Direct answer
Every Agent Is a Non-Human Identity — what is the operational point?
#An AI agent that can access data or invoke tools is an identity with delegated power, not merely a prompt or model endpoint. It needs a named owner, task-scoped credentials, least-agency limits, lifecycle controls, and reviewable activity.
- Issue short-lived, task-scoped credentials where practical.
- Separate planner authority from executor authority.
- Log grants, denials, delegation, and tool use.
Source basis: reviewed synthesis of the strategy corpus. Report-derived claims remain subject to the verification boundary in the source library.