← Blog

Series

Identity and access

Keep the owner and permissions visible when agents call tools or hand work to other agents.

5 articles

Reading list

In this series

Browse every article →
  1. 01

    · Identity & access · 8 min

    Why service-account permissions don't fit agents

    Cross-tenant reach is an identity-model problem. The fix is a different kind of credential, issued at run start and scoped to the work in front of the agent.

  2. 02

    · Identity & access · 8 min

    Sub-agent identity: inherit and narrow

    The two rules that govern how a sub-agent's identity should be derived from its parent's, what a sub-agent claim looks like, and how audit reconciliation works across the run graph.

  3. 03

    · Identity & access · 7 min

    The lethal trifecta: where it actually lives

    Untrusted inputs + private data access + outbound communication. The framing names the risk space correctly; the standard mitigation pattern picks the wrong layer.

  4. 04

    · Identity & access · 4 min

    Who can use AI for marketing work—and who can approve it?

    A practical access model for marketing AI tools that separates requesters, source owners, approvers, and publishing authority.

  5. 05

    · Identity & access · 4 min

    Marketing needs a data boundary before it buys another AI tool

    A plain-language data policy for marketing AI tools: classify inputs, choose allowed paths, name exceptions, and remove access when the work ends.