Tags

63 Tags

Agentic Identity

63 posts
  1. Kerberos Won Because Nobody Had to Implement It The SSPI Question for Agent Authorization
  2. The Runtime Mints the Identity. That Does Not Make It the Authority. The Agent Identity Market Will Be Decided at the Binding Layer
  3. Agent Authority Has No General System of Record The Third Control Point Is the Approved Task, and Its General Record Does Not Exist Yet
  4. The MCP Lesson Running Code Creates the Wedge. Governance Consolidates What Survives.
  5. Cross App Access Shows How the Layered Play Ships The MCP Extension Is Stable. The First Loop Is Live. The Partner Ecosystem Is Still Rolling Out.
View all 63

Authorization

57 posts
  1. Kerberos Won Because Nobody Had to Implement It The SSPI Question for Agent Authorization
  2. Agent Authority Has No General System of Record The Third Control Point Is the Approved Task, and Its General Record Does Not Exist Yet
  3. A Blocked Agent Is a Captive Client
  4. The Company's Memory Must Be an Enterprise Record Inference Is Rented. Institutional Knowledge Must Survive the Supplier.
  5. Continuity Is Not One Thing The Four Questions of Delegated Work, and the Invariants That Compose Their Answers
View all 57

Delegated Authority

19 posts
  1. A Blocked Agent Is a Captive Client
  2. Continuity Is Not One Thing The Four Questions of Delegated Work, and the Invariants That Compose Their Answers
  3. Common Objections to Mission-Based Authorization Answers for the People Who Run Today's Control Planes
  4. The Question Authorization Never Answered A History of Delegated Authority, from Passwords to Missions
  5. Answering the Laws of AIdentity A Critical Crosswalk from Patrick Parker's Seven Laws to Mission-Bound Authorization
View all 19

Intent-Based Authorization

9 posts
  1. Mission-Based Authorization: The Field Reference The Category, the Litmus Test, the Landscape, and the Running Example
  2. The Agent Runtime and Audit Sessions Are Not Authority, Safe Unwinding, and Tamper-Evident Evidence
  3. Mission Lifecycle and Change Observe, Revoke, Grow, Complete
  4. Mission-Bound Runtime Enforcement From Mission-Bound Tokens to Mission-Bound Actions
  5. Mission-Bound Authority: Instances, Actors, and Delegation From Authenticated Agent Identity to Bounded, Narrowing Authority
View all 9

Interoperability

6 posts
  1. The Runtime Mints the Identity. That Does Not Make It the Authority. The Agent Identity Market Will Be Decided at the Binding Layer
  2. Agent Authority Has No General System of Record The Third Control Point Is the Approved Task, and Its General Record Does Not Exist Yet
  3. The MCP Lesson Running Code Creates the Wedge. Governance Consolidates What Survives.
  4. Cross App Access Shows How the Layered Play Ships The MCP Extension Is Stable. The First Loop Is Live. The Partner Ecosystem Is Still Rolling Out.
  5. The Company's Memory Must Be an Enterprise Record Inference Is Rented. Institutional Knowledge Must Survive the Supplier.
View all 6

MCP

10 posts
  1. Kerberos Won Because Nobody Had to Implement It The SSPI Question for Agent Authorization
  2. The MCP Lesson Running Code Creates the Wedge. Governance Consolidates What Survives.
  3. Cross App Access Shows How the Layered Play Ships The MCP Extension Is Stable. The First Loop Is Live. The Partner Ecosystem Is Still Rolling Out.
  4. Least-Privilege MCP Tool Calls Need a Mission Token-Side and Resource-Side Authorization Are Two Projections of One Approved Task
  5. Least Exposure Is Broader Than Least Privilege Bounding What an Agent May See, Not Just What It May Do
View all 10

OAuth

49 posts
  1. Kerberos Won Because Nobody Had to Implement It The SSPI Question for Agent Authorization
  2. The Runtime Mints the Identity. That Does Not Make It the Authority. The Agent Identity Market Will Be Decided at the Binding Layer
  3. Agent Authority Has No General System of Record The Third Control Point Is the Approved Task, and Its General Record Does Not Exist Yet
  4. The MCP Lesson Running Code Creates the Wedge. Governance Consolidates What Survives.
  5. Cross App Access Shows How the Layered Play Ships The MCP Extension Is Stable. The First Loop Is Live. The Partner Ecosystem Is Still Rolling Out.
View all 49

Security Architecture

12 posts
  1. The Mission-Based Authorization Vendor Test Six Questions for Anyone Claiming Agent Authorization
  2. Containing the OWASP Agentic Threats Fifteen Agentic Threats and the LLM Top 10, Each Given a Verdict
  3. Splitting the Lethal Trifecta How Mission-Bound Authorization Contains the Defining Agent Threat Model
  4. Canceling the Card Doesn't Stop the Charges Endings, Unwindings, and the Statement That Reconciles It All
  5. The Network Approves Every Transaction, Not the Card Per-Action Authorization, and the Escape Hatch Called Cash
View all 12

Standards

19 posts
  1. Kerberos Won Because Nobody Had to Implement It The SSPI Question for Agent Authorization
  2. The Runtime Mints the Identity. That Does Not Make It the Authority. The Agent Identity Market Will Be Decided at the Binding Layer
  3. Agent Authority Has No General System of Record The Third Control Point Is the Approved Task, and Its General Record Does Not Exist Yet
  4. The MCP Lesson Running Code Creates the Wedge. Governance Consolidates What Survives.
  5. Cross App Access Shows How the Layered Play Ships The MCP Extension Is Stable. The First Loop Is Live. The Partner Ecosystem Is Still Rolling Out.
View all 19