Agent Identity and Authorization: NHI Design for AI Agents
Originally published at Agent Identity and Authorization: NHI Design for AI Agents on smartgate.network. A shorter version of "Agent Identity and Authorization: NHI Design for AI Agents" — the full piece lives at smart
Originally published at Agent Identity and Authorization: NHI Design for AI Agents on smartgate.network.
A shorter version of "Agent Identity and Authorization: NHI Design for AI Agents" — the full piece lives at smartgate.network.
What the full piece covers
- What agent identity is, and why it is not a user account — An agent identity is the account a software workload authenticates with when it acts on its own.
- Non human identity: the workload account, one layer down — Non human identity (NHI) is the umbrella term for every account a machine rather than a person authenticates with: service accounts, API keys and client secrets, service principals, workload and managed identities, certificates, and the tokens automation holds on their …
- Agent authentication: proving which workload is calling — Authentication answers a single question — is this really the workload it claims to be — and the menu of mechanisms is now much wider than the shared API key most agents still use.
- Agent authorization: from a valid credential to a permitted action — Authentication says who is calling; authorization decides what that identity may do, and conflating them is the most common mistake in agent platforms.
- Agent identity management: issuance, rotation and revocation — Identity management is the lifecycle around the credential, and it is where most agent deployments are weakest, because the fast path — create a key, paste it into a config, move on — has no lifecycle at all.
- AI agent access control: scopes, least privilege and boundaries — Access control for an agent is the set of rules that decide which call proceeds, and the useful move is to build it as a boundary outside the model rather than a sentence inside the prompt.
- Agent access control when agents call other agents — Multi-agent systems turn identity from a property of one workload into a property of a chain, and the chain is where authority usually leaks.
- Audit attribution: whose identity is on the action — Attribution is the question an incident review actually asks: not "what happened" but "whose identity did this".
- How identity travels with a call, read from our own context — "Attribute the action to an identity" sounds like one field.
- Where SmartGate fits — SmartGate does not try to be the identity provider for your fleet, and this page will not claim otherwise.
- …plus 2 more section(s).
Read the full piece: Agent Identity and Authorization: NHI Design for AI Agents on smartgate.network.
Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.