Agent identity should be separate from user identity

If an agent acts using your credentials, everything it does is indistinguishable from you doing it.

That breaks the audit trail and gives the agent everything you have, which is almost always far more than it needs. Giving the agent its own identity, with its own narrow permissions, means you can see which actions were yours, restrict what it can reach, and switch it off without switching off you.

More on AI agents