Episode 209 - GluuFederation/identerati-office-hours GitHub Wiki
Title: The 7 Laws of AIdentity
- Host: Mike Schwartz, Founder/CEO Gluu
- Guest: Patrick Parker, Founder and CEO EmpowerID
Channels
Description
AI agents do more than present identity—they generate intent, delegate authority, invoke tools, and create real-world consequences. In this episode, Patrick Parker joins us to discuss his proposed Seven Laws of AIdentity, including (1) split actors, (2) bounded agency, (3) continuous authorization, (4) least exposure, (5) trustworthy action chains, and (6) proof-carrying actions. We’ll explore why governing agents requires moving the control point from login to action—and replacing incomplete logs with verifiable evidence of who acted, under whose authority, through which chain, and with what outcome. What is law 7? Tune in to find out!
Homework
- Linkedin Article: The Laws of AIdentity
- WSJ Video: We Let AI Run a Vending Machine. It Lost All the Money.
Takeaways
- ⚡ Without distinct identities for the human, agent, authorizer, credential holder, and executor, accountability is impossible.
- ⚡ An agent’s specific intent emerges after delegation, so material actions must be evaluated when generated.
- ⚡ A gateway is only one control point. Continuous authorization must extend through discovery, invocation, credential use, execution, and outcome.
- ⚡ Agents should receive results, not credentials. Brokered execution can preserve delegated authority while keeping OAuth tokens and secrets outside the agent.
- ⚡ Capability metadata can connect agent operations to risk classification, segregation of duties, reporting, and GovOps metrics.