Every AI worker has an identity, not a key
Owner, department, purpose, systems and ceiling, held once and read by everything. An API key proves a request is authentic. It says nothing about who the caller works for.
The day agents start doing real work, a company has to say who they work for, what they may reach, what they may decide alone, and how anyone knows afterwards. These are those answers.
Owner, department, purpose, systems and ceiling, held once and read by everything. An API key proves a request is authentic. It says nothing about who the caller works for.
Name its department, its owner and what it is for. Access, policy and approval requirements follow from that, instead of being configured tool by tool.
Access ends, credentials are revoked and the work it was mid way through is handed on. The trail of what it did stays exactly where it was.
Issued against the agent, not against a person's login, rotated on a schedule and pulled the moment its owner or purpose changes.
What is running, who owns it, what it can reach, what it can change and which ones nobody has used since spring. Agent sprawl stops being invisible.
Define what an agent may reach and what it may change once. Every platform it runs on resolves against the same answer, so the rules cannot drift apart.