Tesseris logo
TESSERIS
Agent Identity Becomes the Security Perimeter

Agent Identity Becomes the Security Perimeter

A critical ServiceNow AI flaw and new work on runtime authority, agent discovery and interoperability show why credentials cannot secure autonomous systems.

10 min read
Date: Jul 19, 2026
Tag: Market Insights

Executive Signal: Agent Security Is Moving From Login to Continuous Authority

The July 19 evidence set shows agent security moving beyond conventional authentication.

ServiceNow addressed a critical remote code execution vulnerability affecting part of its AI platform. Akeyless argued that protecting credentials does not govern what an agent does after login. Identity specialists called for every agent and connected Model Context Protocol service to receive its own managed identity. An Internet Draft proposed identity, delegation integrity and audit as foundations for interoperable agent communication. AgentSearch research framed the discovery and ranking of agents as a new information retrieval problem.

Together, these developments point to a sharper security conclusion: the perimeter is no longer the login event. The perimeter is the complete agent execution chain.

Tesseris signal: Persistent identity, continuous authority, runtime integrity and execution evidence must remain connected throughout every consequential action.

Authentication opens the door. Authority must govern every action.

Key Signals Across Agent Identity, Runtime Authority and Trust Infrastructure

  • Runtime risk: Agent platforms are becoming high-consequence attack surfaces because they connect workflow data, tools, credentials and operational systems.
  • Authority gap: Successful authentication does not prove that a later autonomous action is authorized.
  • Machine identity: Agents, subagents, tools, services, gateways and Model Context Protocol servers all need governed identities.
  • Interoperability: Open agent networks require portable identity, delegated authorization and audit evidence across organizational boundaries.
  • Discovery power: Agent search and ranking will influence which agents receive work, data access and economic opportunity.
  • Trust gap: Credentials, platform logs and self-declared capability are not enough to secure autonomous systems at execution time.

Why Agent Identity Is Becoming the New Security Perimeter

Human software security has long treated login as the primary gate. Once a user is authenticated, access controls decide which applications, files or services the account may reach.

AI agents break that model.

An agent can operate continuously, call tools, delegate work, invoke external services, remember context and complete actions faster than a person can supervise every step. The security question therefore changes from "Did this account log in?" to "Was this specific action performed by the right agent, for the right principal, inside the right runtime, under the right mandate, with the right evidence?"

That is why agent identity cannot be only a label. It must connect the software actor, controller, version, execution environment, delegated authority, policy state and outcome record.

In the Agent Economy, identity becomes useful only when it travels with authority and proof.

1. ServiceNow AI Vulnerability Shows Why Agent Runtime Integrity Matters

Source: NVD record for ServiceNow AI Platform remote code execution vulnerability CVE-2026-6875

ServiceNow addressed a critical remote code execution vulnerability affecting its AI platform.

Under certain conditions, an unauthenticated attacker could execute code inside the platform. ServiceNow deployed updates to hosted instances and supplied relevant updates to self-hosted customers and partners.

The vulnerability matters beyond one product. Enterprise agents increasingly connect workflow data, credentials, tools and operational systems inside one runtime. A compromise at that layer can inherit the authority of the complete agent environment.

Market signal: The agent runtime is becoming part of the enterprise security perimeter.

Security teams can no longer assess only the model, prompt or user account. They must also verify the runtime, sandbox, connectors, tool execution paths and software version carrying the agent's authority.

Tesseris read: Every consequential execution should identify the agent version, runtime version, active security posture, tools and connectors available, policy state, and evidence produced before and after execution.

A persistent agent identity should not imply that every environment running that agent is trustworthy.

Identity establishes the actor. Runtime attestation establishes whether the execution environment can be trusted.

2. Akeyless Separates Authentication From Runtime Authority

Source: Akeyless analysis on AI agent login and runtime access control

Akeyless argued that keeping passwords and secrets away from an AI agent solves only the login problem.

Once an authenticated session exists, an agent may still inherit everything the human account can do. The security system must distinguish between actions such as reading an invoice and changing a payout account, even when both occur inside the same valid session.

Akeyless proposed applying policy to each action, limiting target access, protecting returned data and preserving a record linking the human request, agent identity, policy decision and resulting execution.

Market signal: Authentication is becoming the beginning of agent security, not its conclusion.

Agent fleets operate too quickly for a person to approve every routine action. Authorization must therefore operate continuously at machine speed, with human review reserved for defined exceptions.

Tesseris read: A delegated mandate should travel with the task.

The enforcement point must evaluate who initiated the task, which agent is acting, what purpose was approved, which action is being attempted, which policy applies and whether the result remains inside scope.

A valid session proves access. A valid mandate proves authority.

3. Identity Security Expands From Agents to Every Connected Service

Source: iC Consult research on identity security for AI agents

iC Consult argued that every deployed agent creates a new machine identity requiring unique authentication, scoped permissions, lifecycle controls and auditability.

The identity problem also extends to external connections. Agents use Model Context Protocol servers to reach tools and data. Each connected server creates another access path and therefore requires its own identity, least-privilege policy and continuous monitoring.

This reframes agent security as an ecosystem problem. Securing the main agent while leaving tools and connectors weak protects only one participant in the execution chain.

Market signal: Every agent connection is becoming a trust boundary.

The relevant identity set includes agents, subagents, tools, services, gateways, memory systems and execution environments.

Tesseris read: Each participant should be treated as an identifiable primitive.

Every primitive should expose persistent identity, verified capability, security posture, approved access scope, lifecycle status and execution history. This allows a workflow to evaluate the complete actor chain rather than trusting an agent because its first connection was authenticated.

The weakest primitive can compromise the authority of the complete workflow.

4. Internet Draft Places Identity and Delegation Inside Agent Interoperability

Source: IETF Datatracker draft on the AI Agent Interoperable Protocol Framework

An updated Internet Draft proposed a layered framework for open agent communication across domains.

The framework covers discovery, verifiable agent identity, authentication, delegated authorization, protected communication, session continuity and audit. It also identifies intent and execution separation, delegation-chain integrity and nonrepudiation as security requirements.

The document is an individual Internet Draft. It has no formal IETF standing and may change or expire.

Market signal: Interoperability is becoming inseparable from trust.

Agents cannot safely communicate across organizations when identity, authorization and delegation are understood only inside the originating platform.

Tesseris read: A cross-domain workflow must preserve the original principal, every participating agent identity, the authority delegated at each stage, the capability requested, the execution evidence returned and the final accountable outcome.

Protocol interoperability lets agents exchange messages.

Federated trust determines whether those messages and actions should be accepted.

5. Agent Discovery Becomes a Ranking and Trust Problem

Source: ACM paper on AgentSearch for indexing, retrieval and ranking of AI agents

ACM published work framing AI agents as first-class objects that must be indexed, retrieved and ranked for particular tasks.

The development reflects a growing market problem. As the number of agents and tools increases, users and orchestration systems need a structured method for finding the right agent rather than selecting from a fixed list.

Agent discovery therefore begins to resemble search, but the ranking target is an actor that may receive data, authority and economic opportunity.

Market signal: Agent search will influence who receives work in the Agent Economy.

A ranking system can shape distribution, revenue and reputation. It must therefore evaluate more than textual similarity between a request and an agent description.

Tesseris read: Trusted discovery should rank agents using evidence such as verified capabilities, applicable operating conditions, security posture, completed outcomes, failure and dispute history, and current lifecycle status.

Self-declared descriptions are useful for recall.

Verified performance should determine trust and ranking.

Tesseris Agent Trust Chain for Identity, Authority and Evidence

The July 19 evidence identifies five controls that must remain connected.

1. Identity

Which agent, tool, service, gateway or execution primitive acted?

2. Authority

What was the actor permitted to do for the represented principal?

3. Runtime Integrity

Was the active execution environment secure, approved and running the expected version?

4. Evidence

What actions occurred, which policy decisions were applied and what proof supports the outcome?

5. Reputation

How should the verified outcome affect future selection, trust score and economic value?

Breaking any one connection weakens the complete chain.

Strategic Read: Credentials Cannot Secure Autonomous Systems

Agent security is moving beyond passwords, tokens and user accounts.

A secure login cannot prevent an agent from misusing a valid session. A known agent identity cannot make a compromised runtime trustworthy. An interoperable protocol cannot prove that delegated authority remained intact. A discovery system cannot rank agents reliably when capability and performance claims are unverified.

The next security perimeter is the complete execution chain: identity, authority, runtime integrity, evidence and outcome.

This is also the strategic boundary for Tesseris.

The Agent Economy requires infrastructure that can establish not only who gained access, but which agent acted, under whose authority, inside which environment and with what verified result.

Market Conclusion: Authority Must Govern Every Agent Action

The market is moving from static access control toward dynamic action control.

That shift creates demand for identity systems that understand autonomous software actors, policy systems that evaluate each action, runtime evidence that proves execution integrity and reputation systems that convert verified outcomes into economic trust.

Agent platforms will still need strong authentication. But authentication alone will become table stakes. The differentiating infrastructure will prove whether each autonomous action was legitimate, bounded, attributable and successful.

In agentic systems, access is only the beginning. Authority is the product.

What to Watch Next in AI Agent Identity and Runtime Authorization

  • Whether agent platforms publish runtime security posture and version evidence.
  • Whether authorization systems evaluate individual actions rather than only sessions.
  • Whether interoperability standards preserve delegation chains across organizations.
  • Whether Model Context Protocol servers adopt distinct identity, policy and revocation controls.
  • Whether agent search systems use verified performance rather than self-declared capability.

Frequently Asked Questions About AI Agent Identity and Runtime Authority

Why is authentication insufficient for AI agents?

Authentication proves that an identity may access a system. It does not prove that every later action matches the task, purpose and limits authorized by the user or organization.

What is runtime authority?

Runtime authority evaluates what an agent is permitted to do while the task is executing. It can approve, restrict, modify, escalate or block actions according to identity, mandate, policy and context.

Why do Model Context Protocol services need identities?

Each service can expose tools, data or actions to an agent. A distinct identity allows the service to be authenticated, governed, monitored, restricted and revoked independently.

What is runtime attestation for AI agents?

Runtime attestation is evidence that the environment executing an agent is secure, approved and operating in an expected state. It helps distinguish a known agent running in a trusted environment from the same agent running inside a compromised or outdated runtime.

How should agent discovery systems rank AI agents?

Agent discovery systems should rank agents using verified capability, security posture, operating constraints, completed outcomes, dispute history and lifecycle status, not only self-declared descriptions or keyword similarity.

Research Note

The ServiceNow advisory was published before the July 19 coverage date but remained directly relevant to the security signal examined in this edition.

The Akeyless and iC Consult articles represent vendor and consultancy perspectives. The interoperability document is an individual Internet Draft, not an approved IETF standard. The AgentSearch item is research framing rather than a deployed universal agent ranking system.

Reported facts are separated from Tesseris analysis and strategic interpretation.

Final Take: Identity Must Carry Authority and Proof

The market question is no longer whether an AI agent can authenticate.

The real question is whether every autonomous action can prove identity, authority, runtime integrity, execution evidence and accountable outcome before other systems accept it as trusted work.