Skip to content

Notes

Who is this agent acting for?

Agent identity starts with the actor: who is acting, under whose authority, through which tool, and with what approval boundary.

By Vlad Iftode, September 29, 2026, 4 min read

The first question is not the tool

Most agent systems start by asking which tool a model can call. The more important question comes before that: who is this agent acting for? A tool call without an actor is just a line in a transcript. A tool call with identity can be checked, limited, delegated, revoked, and explained later.

That actor is not always the human directly. An agent might act for a user, a team, another agent, or a temporary role created for one workflow. The system needs to know the difference. Otherwise every permission turns into ambient trust from a previous login, and every audit log becomes a vague memory of a chat session.

Identity and authorization are related, not identical

Identity says which actor is present. Authorization says what that actor may do now. Provenance says where the action came from. Trust says how much weight to give its history. These layers should talk to each other, but collapsing them into one permission field makes systems brittle.

TrustChain is my work in this area: signed bilateral interaction records, delegation, revocation, and trust computation that can travel across agents and services. The Internet-Draft is an individual work in progress, not a standard or endorsement. The useful part is the shape: make authority portable enough to inspect, and strict enough to enforce outside the model.

Approvals are part of the product

Good approval design is not a panic button at the end. It starts by separating reads, drafts, reversible changes, and irreversible actions. A connector can let an agent gather context, prepare a document, and explain a recommendation while still requiring a human confirmation before sending, approving, deleting, or publishing.

That boundary also gives the model cleaner work. If the system can show available authority and stop exactly where authority changes, the agent can move quickly without pretending it has power it does not have. Identity becomes part of the user experience: what happened, who allowed it, and how the same authority can be withdrawn.

References