Agent Access Control: Pilot → Production

Production AI agents need to act on behalf of a human or a service, not with a shared "agent token." That single constraint reshapes identity, authorization, and audit across the whole stack.

This is a six-part series working from first principles to a production-ready architecture.

  1. Part 1, Identity Mesh and Secure AI Agents(published)

    Subject / Actor / Authority, per-action scoped access, and why consistent policy decisions across tools require an identity mesh.

  2. Part 2, Policy Enforcement(in progress)

    Where authorization actually happens, at the tool call, and how to evaluate policy per action without burying it in agent code.

  3. Part 3, Tool & Data Boundaries

    Scoping what an agent can reach: connectors, data planes, and the difference between capability and permission.

  4. Part 4, Agent Runtimes & Monitoring

    Workload identity for the runtime, observability for delegated actions, and catching drift before it becomes an incident.

  5. Part 5, Evidence Trails

    What a defensible audit record looks like when an agent acted on behalf of someone, for security, compliance, and debugging.

  6. Part 6, From Pilot to Production

    Putting the pieces together: a production-ready architecture, rollout patterns, and the failure modes that kill pilots.

Companion piece

Outside the numbered series, but part of the same argument:

Enterprise-Managed Authorization for MCP (ID-JAG) →

Get each part as it ships →

Get the series as it ships

New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.

about

Ehsan Hosseini

Ehsan Hosseini

me [at] ehosseini [dot] info

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it. I write about it here, and build it at my company.