A new protocol proposes a clearer way to connect agent identity, delegated authority and human approval for sensitive actions. AAuth is an authentication and authorization protocol for AI agents inspired by OAuth and OIDC. It authenticates and authorizes agents without the need for a human; it lets agents act on behalf of humans with a separate set of credentials (delegation), and optionally supports human approval before granting access (human in the loop).
An exercise ended with frontier models inside a platform’s production systems, exposing a hard truth about what agents can do with credentials that systems trust.
Visibility tells you what your agents are doing. Enforcement determines what they’re allowed to do. Here’s what the Aembit team saw at Identiverse that confirmed the gap.
Aembit now supports Microsoft Copilot Studio, giving security teams secure agent authentication to enterprise resources, least-privilege access at runtime, and a complete audit trail of every access event.
A working prototype can mask the harder problem: keeping every workload, agent, credential, policy, and audit trail consistent across production environments.