Agent Access Control: Pilot → Production

Production AI agents need to act on behalf of a human or a service, not with a shared "agent token." That single constraint reshapes identity, authorization, and audit across the whole stack.

This is a six-part series working from first principles to a production-ready architecture.

  1. Part 1, Identity Mesh and Secure AI Agents(published)

    Subject / Actor / Authority, per-action scoped access, and why consistent policy decisions across tools require an identity mesh.

  2. Part 2, Policy Enforcement(in progress)

    Where authorization actually happens, at the tool call, and how to evaluate policy per action without burying it in agent code.

  3. Part 3, Tool & Data Boundaries

    Scoping what an agent can reach: connectors, data planes, and the difference between capability and permission.

  4. Part 4, Agent Runtimes & Monitoring

    Workload identity for the runtime, observability for delegated actions, and catching drift before it becomes an incident.

  5. Part 5, Evidence Trails

    What a defensible audit record looks like when an agent acted on behalf of someone, for security, compliance, and debugging.

  6. Part 6, From Pilot to Production

    Putting the pieces together: a production-ready architecture, rollout patterns, and the failure modes that kill pilots.

Companion piece

Outside the numbered series, but part of the same argument:

Enterprise-Managed Authorization for MCP (ID-JAG) →

Get each part as it ships →

Get the series as it ships

New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.

about

Ehsan Hosseini

Ehsan Hosseini

me [at] ehosseini [dot] info

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it. I write about it here, and build it at my company.

How it works?

I write what I learn while building systems that decide what an AI agent is allowed to do. The thinking, the arguments, and the calls about what's true are mine. I use AI to draft, structure, and speed up research, the same way I'd use any other tool. It doesn't decide what I believe.

I check technical claims against primary sources before a post goes out: the specs, the RFCs, the original documentation, not a model's memory of them. When I'm uncertain, I say so. When something is opinion rather than fact, I mark it as one. If I get something wrong, that's on me.

© 2026 Ehsan Hosseini. All rights reserved.