Learn · Identity
How to assign a human sponsor to an AI agent
An agent with no sponsor is an agent no one is accountable for. Enrollment approval ties every agent to an accountable sponsor before it can act, and keeps that link on record for as long as the agent exists.
Why a sponsor matters
Autonomous software still acts on someone's behalf. If an agent deletes a table or emails a customer, the first question is always who stands behind it. Without a sponsor recorded at enrollment, that question has no answer and accountability evaporates. Assigning a sponsor turns every agent into something closer to a badged employee than an anonymous process: there is always a person or organization that approved it and is answerable for its scope.
Enrollment approval
The sponsor relationship is established at the moment an agent is enrolled. The agent's Identity MCP requests enrollment; a principal signs in, is shown the agent, its intended purpose, and the host it runs on, and approves it. Until that enrollment approval happens the agent holds no usable identity and can do nothing. This single checkpoint is what makes the resulting identity meaningful — it was granted deliberately, by a principal, rather than minted automatically.
No approval, no identity, no access. The default is closed, so an agent nobody stands behind simply never starts.
Keeping the sponsor on record
The approval is written into a verifiable credential issued by the credential service (VCI): who approved the agent, when, for what purpose, and on which host. That credential travels with the agent's identity, so months later you can still show the chain from a specific action back to the agent and from the agent back to its sponsor. If the sponsor changes or the agent's purpose changes, you re-enroll rather than silently inheriting stale authority.
How to set it up
- Enroll through your IdP. The agent requests enrollment; your own IdP identifies the principal who approves it.
- Approve once, explicitly. The principal reviews the agent and approves the enrollment. Nothing works beforehand.
- Bind sponsor to identity. The approval is recorded in a verifiable credential (VCI) tied to the agent's identity.
- Re-enroll on change. A change of sponsor or scope requires a fresh enrollment approval, so the record never drifts.
This is how Oathera handles enrollment out of the box. See the platform or the live demo.
FAQ
How do you assign a human sponsor to an AI agent and make that accountable?
Enroll the agent through an enrollment approval step: a principal signs in and approves the enrollment before the agent can act, and that approval is recorded in a verifiable credential tied to the agent's identity. Every later action traces back through the agent to its sponsor, so accountability is provable.
What stops an agent from running without a sponsor?
A fail-closed default. The agent holds no usable identity until its enrollment is approved, so an agent with no sponsor cannot authenticate or act at all.
What happens when a sponsor leaves or the agent changes purpose?
You re-enroll. A change of sponsor or scope requires a fresh enrollment approval, which is recorded, so the record never silently goes stale. When a principal is deprovisioned, Oathera stops issuing identity tokens to that principal's agents.