Skip to content
ModulesModule 02

Agent Trust Identity

Give every agent a machine identity that survives a model swap, a redeploy or a key rotation, and hold a named human accountable for it.

Who owns each agent, and can it prove what it is?Phase 1 · Inventory and policy

What it does

Capabilities

  • A stable agent identity that does not change when the model, infrastructure, credential or deployment does
  • Business, technical and security ownership, with an orphaned-agent warning when nobody holds it
  • A declared purpose that later becomes part of the authorization decision
  • Machine authentication by workload identity, mutual TLS, signed JWT and short-lived tokens rather than permanent keys
  • A lifecycle from discovery through review, approval, production, recertification and retirement

What it leaves behind

Evidence produced

  • An owner of record for every production agent
  • A purpose declaration an out-of-scope action can be measured against

The governed lifecycle

Modification sits late and deliberately: a change to a production agent re-enters review rather than shipping straight through.

  1. 01Discovered
  2. 02Registered
  3. 03Owner assigned
  4. 04Risk reviewed
  5. 05Permissions approved
  6. 06Tested
  7. 07Production
  8. 08Monitored
  9. 09Modified
  10. 10Re-certified
  11. 11Retired

Specification

Where this is specified

3 blueprint pages carry the specification for this module.

13 modules and services make up the platform. See how they fit together.