, each depending on the ones below and serving the ones above, and each answering one question.34
- scope
- both are Internet-Drafts proposing a shape, and neither claims a deployment.
What one shipping system binds to
- what
- in Amazon Bedrock AgentCore a Cedar policy names a principal, the entity making the authorization request.35
- what
- it supports two principal types, one for OAuth-authenticated users and one for IAM-authenticated callers.36
- therefore
- neither of the two is the agent.
- what
- an IAM principal carries the caller’s IAM ARN, which for an assumed role names the role and enables stable equality matching.37
- what
- a temporal policy conditions on what happened earlier in the same policy session.38
- scope
- the source is AWS documenting its own product, and is undated living documentation.
Permalink
-
« We define AI Identity as the continuous relationship between what an AI agent is declared to be and what it is observed to do, bounded by the confidence that those two things correspond at any given moment. » — Takumi Otsuka, Kentaroh Toyoda, Alex Leung, abstract, AI Identity: Standards, Gaps, and Research Directions for AI Agents, 25 April 2026, arXiv preprint, primary (). ↩︎ ↩︎
-
« Agent Identity: A cryptographically verifiable credential that uniquely identifies a specific agent instance. Agent identity is non-transferable, non-repudiable within its validity period, and distinct from the identity of the principal. » — R. Sharif, Terminology, Agent Identity Framework: Trust and Identity for Autonomous AI Agents, CyberSecAI Ltd, 6 April 2026, Informational Internet-Draft, primary (). ↩︎
-
« Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as “work in progress.” » — Status of This Memo, Agent Identity Framework: Trust and Identity for Autonomous AI Agents, primary (). ↩︎
-
« The concept of identity in the context of AI agents is multifaceted and extends beyond simple user impersonation, playing a critical role in authentication, authorization, and auditability. » — section 2.8, identity management for agentic ai. ↩︎
-
« But at runtime, when the agent is making decisions about how to accomplish a task and actually executing calls, we need a stable, verifiable principal. » — Christian Posta, What ‘is’ Agent Identity? Human? Workload? A new Layer?, Solo.io, 23 June 2026, primary (). ↩︎
-
« That, in turn, requires a body for the signal to land on: a boundary whose integrity it protects, a locus where it accumulates, consolidation that converts episodic signal into durable update, and a substrate that responds by altering future action. Current LLM agents—software-defined composites of weights, prompts, tools, memory, and credentials, freely swapped, copied, reset, and reassembled—satisfy none of these conditions. » — Botao Amber Hu and Helena Rong, abstract, Some[Body] Must Receive That Pain for Agent Accountability, arXiv 2605.16872, 16 May 2026, arXiv preprint, primary (). ↩︎ ↩︎
-
« The thin response pairs each AI agent with an identifiable human or organizational principal and treats the pair as the unit of accountability. » and « But the principal is not the decision substrate. Pain lands on a body that did not produce the action. » — section 4.1, arXiv 2605.16872, arXiv preprint, primary (). ↩︎ ↩︎
-
« Variants appear in OpenAI’s agentic-systems guidance [Shavit et al., 2023], the Know Your Agent framework [Chaffer, 2025], and the EU AI Act’s provider/deployer split. » — section 4.1, arXiv 2605.16872, arXiv preprint, primary (). ↩︎
-
« Achieving consequence–agency coupling is therefore a sociotechnical infrastructural problem, not only a legal one. Until such architectures exist, high-stakes AI deployment should remain tethered to accountable human principals with meaningful control, proportional liability, and authority to constrain or terminate the agent. » — abstract, arXiv 2605.16872, arXiv preprint, primary (). ↩︎
-
« Should an agent identity be a “new thing”, i.e, a layer on top of workload identity? Or can we just use existing workload identity? The answer to both questions simultaneously is “yes” » — Christian Posta, What ‘is’ Agent Identity? Human? Workload? A new Layer?, Solo.io, 23 June 2026, primary (). ↩︎
-
« Agents are not human. Giving them human identities would give them the standing of a human with none of the built-in human-ness/constraints. » — Christian Posta, What ‘is’ Agent Identity? Human? Workload? A new Layer?, Solo.io, 23 June 2026, primary (). ↩︎
-
« This is a live debate, not a settled point, and the honest answer is: it depends. It depends on three invariants. » — Zawad Chowdhury and Jayanth Rajashekariah, What a first-class agent identity actually is, and whether it is just workload identity, DataRobot, 14 July 2026, primary (). ↩︎
-
« A one-to-one mapping. One agent corresponds to exactly one workload. […] A registry as the source of truth. Something authoritative records which agents exist and what they are. […] Identity continuity. The identity survives restarts, pauses, and reschedules. » — Zawad Chowdhury and Jayanth Rajashekariah, What a first-class agent identity actually is, and whether it is just workload identity, DataRobot, 14 July 2026, primary (). ↩︎ ↩︎ ↩︎
-
« When all three hold, agent identity collapses into workload identity. You attest the workload with something like SPIFFE or WIMSE and you authorize against it directly. No extra layer earns its place. When they break, agent identity becomes a layer on top of workload identity. And they break often. » — Zawad Chowdhury and Jayanth Rajashekariah, What a first-class agent identity actually is, and whether it is just workload identity, DataRobot, 14 July 2026, primary (). ↩︎ ↩︎
-
« AI agents are now running real transactions, workflows, and sub-agent chains across organizational boundaries without continuous human supervision. » — Otsuka, Toyoda and Leung, abstract, AI Identity: Standards, Gaps, and Research Directions for AI Agents, arXiv preprint, primary (). ↩︎
-
« This document addresses the narrower question of what identity and trust primitives the Internet requires to make agent actions safe, auditable, and accountable. » — Introduction, Agent Identity Framework: Trust and Identity for Autonomous AI Agents, primary (). ↩︎
-
« This document defines the term Agent Identity Management System (AIMS) as a conceptual model describing the set of functions required to establish, maintain, and evaluate the identity and permissions of an agent workload. » — P. Kasselman, J. Lombardo, Y. Rosomakho, B. Campbell, N. Steele, A. Parecki, section 5, AI Agent Authentication and Authorization, 6 July 2026, Informational Internet-Draft, primary (). ↩︎
-
« However, many of these efforts develop solutions in isolation, often reinventing existing mechanisms unaware of applicable prior art. This fragmentation risks creating incompatible implementations, duplicated development effort, and missed opportunities to leverage decades of established identity and authorization standards. » — Introduction, AI Agent Authentication and Authorization, primary (). ↩︎
-
« This increased scale and autonomy brings new opportunities as well as new risks. To enable effective management of these risks and to securely capitalize on these opportunities, enterprises and individuals need to understand how foundational identity principles—identification, authentication, and authorization—can be applied to ensure that agents are known, trusted, and properly governed. » — Challenge Overview, Accelerating the Adoption of Software and AI Agent Identity and Authorization, NIST NCCoE, February 2026, draft, primary (). ↩︎ ↩︎
-
« How might agents be identified in an enterprise architecture? » — Harold Booth, Bill Fisher, Ryan Galluzzo, Joshua Roberts, Accelerating the Adoption of Software and AI Agent Identity and Authorization, NIST NCCoE, February 2026, draft, primary (). ↩︎
-
« Recognizing that the traditional service account is insufficient for the dynamic lifecycle and unique governance needs of AI agents, identity vendors have started to treat them as first-class entities. » — section 2.8, identity management for agentic ai. ↩︎ ↩︎
-
« This creates a problem no current infrastructure is equipped to solve: how do you identify, verify, and hold accountable an entity with no body, no persistent memory, and no legal standing? » — Otsuka, Toyoda and Leung, abstract, AI Identity: Standards, Gaps, and Research Directions for AI Agents, arXiv preprint, primary (). ↩︎
-
« an evaluation of current technical and regulatory documents against the identity requirements of autonomous agents, finding that none adequately address the challenge of governing nondeterministic, boundary-crossing entities » — Otsuka, Toyoda and Leung, abstract, AI Identity: Standards, Gaps, and Research Directions for AI Agents, arXiv preprint, primary (). ↩︎ ↩︎
-
« Identification of five critical gaps (semantic intent verification, recursive delegation accountability, agent identity integrity, governance opacity and enforcement, and operational sustainability), none of which current technology or regulatory instruments resolve » — Takumi Otsuka, Kentaroh Toyoda, Alex Leung, AI Identity: Standards, Gaps, and Research Directions for AI Agents, 25 April 2026, arXiv preprint, primary (). ↩︎
-
« What metadata is essential for an AI agent’s identity? Should agent identity metadata be ephemeral (e.g. task dependent) or is it fixed? Should agent identities be tied to specific hardware, software, or organizational boundaries? » — Accelerating the Adoption of Software and AI Agent Identity and Authorization, NIST NCCoE, February 2026, draft, primary (). ↩︎
-
« This principal is used to make authorization decisions, attribute actions to the agent and lastly to revoke an agent. » — Christian Posta, What ‘is’ Agent Identity? Human? Workload? A new Layer?, Solo.io, 23 June 2026, primary (). ↩︎
-
« A traditional workload’s identity confirms what it is, but in the context of agents, its behaviour is also important. Agent identity must be enriched with metadata about its underlying model, version, and capabilities to enable risk-based access control. » — section 2.8, identity management for agentic ai. ↩︎ ↩︎
-
« An agent’s identity must be portable and verifiable to a third party that has no visibility into its host environment. » — section 2.8, identity management for agentic ai. ↩︎
-
« a structural comparison of human and AI identity across four dimensions (substrate, persistence, verifiability, and legal standing) showing that the asymmetry is fundamental and that extending human frameworks to agents without structural modification produces systematic failures » — Otsuka, Toyoda and Leung, abstract, AI Identity: Standards, Gaps, and Research Directions for AI Agents, arXiv preprint, primary (). ↩︎ ↩︎
-
« formalize compliance policies as deterministic functions mapping agent identity, partial path, proposed next action, and organizational state to a policy violation probability » — Maurits Kaptein, Vassilis-Javed Khan, Andriy Podstavnychy, abstract, Runtime Governance for AI Agents: Policies on Paths, 17 March 2026, arXiv preprint, primary (). ↩︎
-
« We argue that the execution path is the central object for effective runtime governance » — Kaptein, Khan and Podstavnychy, abstract, Runtime Governance for AI Agents: Policies on Paths, arXiv preprint, primary (). ↩︎
-
« We show that prompt-level instructions (and “system prompts”), and static access control are special cases of this framework: the former shape the distribution over paths without actually evaluating them; the latter evaluates deterministic policies that ignore the path (i.e., these can only account for a specific subset of all possible paths). » — Kaptein, Khan and Podstavnychy, abstract, Runtime Governance for AI Agents: Policies on Paths, arXiv preprint, primary (). ↩︎
-
« The components form a logical stack in which higher layers depend on guarantees provided by lower layers, as illustrated in Figure 2. » — P. Kasselman, J. Lombardo, Y. Rosomakho, B. Campbell, N. Steele, A. Parecki, section 5, AI Agent Authentication and Authorization, 6 July 2026, Informational Internet-Draft, primary (). The diagram’s boxes carry that figure’s own labels. ↩︎
-
« The layers form a stack. Each layer depends on the ones below it and provides services to the ones above it. The figure below shows the stack and the question each layer answers. » — R. Sharif, section 4.1, Agent Identity Framework: Trust and Identity for Autonomous AI Agents, 6 April 2026, Informational Internet-Draft, primary (). The diagram’s boxes carry that figure’s own labels and questions. ↩︎
-
« Cedar policies use principals to represent the entity making an authorization request. » — Amazon Bedrock AgentCore, Core concepts, primary, undated living documentation, read (). ↩︎
-
« Policy in AgentCore supports two principal types depending on how your AgentCore Gateway is configured for authentication: AgentCore::OAuthUser - Represents OAuth-authenticated users. […] AgentCore::IamEntity - Represents IAM-authenticated callers. » — Amazon Bedrock AgentCore, Core concepts, primary, undated living documentation, read (). ↩︎
-
« IAM principals have an id attribute containing the IAM ARN (format: arn:aws:sts::<account>:assumed-role/<role-name> for assumed roles), enabling stable principal == matching. » — Amazon Bedrock AgentCore, Core concepts, primary, undated living documentation, read (). ↩︎
-
« A temporal policy adds conditions that depend on what happened earlier in the same session, such as requiring a prior approval, limiting how often an action runs, or keeping a running total under a threshold. » — Amazon Bedrock AgentCore, Core concepts, primary, undated living documentation, read (). ↩︎