Resolve the acting identity
Connect the agent to the user or service identity it represents and the authority passed to it.
PLATFORM CAPABILITY / IDENTITY AND ACCESS FOR AI AGENTS
A tool credential is only one part of authorization. Evaluate the user, delegated scope and task alongside existing permissions before an agent acts.
Early access. Already in paid production.
Prepare a vendor renewal summary.
The user delegated contract review, not payment administration.
A PLAUSIBLE ACTION. A MATERIAL RISK.
Access to a credential does not expand the scope of the delegated task.
Try a context challengeThe user delegated contract review, not payment administration.
BlockFROM VISIBILITY TO CONTROL
Connect the agent to the user or service identity it represents and the authority passed to it.
Consider existing permissions alongside the task, resource and policy. Investigate overly broad access instead of treating it as sufficient authorization.
Use configured policies to permit work within scope and hold or block actions that exceed it.
INSIDE ACKUITY
The OPA Rules screen shows configurable policies for agent routing, MCP calls and other execution boundaries.
See it with your team
YOUR QUESTIONS, ANSWERED
Agents need identifiable authority and controlled access. Their actions should be evaluated against both their credentials and the user or service scope under which they operate.
The execution trust layer complements identity systems. It brings identity and permission context into the assessment of proposed agent actions.
A role may be overly broad, stale or unrelated to the current task. Delegation can also lose scope across agents. These conditions require context beyond whether a credential can call a tool.
CONTINUE YOUR REVIEW
NEXT STEP
Review your environment and the controls your team needs. Begin with read-only discovery.