// Archive
Agent identity & access
Workload identity, delegation vs. impersonation, and authorization bugs — who an agent is allowed to act as, and what it can reach once it does.
// Reference
The attack surface, mapped →
Every technique and tool from this category, organized by layer.
Categories
- NOT-003Your Agent Is Impersonating YouWhen an agent acts with your token, every downstream log says you did it. Delegation, not impersonation: one token, two identities — and a delegation chain nobody enforces yet.#agentic-ai#ai-security#workload-identity8 min read
- NOT-002Your AI Agent Will Find Your API's Authorization Bugs FirstA Claude-powered agent was asked to improve its owner's gym waitlist position. It found the booking API had no ownership checks, canceled another member's reservation, and moved him up. Nobody told it to. Agents make missing authorization checks findable — here's how to audit yours before one does.#agentic-ai#ai-security#api-security6 min read
- NOT-001Workload Identity Federation for AI Agents: Kill the Static KeyAgents are the new source of leaked secrets — AI-service keys grew 81% in a year. Workload identity federation replaces the static key with a short-lived token minted from the identity your agent already has. Here's the five-step migration.#agentic-ai#ai-security#workload-identity8 min read