Skip to main content
OATHERA logo OATHERA
PlatformControl plane and enforcement plane. FeaturesAnchor keys, identity tokens, operation proofs, boundary decisions. IntegrationsOIDC, SPIFFE, OPA, NVIDIA OpenShell, OpenTelemetry. Use casesWhere Oathera gives every AI agent an identity bound to its host.
DocsIdentity MCP, Gateway MCP, MCP bundle, BYOA. LearnGuides on giving AI agents an identity bound to their host. GlossaryAccepted terms: sponsor, principal, anchor key, identity token. GitHub ↗Open-source code and examples. Live demo ↗See the identity flow run end to end.
SecurityHost binding, fail closed, and why Oathera never proofs people. ContactTalk to the Oathera team.
Privacy PolicyHow we handle data. Terms of ServiceTerms for using Oathera. Data Processing AgreementOur DPA for customers. Sub-processorsThird parties we rely on.
Request access

Learn · Identity

How to assign a human sponsor to an AI agent

An agent with no sponsor is an agent no one is accountable for. Enrollment approval ties every agent to an accountable sponsor before it can act, and keeps that link on record for as long as the agent exists.

On this page

  1. Why a sponsor matters
  2. Enrollment approval
  3. Keeping the sponsor on record
  4. How to set it up
  5. FAQ

Why a sponsor matters

Autonomous software still acts on someone's behalf. If an agent deletes a table or emails a customer, the first question is always who stands behind it. Without a sponsor recorded at enrollment, that question has no answer and accountability evaporates. Assigning a sponsor turns every agent into something closer to a badged employee than an anonymous process: there is always a person or organization that approved it and is answerable for its scope.

Enrollment approval

The sponsor relationship is established at the moment an agent is enrolled. The agent's Identity MCP requests enrollment; a principal signs in, is shown the agent, its intended purpose, and the host it runs on, and approves it. Until that enrollment approval happens the agent holds no usable identity and can do nothing. This single checkpoint is what makes the resulting identity meaningful — it was granted deliberately, by a principal, rather than minted automatically.

No approval, no identity, no access. The default is closed, so an agent nobody stands behind simply never starts.

Keeping the sponsor on record

The approval is written into a verifiable credential issued by the credential service (VCI): who approved the agent, when, for what purpose, and on which host. That credential travels with the agent's identity, so months later you can still show the chain from a specific action back to the agent and from the agent back to its sponsor. If the sponsor changes or the agent's purpose changes, you re-enroll rather than silently inheriting stale authority.

How to set it up

  1. Enroll through your IdP. The agent requests enrollment; your own IdP identifies the principal who approves it.
  2. Approve once, explicitly. The principal reviews the agent and approves the enrollment. Nothing works beforehand.
  3. Bind sponsor to identity. The approval is recorded in a verifiable credential (VCI) tied to the agent's identity.
  4. Re-enroll on change. A change of sponsor or scope requires a fresh enrollment approval, so the record never drifts.

This is how Oathera handles enrollment out of the box. See the platform or the live demo.

FAQ

How do you assign a human sponsor to an AI agent and make that accountable?

Enroll the agent through an enrollment approval step: a principal signs in and approves the enrollment before the agent can act, and that approval is recorded in a verifiable credential tied to the agent's identity. Every later action traces back through the agent to its sponsor, so accountability is provable.

What stops an agent from running without a sponsor?

A fail-closed default. The agent holds no usable identity until its enrollment is approved, so an agent with no sponsor cannot authenticate or act at all.

What happens when a sponsor leaves or the agent changes purpose?

You re-enroll. A change of sponsor or scope requires a fresh enrollment approval, which is recorded, so the record never silently goes stale. When a principal is deprovisioned, Oathera stops issuing identity tokens to that principal's agents.

See it live More guides

← Back to Learn
OATHERA logo Oathera

Know Your Agent — the category Oathera defines. Every agent gets a verifiable identity and an enrollment approval before it acts.

Product

  • Platform
  • Features
  • Integrations
  • Use cases

Developers

  • Docs
  • Learn
  • GitHub
  • Demo

Company

  • Security
  • Contact
  • Careers soon

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
© 2026 Oathera · Know Your Agent

Cookie preferences

We use cookies to run this site and, with your consent, to understand usage and improve Oathera. Strictly necessary cookies are always on; you can choose whether to allow analytics and marketing cookies below.

  • Strictly necessaryAlways on

    Required for the site to work — security, load balancing, and remembering your cookie choices. These cannot be switched off.

  • Help us measure traffic and see how the site is used, so we can improve it. No personal profiles are built.

  • Used to make messages about Oathera more relevant across other sites. Off unless you turn it on.