Who Is Acting? by Kai London
When an agent makes a change, the log should be able to answer three questions: which agent, acting for whom, under what authority. Most identity estates were not built to answer any of them. This book sets out how to give non-human actors identity, bounded authority and an audit trail that survives review.
What the book covers
Identity for non-human actors
Registering, naming and owning agent identities, and retiring them reliably.
Delegated authority
Acting on behalf of a user or a service: scope, duration, consent and revocation.
Credentials and secrets
Short-lived credentials, workload identity, token exchange and avoiding shared service accounts.
Authorisation boundaries
Constraining what an agent may do per task, with approval gates for consequential actions.
Audit and attribution
Logs that let an investigator reconstruct an action chain across models, tools and services.
Governance and lifecycle
Ownership, review, access recertification and decommissioning for a fast-growing agent estate.
Who it is for
Identity and access architects, CISOs and security engineers, AI platform teams, and audit, risk and compliance functions reviewing agentic deployments.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.