Public worksheet · identity · lifecycle · authority

Every acting agent needs an identity, an owner and an end-of-life path.

Use this worksheet to map the identity and access boundary before an AI agent gains consequential tools. It is a planning artifact — not certification and not proof that an IAM platform is correctly configured.

Identity record

Who actually acts?

  • Agent / workload name
  • Environment
  • Human sponsor / business owner
  • Technical owner
  • Identity provider
  • Workload/service identity
  • Credential type and lifetime
  • Revocation path
Authority inventory

What can that identity reach?

  • Resource / tool
  • Read / write / delete / high consequence
  • Credential and scope
  • Owner
  • Approval requirement
  • Target/resource binding
Lifecycle questions

Authority should not outlive its owner or purpose.

  1. 01Who creates the agent/workload identity?
  2. 02Who sponsors it while active?
  3. 03Who can revoke it?
  4. 04What happens when the human sponsor leaves?
  5. 05What happens when the agent/project is retired?
  6. 06Are dormant identities detected?
  7. 07Can the credential be reused outside the intended workflow?
Evidence fields

Make one consequential action attributable.

The exact evidence depends on the platform and engagement scope.

01Identity / workload identifier
02Human sponsor and technical owner
03Credential issuer and resource/audience
04Scopes / roles and issue / expiry timestamps
05Policy decision and approval reference
06Tool/action and target resource
07Resulting-state or revocation evidence
Review outcomes

PASS · PARTIAL · FAIL · NOT TESTED · N/A

Keep domain-level results visible instead of inventing one universal identity-security score.

Claim boundary

Identity review is bounded engineering evidence.

No certification and no guarantee that unauthorized access or unknown bypasses cannot exist outside the tested scope.