Research

Watch · narrated whiteboard episodesL2

Agent Identity and Lifecycle Governance

An autonomous agent is a non-human principal that provisions itself, calls other services, delegates to sub-agents, and outlives any single request — and human identity systems were never designed for it. This series builds operational identity governance for agents from the ground up: why agents break human IAM and what a machine identity actually needs, how to provision and attest an identity so its bearer can be proven rather than assumed, how to run the credential lifecycle with short-lived tokens, rotation, and bounded delegation chains at runtime, how to decommission and revoke an agent's authority cleanly and provably, and how to govern a whole fleet with an identity inventory, least-privilege drift detection, and lifecycle audit. Grounded in NIST SP 800-207 Zero Trust Architecture, NIST SP 800-63 Digital Identity Guidelines, the SPIFFE workload-identity specification, the OAuth 2.0 and Token Exchange RFCs, the OWASP Agentic Security Initiative, and the NIST AI RMF.

Murali Chillakuru·5 episodes
  1. 12 min Episode 1Non-Human Identity for Agents: Why Agents Break Human IAM and What a Machine Identity NeedsA moderator and a staff engineer work through why identity built for people fails autonomous agents, and what a machine identity must actually provide.
  2. 11 min Episode 2Provisioning and Attestation: Issuing, Binding, and Proving an Agent's IdentityA moderator and a staff engineer work through how a brand-new workload with no secret earns a trustworthy, bound identity — through attestation.
  3. 11 min Episode 3Credential Lifecycle: Short-Lived Tokens, Rotation, and Delegation Chains at RuntimeA moderator and a staff engineer work through how an agent credential should behave over time — born expiring, rotated without downtime, and narrowed down every delegation hop.
  4. 11 min Episode 4Decommissioning and Revocation: Killing an Agent's Authority Cleanly and ProvablyA moderator and a staff engineer work through how to end an agent's authority the moment you decide to — completely, and in a way you can prove.
  5. 11 min Episode 5Governing the Fleet: Identity Inventory, Least-Privilege Drift, and Lifecycle AuditA moderator and a staff engineer work through how to secure a whole population of agent identities — knowing every one, catching privilege that creeps, and proving the lifecycle holds.