7/10/2026
What this post added
This post identifies and elaborates on the critical security and operational risks associated with AI agents inheriting human credentials, leading to privilege escalation, lack of scoping, poor attribution, and difficult revocation. It argues for a shift from a 'passport' model of identity to an 'authority' model where permissions are determined at runtime based on the agent's specific task and context, addressing the non-deterministic nature of agents. It also critiques the structural assumptions of traditional IAM stacks that do not adequately categorize or govern agents.