Account Access Management & Permissions
The Agent Access Model

The Agent Access Model

8/5/2026 · Matt Silverlock

What this post added

This post introduces the Agent Access Model (AAM) as a new approach to enterprise security for software principals (agents). It contrasts AAM with the human-centric BeyondCorp model, highlighting the limitations of existing controls for agents due to their ephemeral nature, machine-speed actions, and ability to compose authority across hops. AAM's core principles include short-lived, task-scoped, sender-constrained credentials; enforcement in the harness and network; exceptional human oversight; grants reviewed from evidence; and unidirectional capability state reduction via a Trust Ratchet. A reference architecture is proposed with an Agent Identity Broker (using OAuth 2.0 Token Exchange and DPoP), a Task-Scoped Access Engine (extending BeyondCorp's ACE), and a Mediation Layer (harness and network).

Read the original post ↗