Identity · Agentic AI

Who Is Acting? by Kai London

When an agent makes a change, the log should be able to answer three questions: which agent, acting for whom, under what authority. Most identity estates were not built to answer any of them. This book sets out how to give non-human actors identity, bounded authority and an audit trail that survives review.

Coming soonAll books

What the book covers

Identity for non-human actors

Registering, naming and owning agent identities, and retiring them reliably.

Delegated authority

Acting on behalf of a user or a service: scope, duration, consent and revocation.

Credentials and secrets

Short-lived credentials, workload identity, token exchange and avoiding shared service accounts.

Authorisation boundaries

Constraining what an agent may do per task, with approval gates for consequential actions.

Audit and attribution

Logs that let an investigator reconstruct an action chain across models, tools and services.

Governance and lifecycle

Ownership, review, access recertification and decommissioning for a fast-growing agent estate.

ISO/IEC 42001NIST AI RMFZero TrustNIS2

Who it is for

Identity and access architects, CISOs and security engineers, AI platform teams, and audit, risk and compliance functions reviewing agentic deployments.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.