Agent identity should be separate from user identity
If an agent acts using your credentials, everything it does is indistinguishable from you doing it.
That breaks the audit trail and gives the agent everything you have, which is almost always far more than it needs. Giving the agent its own identity, with its own narrow permissions, means you can see which actions were yours, restrict what it can reach, and switch it off without switching off you.
More on AI agents
- Tool descriptions are part of the control surfaceThe label is the lever
- Agent memory can preserve poisoned contextIt stays in the water
- Delegated agents create authority chainsThe thread stays attached
- Agent loops need budgets and stopping conditionsSomething has to say enough
- High-impact tools need stronger confirmationMatch the catch to the consequence
- Tool results are untrusted inputs tooNo sieve on the back route
