Episode 209 - GluuFederation/identerati-office-hours GitHub Wiki

Title: The 7 Laws of AIdentity

Channels

Description

AI agents do more than present identity—they generate intent, delegate authority, invoke tools, and create real-world consequences. In this episode, Patrick Parker joins us to discuss his proposed Seven Laws of AIdentity, including (1) split actors, (2) bounded agency, (3) continuous authorization, (4) least exposure, (5) trustworthy action chains, and (6) proof-carrying actions. We’ll explore why governing agents requires moving the control point from login to action—and replacing incomplete logs with verifiable evidence of who acted, under whose authority, through which chain, and with what outcome. What is law 7? Tune in to find out!

Homework

Takeaways

  • ⚡ Without distinct identities for the human, agent, authorizer, credential holder, and executor, accountability is impossible.
  • ⚡ An agent’s specific intent emerges after delegation, so material actions must be evaluated when generated.
  • ⚡ A gateway is only one control point. Continuous authorization must extend through discovery, invocation, credential use, execution, and outcome.
  • ⚡ Agents should receive results, not credentials. Brokered execution can preserve delegated authority while keeping OAuth tokens and secrets outside the agent.
  • ⚡ Capability metadata can connect agent operations to risk classification, segregation of duties, reporting, and GovOps metrics.

Livestream Archive