Digital workforce · machine actors
If agents become workers, they need defined authority.
The useful enterprise analogy is not a humanoid employee. It is a machine actor: software that can receive a goal, access data, use tools, communicate with other agents and sometimes change business state.
Human organisations already govern identity, role, ownership, permissions, delegation, records and revocation. As AI systems gain agency, equivalent control concepts need to exist for the software actors operating inside the company.
Identity · ownership · permissions · delegation · expiry · revocation · audit
Machine actor record
AP-042 · Commercial Review Agent
Owner
Commercial Director
Tenant
Example organisation
Purpose
Prepare variation evidence
Status
Active · bounded
Data
Project + contract records
Tools
Search · cost model · draft
Action ceiling
Prepare only
Approver
Commercial Manager
Authority state
First principle
Human users and machine actors are not the same identity problem.
A human signs in, understands organisational context and can be held directly accountable. A software workload may run continuously, hold credentials, make dynamic decisions and operate faster than any human supervisor can manually inspect.
Microsoft describes workload identities as identities assigned to software workloads so they can authenticate and access resources. SPIFFE similarly treats workload identity as a first-class security primitive. AI agents add a further governance question: not merely who is calling?, but what purpose, authority and decision boundary has this machine actor been granted?
The future company may have more machine actors than human users. They cannot be invisible.
Identity before autonomy
Identity
Which exact machine actor is this?
A stable identifier tied to a known trust and tenant boundary.
Authority
What may this actor access and do?
Data, tools, actions, delegation and thresholds expressed outside the prompt.
Accountability
Who owns the actor and its outcomes?
A named business owner, human approver, review cycle and reconstructable evidence.
An API key proves access to a service. It does not define business authority.
TEMRIK architecture concept
Interactive explorer
Inspect Maya's Agent Passport.
Maya is an illustrative Commercial Analyst. Select any passport field to see what it means, why it matters, what failure looks like and how the control should work.
Selected control
Agent ID
A stable identity for the machine actor.
What it means
Identifies one machine actor distinctly from users and services.
Why it matters
Without it, activity can be hard to attribute.
Example
Maya-COM-01
What failure looks like
activity can be hard to attribute.
TEMRIK control
Identity registry and workflow binding.
TEMRIK architecture concept · not a claim of current deployment
The Agent Passport.
A governance record that binds a machine actor to purpose, ownership, permissions, delegation boundaries, human authority and lifecycle state. It complements runtime identity; it does not replace an identity provider, OAuth, workload identity or A2A security.
Agent ID
Stable machine identity
Owner
Accountable human or function
Tenant
Organisational boundary
Purpose
Approved business objective
Model
Runtime model or provider class
Allowed data
Permitted information domains
Tools
Approved capabilities
Delegation rights
What work may be handed off
Action ceiling
Maximum consequence without approval
Human approver
Escalation authority
Expiry
When authority must be renewed
Status
Active · paused · revoked
Audit history
Material identity and authority events
Runtime identity
Prove which workload is calling.
Workload identity technologies can authenticate software without treating it as a human account. Patterns such as managed identities, federated workload identities and SPIFFE short-lived credentials reduce dependence on long-lived embedded secrets.
Governance identity
Prove why that workload is allowed to act.
The business still needs an explicit record of owner, approved purpose, data scope, tools, delegation, action ceiling, approver, expiry and status. This is the additional control problem the Agent Passport is designed to make legible.
Ownership
Every agent needs an accountable owner.
Ownership is not the same as authorship. The engineer who built an agent may not be the business person who should approve its purpose, data access or operating threshold.
Business owner
Owns the business outcome and acceptable operating boundary.
Technical owner
Owns runtime, integrations, reliability and identity implementation.
Data owner
Approves access to governed data domains.
Human approver
Holds decision authority for consequential exceptions or releases.
Security owner
Defines credential, access and incident requirements.
Reviewer
Periodically re-validates the passport and continued need.
Credentials
Do not confuse the agent with its credentials.
Credentials are evidence used to authenticate or obtain access. They should be scoped, rotated, revocable and—where infrastructure permits—short-lived or federated instead of permanently embedded in prompts, source code or agent memory.
Higher operational burden
Long-lived secret
Avoid where a stronger workload-identity pattern is available.
Platform-managed credentials
Managed identity
Useful when the hosting platform and target resource support it.
Trust without duplicated static secrets
Federated identity
Useful across CI, Kubernetes and cross-cloud scenarios.
Portable workload identity
SPIFFE / SVID
Useful where cryptographically verifiable workload identity and trust domains fit the architecture.
Permissions and action ceiling
Permission should describe more than a tool list.
A machine actor may have permission to call a finance system but still lack authority to release a payment. TEMRIK separates capability from consequence through the idea of an action ceiling.
Observe
Read approved information
No external state change
Prepare
Draft, classify, assemble evidence
Human releases the work
Recommend
Propose a decision or next action
Named human approval
Act
Execute low-consequence approved actions
Bounded by policy and thresholds
Escalate
Stop and request higher authority
Required for exceptions and high consequence
Tool access answers “can it call this?” Action authority answers “may the business allow this outcome?”
Delegation
Delegation cannot create authority from nowhere.
Multi-agent systems may hand tasks to specialists. That handoff should not silently grant the receiving agent broader data, tools or action rights than the originating business authority allows.
Agent A
Authenticated actor
Delegate
Defined task
Agent B
Known identity
Policy
Intersect rights
Result
Return + evidence
A safe default is delegated authority = the intersection of the delegator’s remaining authority, the delegate’s own passport and the policy for the requested task.
Agent to agent
Discovery is not trust. An Agent Card is not an approval.
A2A Agent Card
The A2A protocol uses Agent Cards to advertise an agent’s identity metadata, capabilities, endpoint, skills and authentication requirements. It relies on standard web security mechanisms for authentication and leaves authorisation to the implementation.
Enterprise policy
The company still decides whether this agent may be discovered, invoked, trusted for a specific skill, supplied with a particular data class, delegated a task or allowed to trigger an external action.
Identity enables interaction. Policy grants authority.
Expiry and revocation
Authority should decay unless deliberately renewed.
Time expiry
Passport requires renewal after a fixed review period.
Owner change
Pause when the accountable owner leaves or changes role.
Purpose change
Re-authorise when the business objective materially changes.
Permission change
Re-test when tools, data or action rights expand.
Model / runtime change
Review when a material technical assumption changes.
Security event
Immediate pause or revocation where compromise is suspected.
Revocation should address more than a UI status. Depending on the architecture it can require invalidating credentials, terminating sessions, disabling service identities, removing tool access, blocking A2A invocation and preventing queued work from releasing.
Supervision
Supervise the material events, not every token.
A useful digital-workforce control model records operational evidence: identity, goal, data boundary, tool use, delegations, policy decisions, approvals, exceptions, released actions and outcomes. It does not require exposing private model chain-of-thought.
See the wider TEMRIK AI security architecture for identity, tenant boundaries, tool control and audit design.
Lifecycle
An agent should have a lifecycle, not just an API endpoint.
Register
Create a unique machine identity and bind it to a tenant, owner and approved purpose.
Attest
Establish that the running workload is the workload that should receive the identity.
Authorise
Grant the minimum data, tool, skill and action rights needed for the role.
Activate
Permit operation only after required policy, test and human checks are satisfied.
Supervise
Observe tool use, delegation, exceptions, approvals and material outcomes.
Review
Reconfirm purpose, owner, permissions, credentials, model assumptions and action ceiling.
Expire
End authority automatically unless a defined renewal condition is met.
Revoke
Disable identity, credentials, sessions and downstream access when risk or ownership changes.
TEMRIK control model
Machine actors belong inside the control plane.
The TEMRIK AI control plane is the architectural layer intended to keep company policy, identity, playbooks, tools, human authority and evidence around the models and agents doing the work.
Company policy
Purpose · risk · decision rights
Agent Passport
Identity · owner · tenant · lifecycle
Data + tools
Least privilege · scoped capabilities
Agent runtime
Model · orchestration · delegation
Dispatcher gate
Allow · restrict · approve · escalate
Human authority
Named approver · exception owner
Audit
Identity · action · outcome · review
Research & standards
Primary sources behind this architecture.
The sources below describe workload identity, agent-specific identity, A2A discovery and agent runtime control patterns. TEMRIK does not imply partnership, certification or implementation parity with these organisations.
NIST
Why agentic AI needs a strong identity foundation
August 2026 guidance on applying established identity and authorisation foundations to agentic AI.
Open primary source in a new tabNIST
Security Considerations for AI Agents
2026 analysis of agent security risks and the need to adapt conventional cybersecurity controls.
Open primary source in a new tabMicrosoft Entra
Workload identities and agent identities
Machine identities, service principals, managed identities and agent-specific lifecycle governance concepts.
Open primary source in a new tabAWS
Amazon Bedrock AgentCore Identity
Agent-specific authentication, authorisation and credential management using workload-identity patterns.
Open primary source in a new tabSPIFFE
SPIFFE workload identity concepts
Workload IDs, trust domains, verifiable identity documents and short-lived credential patterns.
Open primary source in a new tabA2A Protocol
Agent Cards and enterprise security
Agent discovery metadata, authentication requirements, tasks and interoperable agent communication.
Open primary source in a new tabOpenAI
Agents SDK
Agent loops, tools, orchestration, handoffs, guardrails, human review and observability.
Open primary source in a new tabRelated architecture
Start with one machine actor
Design an Agent Passport for one workflow.
Define the owner, purpose, data, tools, delegation rights, action ceiling, approver, expiry and audit events before expanding autonomy.
AI capability can expand without organisational authority becoming ambiguous. Explore controlled business AI with TEMRIK.