7/8/2026
What this post added
This post introduces the concept of agents as a third type of actor in identity and access management (IAM) systems, distinct from human users and service accounts. It highlights the non-deterministic nature of agents and the resulting security gap where agents borrow human credentials, leading to privilege escalation and auditability issues. The post outlines immediate checks for borrowed human API keys, audit log separation, and agent revocation without collateral damage. It also sets the stage for a series that will detail building a robust agent identity and governance system, including first-class agent identity, delegation chains, credential management, and lifecycle governance.