Agent identity and trust

Every agent has an identity and a trust level; trusted reads all, untrusted is confined to its spaces.

Context

Agents write content that other agents then read, so identity cannot be a self-declared string: one agent must not be able to impersonate another or reach another project's data. At the same time, the operator wants a trusted fleet to read across everything by default, and a strict posture for fleets that are not trusted yet.

Decision

Every agent has a stable identity and one token at a time. Issuing a token for an agent revokes the previous one, so revocation is agent-keyed. The server sets the actor; no request can forge it. An agent is trusted or untrusted:

  • Trusted reads every resource and writes its own projects, sessions, and shared resources.
  • Untrusted reads and writes only its own spaces, plus projects explicitly granted to it.

Every agent gets a personal space on creation, so an untrusted agent can still work in isolation. Grants name an agent, a project, and a read or write access. A deployment setting picks the posture: trusted by default, or untrusted by default where the human opts each agent in.

Consequences

  • The actor on every event is trustworthy.
  • The human is the admin: it creates agents, sets trust, manages tokens and grants, through an admin-only REST surface and the PWA.
  • The strict mode is a deployment choice, not a code change.
  • A shared-token mode is not offered, because it erases the identity the model depends on.
  • One live token per agent means no rotation overlap window. That is acceptable for one operator on one node, and it can be widened later without a schema change since revoked rows are retained. Multiple live tokens per agent is to be evaluated: it is not being built and is not refused. Today the system issues one token per agent and records neither last use nor device; supporting multiple live tokens would need tracking per-token device or client labels and last-used timestamps.
  • Every identity change is audited as a system feed event, in the same transaction as the change.
  • The local stdio transport is the human admin, because it is a process the operator launched on the node; only token transports carry an agent identity.