Glossary · term

Agent identity

Agent identity is a distinct machine or digital identity assigned to an AI agent so systems can recognize the acting principal, associate it with an owner or sponsor, and record its lifecycle and activity. Depending on the implementation, the identity can carry relationships to human users, applications, or organizations and can be used when evaluating access requests. Identity answers who or what is acting; it does not by itself grant permission, verify an outcome, or make the agent trustworthy.

Agents2025-04-15Wave 2 · 2024Maturity: 3/5

Origin and context

A CNCF conference session published in April 2025 applied workload identity, delegated user context, authentication, and attestation to autonomous AI agents. Microsoft announced Entra Agent ID the following month and later documented identities for agents created inside and outside Microsoft environments. In October, an OpenID Foundation whitepaper treated identity management for agentic AI as a broader cross-industry problem. These sources show converging work, but implementations and terminology remain heterogeneous; the reviewed evidence does not establish IETF or W3C authorship of the concept.

Sources: s6, s1, s2, s3

Why it matters

When an agent calls tools or acts for a person, reusing the person's session or an undifferentiated service account can obscure who initiated an action and what was delegated. A separate identity can support inventory, credential isolation, policy decisions, revocation, and audit trails while preserving the relationship to a responsible sponsor. Those controls become especially useful when many agents are created dynamically or operate across organizations.

Sources: s1, s2, s3

Example

A purchasing agent receives its own managed identity linked to the employee who invoked it and to the application that created it. The identity is allowed to read approved catalogs but must present a fresh delegated authorization before placing an order above a threshold. Logs preserve the agent, sponsor, requested action, policy decision, and tool result. The identity enables attribution and policy evaluation; the authorization service still decides whether the particular purchase is allowed.

Sources: s2, s3

How it differs

Agent harness

Agent identity represents the principal that acts and its relevant relationships. An agent harness is runtime scaffolding that manages the model loop, tools, state, context, and controls. A harness can obtain and present an identity, but runtime structure and principal identity solve different problems and neither substitutes for authorization.

Agent2Agent Protocol

An A2A Agent Card advertises an agent endpoint, capabilities, and supported interaction details. That descriptive discovery document is not the same as a credentialed principal identity. A system may bind card metadata to a verified identity, but the card alone does not prove who controls the endpoint.

Maturity and evidence

Maturity is rated 3. The core need for separately identifiable non-human actors is stable, and enterprise documentation plus an independent foundation analysis provide concrete models for ownership, delegation, and lifecycle. A higher rating would require greater interoperability and consensus across identity providers, agent protocols, credential formats, and policy systems. The general concept is established even though its implementations are not one standard.

Sources: s1, s2, s3

Limits and open questions

Identity is not authorization, capability proof, reputation, or safety certification. A valid agent credential can still be over-privileged, compromised, or used outside the sponsor's intent. Delegation chains, short-lived agents, cross-domain federation, revocation, and accountability for autonomous actions remain difficult. Implementers should minimize credentials, bind delegation to specific actions and time windows, protect identity issuance, log policy decisions, and avoid treating a product-specific identifier as universal trust evidence.

Sources: s2, s3

Related terms

References

Last updated: 2026-09-04

In the Skills Atlas

This term is also covered in the Skills Atlas as ai auditability skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as agent threat modeling maestro skill.