Tag: AI Agents

Broad credentials made sense when fixed application logic stood between users and actions, but AI agents have changed that equation.
What began as a way for agents to call tools is expanding into infrastructure for longer-running, governed interactions across enterprise systems.
When one identity acts for another, the token model determines what downstream systems can actually see, trust, and audit.
Stateless requests, explicit state, and routing metadata bring familiar distributed-systems patterns to agent infrastructure at scale.
Breaches involve non-human identity credentials more than ever, and that trend should continue. Here is a catalog of those incidents, with advice for mitigating the risk.