
Ehsan Hosseini
I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it.
For AI agents, authentication is largely solved. Authorization is not. I write about the identity, delegation, and audit primitives that decide what an agent is actually allowed to do, and I build them at my company.
Currently
- - Writing Agent Access Control: Pilot → Production, a six-part series
- - Building an access control layer for enterprise AI at my company
- - Tracking the IETF drafts on agentic delegation and token attenuation
- - Working through what the EU AI Act's audit trail requirements mean in practice
Get the series as it ships
New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.