Learn
Know Your Agent in production
Straight answers to the questions security and platform teams ask when real AI agents start touching real systems: how to give each agent its own identity, how to scope and revoke access, how to prove which agent did what, and where existing tools stop short. Each guide is self-contained and practical.
Identity
-
Give each AI agent its own identity instead of a shared API key
Why a shared key can't tell your agents apart in logs, and how to issue a distinct, verifiable identity per agent.
-
Give an AI agent a human sponsor
Tie every agent to an accountable sponsor, recorded in evidence you can hand to an auditor.
-
Identity tokens vs standing API keys
The real security tradeoff for AI agents, and whether the operational overhead is worth it.
Governance & accountability
Access & enforcement
-
Enforce least privilege for an AI agent calling your systems
Scope an agent to the smallest set of operations it needs, and enforce it on every request.
-
Revoke an AI agent's access immediately
A playbook for cutting off an agent the moment it starts behaving unexpectedly.
-
Operational boundaries, enforced at runtime
What an operational boundary is, and why enforcing it at runtime beats trusting a config file.
Standards & interop
-
Can Open Policy Agent handle AI agent authorization?
Where OPA fits for agents, what it decides well, and what has to sit in front of it.
-
SPIFFE/SPIRE and the agentic identity gap
Workload identity covers services; here's what's missing for an agent acting on a human's behalf, and how teams fill it.