Episode 203 - GluuFederation/identerati-office-hours GitHub Wiki

Title: We Solved Identity. Then We Hired Agents

Channels

Description

For years we told ourselves identity was solved. We know who you are, we know what you're allowed to do, ship it. Then we hired agents that act on their own, and the tidy story started to fray. Authentication and authorization tell us who's at the door and what they can touch. Neither was built for the questions agentic systems now force into the control plane, and they're governance questions: Who created this entity? Who trained it? Who authorized it? Who can revoke it? Who is it economically aligned to? This session is about that gap, and what changes when we treat authorship as identity's third pillar. Steve shares why he launched AuthR as an open protocol to give that pillar a home.

Homework

Takeaways

  • ⚡ AuthR = Authorship Representation. It indicates a challenge when there are multiple principals--agents, humans, organizations--and it may be hard to determine which originates the original agentic action.

  • ⚡ Steve argues "Intent" may be the new perimeter. Eve Maler, Nick Gamb, Dick Hardt, Karl McGuinness agree that "intent" is an important part of agentic authorization.

  • ⚡ Agent governance has to move into runtime. AuthR’s bet is that agentic systems need embedded governance for intent, scope, provenance, drift, and revocation—not just more attributes bolted onto OAuth.

  • ⚡ Agentic security is embryonic. What is the right identifier for agents and sub-agents? What credentials should agents use for authentication? What claims are needed to describe agents? Do agents attest or register? How are agents discovered? What tokens are issued to agents? What flows are used to obtain those tokens? How do we write the authz policies absed on those tokens? How do we govern--manage risk, and hold entities accountable? And there are a myriad more questions... so much of this is unknown right now.

Livestream Archive