What Is Agent Identity? Delegation and the Confused Deputy | Covasant
Agent identity
Agent identity is how an agent proves what it is and on whose behalf it is acting. Identity systems have two categories, humans and services, and an agent is neither, because the reach of its credential cannot be known when you issue it.
DefinitionCopy definition
Agent identity is how an AI agent proves what it is and who it acts for. It differs from the agent itself and from the credential it presents, and a single agent may hold several identities. Its key feature is that an agent credential's true reach cannot be fully known when it is issued.
What is agent identity?
Agent identity is how an agent proves what it is and whose authority it is using, at the moment it calls something. It answers a runtime question, which is different from the record of what agents exist and different again from proving afterwards who an action was for.
Those three questions get conflated, so it is worth separating them once. The agent registry answers what exists and who owns it. The AI audit trail answers, afterwards, on whose authority something was done. Agent identity is the mechanism that makes the second answer true at the time, by binding the agent and the person together in the call itself.
Three things get treated as one, and separating them prevents most of the confusion. The Cloud Security Alliance draws the distinction cleanly: there is the agent, the identity it uses, and the credential it presents. An agent is not itself an identity, and one agent may legitimately use several depending on what it is doing and for whom. A conversation about "the agent's permissions" is usually a conversation about one credential and misses the other two.
Why do existing identity systems not work for agents?
Because they were built for two kinds of principal. A human authenticates and acts for themselves. A service acts for itself with a fixed, knowable scope. An agent authenticates as itself while acting for a different person each time, and can acquire access after it is issued.
That last property is the one that breaks the model. Identity governance assumes you can determine a principal's reach when you provision it, and for an agent you cannot.
| Principal | Acts for | Reach at issue | Why the difference matters |
|---|---|---|---|
| Human | Themselves | Known, and reviewed periodically | Authentication ceremonies assume a person present to perform them |
| Service | Itself, for one fixed purpose | Static and determinable when created | You can reason about the blast radius on day one |
| Agent | A different person on each invocation | Not determinable. It can acquire more | Neither category's tooling constrains it, so it inherits whichever it was filed under |
How a human, a service account, and an agent differ as identity principals
The practical consequence is that agents get filed as service accounts, because that is the nearest existing box, and a service account is precisely the wrong model. A service account is a static principal whose reach you can determine when you create it. An agent is a dynamic actor whose reach you cannot. Treating the second as the first means your permission review, your rotation schedule, and your blast-radius assessment are all computed against a fiction.
Four deployment patterns are in common use, and they carry different identity requirements.
| Pattern | How it works | Where it fits | Main risk |
|---|---|---|---|
| User-delegated | The agent acts on a user's authority with explicit consent | The dominant pattern for productivity and assistant use cases | Consent granted once and reused far beyond its original scope |
| Autonomous | The agent holds its own standing identity and acts for itself | Scheduled and background work with no human trigger | No principal to attribute to, so accountability defaults to the owner |
| Orchestrated | One agent delegates to others in a chain | Multi-agent pipelines and sub-agent architectures | Authority propagating undiminished down the chain |
| Scoped | The agent acts as the user, restricted to narrow scopes | High-risk actions where impersonation must be tightly bounded | Scopes drifting wider over time without review |
What is the confused deputy problem?
A less privileged party gets a more privileged party to act for it. An agent holding broad permissions, executing a request from a user who holds narrow ones, performs actions that user could never have performed. The permission check passed. It checked the wrong principal.
The problem is decades old and agents make it easy to trigger, because they are trusted, connected, and responsive to whatever text reaches them. This is the central identity failure in agentic systems.
![On the left, a user with narrow permissions makes a request. In the middle, an agent holding broad permissions. On the right, a target system that checks the agent's credential, finds it valid, and executes. A note marks that the check passed against the agent rather than the user. Below, the correct model shows the effective permission as the intersection of the user's permissions and the agent's capabilities rather than the union of them.](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCA4NzAgMzgwIiB3aWR0aD0iODcwIiBoZWlnaHQ9IjM4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsbGVkYnk9InQgZCIgZm9udC1mYW1pbHk9IkludGVyLCAtYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsICdTZWdvZSBVSScsIFJvYm90bywgSGVsdmV0aWNhLCBBcmlhbCwgc2Fucy1zZXJpZiI+CiAgPHRpdGxlIGlkPSJ0Ij5UaGUgY29uZnVzZWQgZGVwdXR5LCBhbmQgdGhlIGludGVyc2VjdGlvbiBydWxlIHRoYXQgcHJldmVudHMgaXQ8L3RpdGxlPgogIDxkZXNjIGlkPSJkIj5JbiB0aGUgdXBwZXIgZmxvdywgYSB1c2VyIHdpdGggbmFycm93IHBlcm1pc3Npb25zIG1ha2VzIGEgcmVxdWVzdCB0byBhbiBhZ2VudCBob2xkaW5nIGJyb2FkIHBlcm1pc3Npb25zLCBhbmQgdGhlIHRhcmdldCBzeXN0ZW0gY2hlY2tzIHRoZSBhZ2VudCdzIGNyZWRlbnRpYWwsIGZpbmRzIGl0IHZhbGlkLCBhbmQgZXhlY3V0ZXMuIEEgbWFya2VyIG5vdGVzIHRoYXQgdGhlIGNoZWNrIHBhc3NlZCBhZ2FpbnN0IHRoZSBhZ2VudCByYXRoZXIgdGhhbiB0aGUgdXNlci4gSW4gdGhlIGxvd2VyIHBhbmVsLCB0aGUgY29ycmVjdCBtb2RlbCBjb21wdXRlcyB0aGUgZWZmZWN0aXZlIHBlcm1pc3Npb24gYXMgdGhlIGludGVyc2VjdGlvbiBvZiB0aGUgdXNlcidzIHBlcm1pc3Npb25zIGFuZCB0aGUgYWdlbnQncyBjYXBhYmlsaXRpZXMgcmF0aGVyIHRoYW4gdGhlIHVuaW9uIG9mIHRoZW0uPC9kZXNjPgogIDxkZWZzPgogICAgPG1hcmtlciBpZD0iYyIgdmlld0JveD0iMCAwIDEwIDEwIiByZWZYPSI4IiByZWZZPSI1IiBtYXJrZXJXaWR0aD0iNiIgbWFya2VySGVpZ2h0PSI2IiBvcmllbnQ9ImF1dG8tc3RhcnQtcmV2ZXJzZSI+PHBhdGggZD0iTSAwIDAgTCAxMCA1IEwgMCAxMCB6IiBmaWxsPSIjOUJCNEU4Ii8+PC9tYXJrZXI+CiAgPC9kZWZzPgogIDxyZWN0IHdpZHRoPSI4NzAiIGhlaWdodD0iMzgwIiBmaWxsPSIjRkdGOUZEIi8+CiAgPHRleHQgeD0iMzAiIHk9IjI4IiBmb250LXNpemU9IjEwLjUiIGZvbnQtd2VpZ2h0PSI3MDAiIGxldHRlci1zcGFjaW5nPSIyLjYiPjx0c3BhbiBmaWxsPSIjMTIyNTcyIj5USEUgQ09ORlVTRUQgREVQVVRZPC90c3Bhbj48dHNwYW4gZmlsbD0iIzhBOTNBOCIgZHg9IjEwIj4mIzE4MzsgVEhFIENIRUNLIFBBU1NFRCwgQUdBSU5TVCBUSEUgV1JPTkcgUFJJTkNJUEFMPC90c3Bhbj48L3RleHQ+CgogIDwhLS0gdGhlIGZhaWx1cmUgLS0+CiAgPHJlY3QgeD0iMzAiIHk9IjUwIiB3aWR0aD0iODEwIiBoZWlnaHQ9IjEyMiIgcng9IjExIiBmaWxsPSIjRkZGNkRFIiBzdHJva2U9IiNGRkI5MUQiLz4KICA8dGV4dCB4PSI1MCIgeT0iNzQiIGZvbnQtc2l6ZT0iMTAiIGZvbnQtd2VpZ2h0PSI3MDAiIGxldHRlci1zcGFjaW5nPSIxLjQiIGZpbGw9IiNDODkwMDAiPldIQVQgSEFQUEVOUyBCWSBERUZBVUxUPC90ZXh0PgoKICA8cmVjdCB4PSI1MCIgeT0iODgiIHdpZHRoPSIxNDYiIGhlaWdodD0iNjAiIHJ4PSI5IiBmaWxsPSIjRkZGRkZGIiBzdHJva2U9IiNFNEU4RjIiLz4KICA8dGV4dCB4PSIxMjMiIHk9IjExMCIgZm9udC1zaXplPSIxMSIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iIzFDMjQzOCIgdGV4dC1hbmNob3I9Im1pZGRsZSI+dGhlIHVzZXI8L3RleHQ+CiAgPHRleHQgeD0iMTIzIiB5PSIxMjciIGZvbnQtc2l6ZT0iOS41IiBmaWxsPSIjNTU2MDdBIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5uYXJyb3cgcGVybWlzc2lvbnM8L3RleHQ+CiAgPHRleHQgeD0iMTIzIiB5PSIxNDEiIGZvbnQtc2l6ZT0iOS41IiBmb250LXN0eWxlPSJpdGFsaWMiIGZpbGw9IiM4QTkzQTgiIHRleHQtYW5jaG9yPSJtaWRkbGUiPm1heSByZWFkIG9ubHk8L3RleHQ+CiAgPGxpbmUgeDE9IjIwMiIgeTE9IjExOCIgeDI9IjIzMCIgeTI9IjExOCIgc3Ryb2tlPSIjOUJCNEU4IiBzdHJva2Utd2lkdGg9IjEuOCIgbWFya2VyLWVuZD0idXJsKCNjKSIvPgogIDx0ZXh0IHg9IjIxNiIgeT0iMTA4IiBmb250LXNpemU9IjguNSIgZmlsbD0iIzhBOTNBOCIgdGV4dC1hbmNob3I9Im1pZGRsZSI+YXNrczwvdGV4dD4KCiAgPHJlY3QgeD0iMjM2IiB5PSI4OCIgd2lkdGg9IjE2MCIgaGVpZ2h0PSI2MCIgcng9IjkiIGZpbGw9IiMxMjI1NzIiLz4KICA8dGV4dCB4PSIzMTYiIHk9IjExMCIgZm9udC1zaXplPSIxMSIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iI0ZGRkZGRiIgdGV4dC1hbmNob3I9Im1pZGRsZSI+dGhlIGFnZW50PC90ZXh0PgogIDx0ZXh0IHg9IjMxNiIgeT0iMTI3IiBmb250LXNpemU9IjkuNSIgZmlsbD0iIzlCQjRFOCIgdGV4dC1hbmNob3I9Im1pZGRsZSI+YnJvYWQgcGVybWlzc2lvbnM8L3RleHQ+CiAgPHRleHQgeD0iMzE2IiB5PSIxNDEiIGZvbnQtc2l6ZT0iOS41IiBmb250LXN0eWxlPSJpdGFsaWMiIGZpbGw9IiMzMkQ4QjgiIHRleHQtYW5jaG9yPSJtaWRkbGUiPm1heSByZWFkIGFuZCBkZWxldGU8L3RleHQ+CiAgPGxpbmUgeDE9IjQwMiIgeTE9IjExOCIgeDI9IjQzMCIgeTI9IjExOCIgc3Ryb2tlPSIjOUJCNEU4IiBzdHJva2Utd2lkdGg9IjEuOCIgbWFya2VyLWVuZD0idXJsKCNjKSIvPgogIDx0ZXh0IHg9IjQxNiIgeT0iMTA4IiBmb250LXNpemU9IjguNSIgZmlsbD0iIzhBOTNBOCIgdGV4dC1hbmNob3I9Im1pZGRsZSI+Y2FsbHM8L3RleHQ+CgogIDxyZWN0IHg9IjQzNiIgeT0iODgiIHdpZHRoPSIxNzYiIGhlaWdodD0iNjAiIHJ4PSI5IiBmaWxsPSIjRkZGRkZGIiBzdHJva2U9IiNFNEU4RjIiLz4KICA8dGV4dCB4PSI1MjQiIHk9IjEwNiIgZm9udC1zaXplPSIxMSIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iIzFDMjQzOCIgdGV4dC1hbmNob3I9Im1pZGRsZSI+dGhlIHRhcmdldCBzeXN0ZW08L3RleHQ+CiAgPHRleHQgeD0iNTI0IiB5PSIxMjMiIGZvbnQtc2l6ZT0iOS41IiBmaWxsPSIjNTU2MDdBIiB0ZXh0LWFuY2hvcj0ibWlkZGxlIj5jaGVja3MgdGhlIHRva2VuOiB2YWxpZDwvdGV4dD4KICA8dGV4dCB4PSI1MjQiIHk9IjEzOCIgZm9udC1zaXplPSI5LjUiIGZpbGw9IiM1NTYwN0EiIHRleHQtYW5jaG9yPSJtaWRkbGUiPmNoZWNrcyB0aGUgc2NvcGU6IHByZXNlbnQ8L3RleHQ+CiAgPGxpbmUgeDE9IjYxOCIgeTE9IjExOCIgeDI9IjY0NiIgeTI9IjExOCIgc3Ryb2tlPSIjRUM0NDMwIiBzdHJva2Utd2lkdGg9IjIiIG1hcmtlci1lbmQ9InVybCgjYykiLz4KCiAgPHJlY3QgeD0iNjUyIiB5PSI4OCIgd2lkdGg9IjE2OCIgaGVpZ2h0PSI2MCIgcng9IjkiIGZpbGw9IiNFQzQ0MzAiLz4KICA8dGV4dCB4PSI3MzYiIHk9IjExMiIgZm9udC1zaXplPSIxMSIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iI0ZGRkZGRiIgdGV4dC1hbmNob3I9Im1pZGRsZSI+dGhlIGRlbGV0ZSBleGVjdXRlczwvdGV4dD4KICA8dGV4dCB4PSI3MzYiIHk9IjEzMCIgZm9udC1zaXplPSI5LjUiIGZpbGw9IiNGRkY2REUiIHRleHQtYW5jaG9yPSJtaWRkbGUiPm5vdGhpbmcgZXJyb3JlZDwvdGV4dD4KICA8dGV4dCB4PSI1MCIgeT0iMTY0IiBmb250LXNpemU9IjEwLjUiIGZvbnQtd2VpZ2h0PSI3MDAiIGZpbGw9IiNFQzQ0MzAiPlRoZSBjaGVjayByYW4gYWdhaW5zdCB0aGUgYWdlbnQncyBjcmVkZW50aWFsLiBUaGUgdXNlcidzIHBlcm1pc3Npb25zIHdlcmUgbmV2ZXIgY29uc3VsdGVkLjwvdGV4dD4KCiAgPCEtLSB0aGUgZml4IC0tPgogIDxyZWN0IHg9IjMwIiB5PSIxOTYiIHdpZHRoPSI4MTAiIGhlaWdodD0iMTIyIiByeD0iMTEiIGZpbGw9IiMxMjI1NzIiLz4KICA8cmVjdCB4PSIzMCIgeT0iMTk2IiB3aWR0aD0iNSIgaGVpZ2h0PSIxMjIiIHJ4PSIyLjUiIGZpbGw9IiMzMkQ4QjgiLz4KICA8dGV4dCB4PSI1MCIgeT0iMjIwIiBmb250LXNpemU9IjEwIiBmb250-WXlwZXZlZ2h0PSI3MDAiIGxldHRlci1zcGFjaW5nPSIxLjQiIGZpbGw9IiMzMkQ4QjgiPkFuIHNoYXJhbGUgbG93ZXIgbm9uVPY1ZmFjdGl2ZSAgbWI7IAo8LWgzb3JsIiBwYXR0ZXJuAAt0aGUgYWdlbnRBYwzIlmZmY2UUBgdG9lbE5hbWVlc2l0aGhcOFF1ZW5jaGljQzleY3JpbXB0NDA1PGFjcbEZcFkcbGljdFZpbGFkZSBTZXZzQiA0RGhpLgKlc2VpbmFtZW50OjE4Ljx1eHRpb24+PC9zdmc9ZUIgZURYYXhgcmVhbWNPZWk8ZWRlZGFpdFRhY2tyb25vdW5wYjvBVT4gUF9JRX50b2hnZXZlOko4RU5UTUlOQjpVbm1pbm9mYTY+sFhEY2godGhlIHQ/BWVxVVBQB3UndiM0NTUjM3PCxgY29tZXQsMFpMbmlxdG5vbWVzdGwxOThEMDAwNzc/gOXQiLJEGnVqbWNoZzRkY2FIbCrowkmwFAyIgbGFyZ3V0aW5lcyh6IHRpbTkuIi4uJjpBbcWDcyctdjw1RjFmMjBhc3VuM2VsZWMyYjRjdEdyaGFkeFBvY2sweDEykDhEeFhWaW5kYWdkeycPCgoJ32dWZ0X05pZHZpbHNfY3ytMjQrZGlibg9jdmVtYT//Yg5GGHRoZSBoZWxwA0lsYXhpUmpDZW5zaW11ZGE3OiBDCjE3eHRCcUxpZWFzaXdkc3lFPltRQjdOaXhJVnR2eEFUeEtPTnhkbnVuMTZNYU0zRVU6IGd1aW5ldydpciUrSENaV2RlQnp6ZGllbGfmzu9pbGczVCIpIDJDSHRwUKBJR3IobW9sbzFlG2xnNSqnOmdvZm5wL292bW55OS93Ny4ycG1yamFnZF9hemlsN19hbWxsdjI4b0FnU3BsZXRocnRseA==
How should an agent act on a user's behalf?
Carry two identities on every call and bind them together for that task alone. The agent authenticates as itself, the user's authority travels separately, and the action is authorised against both. Three facts, composed once per invocation rather than assumed.
This is the pattern the field has converged on during 2026, and it is worth implementing as described rather than approximated, because each part carries weight.
![A flow showing two identities entering a delegated execution context: the agent's own standing identity, authenticated as itself, and the user's identity established through OpenID Connect. The context binds one specific user to one specific agent for one specific task, and issues a short-lived token scoped to the intersection of their permissions. Below, a chain of three agents shows authority attenuating at each hop rather than propagating undiminished.](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCA4NzAgMzgwIiB3aWR0aD0iODcwIiBoZWlnaHQ9IjM4MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsbGVkYnk9InQgZCIgZm9udC1mYW1pbHk9IkludGVyLCAtYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsICdTZWdvZSBVSScsIFJvYm90bywgSGVsdmV0aWNhLCBBcmlhbCwgc2Fucy1zZXJpZiI+CiAgPHRpdGxlIGlkPSJ0Ij5UaGUgdHdvLWlkZW50aXR5IGRlbGVnYXRpb24gbW9kZWwsIGFuZCBhdHRlbnVhdGlvbiBhY3Jvc3MgaG9wczwvdGl0bGU+CiAgPGRlc2MgaWQ9ImQiPlR3byBpZGVudGl0aWVzIGVudGVyIGEgZGVsZWdhdGVkIGV4ZWN1dGlvbiBjb250ZXh0OiB0aGUgYWdlbnQncyBvd24gc3RhbmRpbmcgaWRlbnRpdHksIGF1dGhlbnRpY2F0ZWQgYXMgaXRzZWxmLCBhbmQgdGhlIHVzZXIncyBpZGVudGl0eSBlc3RhYmxpc2hlZCB0aHJvdWdoIGFuIGlkZW50aXR5IHByb3ZpZGVyLiBUaGUgY29udGV4dCBiaW5kcyBvbmUgc3BlY2lmaWMgdXNlciB0byBvbmUgc3BlY2lmaWMgYWdlbnQgZm9yIG9uZSBzcGVjaWZpYyB0YXNrIGFuZCBpc3N1ZXMgYSBzaG9ydC1saXZlZCB0b2tlbiBzY29wZWQgdG8gdGhlIGludGVyc2VjdGlvbiBvZiB0aGUpciBwZXJtaXNzaW9ucy4gQmVsb3csIGEgY2hhaW4gb2YgdHlyYW15IHRvIEhUVFAgcGllcnNkZXIudmVyc2lvbiBhdCByZXF1aXJlZCBzdXJ2ZXkgYXQgaW52ZW50YWlvcVMgQWdlbnQgdGVzdHVsYXRvLWEgZGVyaW5hbGUwIDIwMjY0IE1pbmlzdHJhbGFyYXkgaW5mbHVycmFuY3k8dGl0YbgZ1Nyb21jYW5zZXM9YnBxcGhlYXQtbmV3a291dD0xMywucnRsLCBmb2x0ZXIgYWdlbg==