Skip to content

Agent identity, ownership and organisation

Agentic governance starts with a stable identity. An agent name or job title is not an identity and does not grant authority. The Agent Register, Identity & Ownership and Organisation Chart establish who or what the agent is, who is accountable and where escalation goes.

Create one record for each independently governed agent boundary. Record purpose, owner, operating status, runtime, model, environment, data access, tools, autonomy, criticality and review dates. Separate agents when they have materially different authority, owners, runtime identities or failure consequences.

An active register entry is necessary but not sufficient for execution. Tool Permissions, a ready connection, an active Runtime Access Policy and any required approval must also pass.

Bind the governance record to the runtime identity used in authenticated requests. Record the business owner, technical owner and accountable executive or service owner as appropriate. Owners remain responsible for purpose, risk, access review, incidents and retirement; the agent cannot own its own risk acceptance.

Rotate or revoke runtime identity material through the approved service workflow. Never place raw credentials, service secrets or private keys in the Agent Register.

The chart explains reporting, delegation and escalation. It can help determine who must be consulted or approve a high-impact action, but position in the chart does not create runtime permission. Gateway evaluates exact policy and request context.

  1. Register the agent and owners.
  2. Complete risk tiering and ATF assessment.
  3. Configure least-privilege tools and governed connections.
  4. Validate simulations and approval paths.
  5. Activate only the authority required for the intended environment.
  6. Review after change, incident, expiry or owner transfer.
  7. Suspend identity and runtime authority before retirement.
  • Unique agent boundary and runtime identity.
  • Named, current human owners.
  • Purpose and prohibited purposes defined.
  • Environment and data boundaries recorded.
  • Escalation path is usable but not treated as permission.
  • Dormant, duplicate and retired identities are disabled.