agent gateway · identity · guardrails · audit

When the thing making decisions is not a person: governing an estate of agents

Every security control ever built assumes a human or a program on the other side. An agent is neither: it decides what to do next by reading text, and text can be written by an attacker. So the question stops being “who is allowed in” and becomes “what is this thing allowed to do, who is it doing it on behalf of, what did it just read, and can anyone prove afterwards what happened”. Twelve sections, plain English first, and simulations for the controls that only make sense once you have watched one fail.

Try it: four incidents, four questions

Try this: four things that went wrong. For each, decide which of the four questions the estate had failed to answer, because each one maps to a different mechanism, and reaching for the wrong one is how a post-incident action produces no change.
in real lifeFour break-ins at four buildings. One had no name badges, one lent out a master key, one let a stranger in with a forged note, and one had cameras that recorded nothing useful. Four different failures, four different fixes.
start bypick the warranty document incident and try tighter permissions, the answer that feels right and is not.
words hereidentity which particular agent acted, provablydelegated authority acting as a person, so their permissions applyaudit trail a record complete enough to reconstruct a decision afterwards
WHICH QUESTION WENT UNANSWERED?