Agent Identity & Delegation Ledger

Why this page exists. Agentic remediation is not just an AI workflow. It is a non-human identity acting through tools, source hosts, ticket systems, scanners, registries, and MCP servers. Enterprises need a ledger that says which agent may act, on whose authority, with what scope, and how that authority is revoked.

The product bet

SecurityRecipes already has a Workflow Control Plane and an MCP Gateway Policy Pack. The missing enterprise surface is identity: IAM, AI Platform, GRC, and trust review diligence teams will ask whether agent permissions are unique, scoped, auditable, and revocable.

The Agent Identity & Delegation Ledger is the answer. It turns each approved workflow plus each approved agent class into a machine-readable identity contract:

  • who delegates authority to the agent,
  • which MCP namespaces and access modes the agent may use,
  • which repository paths and branch prefixes it may write,
  • which actions are explicitly denied,
  • which reviewers must approve the output,
  • which runtime attributes and evidence records must exist,
  • which kill signals revoke the run.

This makes AI easier for adopters because the model does not have to remember identity policy. The host, gateway, or orchestrator can load one JSON artifact and make a default-deny decision.

Rechecked October 2, 2026 against NIST IR 8587 (final, 2026-09-15) and the public MCP specification 2026-07-28. IR 8587 section 1.1.1 says organizations should apply these token guidelines when AI agents use signed tokens to access systems, data, tools, or APIs. Workload and non-person identities MUST use tightly scoped, short-lived tokens issued through approved identity platforms and SHOULD use sender-constrained mechanisms such as DPoP or mTLS whenever feasible. Access and identity tokens MUST have defined short lifetimes, SHOULD be valid for no more than one hour, and expired tokens MUST be rejected. Tokens MUST include an audience and MUST NOT be written to logs, console output, cache directories, or artifact stores; detected exposure is an incident. Conformance with IR 8587 remains voluntary unless required by policy or contract. This pass does not claim human review of the pack.

Workflow at a glance

Agent Identity & Delegation Ledger workflow

Record non-human identity ownership, delegation, scope, lease, and runtime use so every agent action is attributable.

agent-runtime
  1. Signal

    Register the identity

    Capture provider, subject, owner, purpose, environment, credentials, trust tier, and lifecycle state.

  2. Scope

    Issue scoped delegation

    Bind workflow, resources, actions, constraints, approver, parent identity, start, expiry, audience, and revocation channel.

  3. Decision

    Validate at action time

    Check active status, chain integrity, lease, audience, sender constraint, expiry, scope, entitlement, separation of duties, and requested target.

  4. Action

    Allow or revoke

    Permit the bounded use, hold for owner review, deny excess authority, reject expired tokens, or revoke on compromise or token exposure.

  5. Proof

    Append ledger evidence

    Record use, renewal, scope change, denial, revocation, linked receipt, and next review without rewriting history or logging the token.

Decision gate

Is the identity active, owned, within an intact unexpired delegation chain, using an audience-restricted token, and authorized for this exact action?

Proceed

Permit the action and append its usage receipt.

Hold or stop

Hold, deny, or revoke when ownership, chain, lease, audience, expiry, scope, credential trust, or token exposure fails.

Evidence to retain

  • identity and ownership record
  • delegation chain and lease
  • runtime-use/revocation entries

Expected outputs

  • identity ledger entry
  • delegation decision
  • revocation record

What was added

The identity layer lives in two generated artifacts and one MCP tool:

  • data/evidence/agent-identity-delegation-ledger.json - the generated ledger that joins workflow manifests, MCP gateway policy, and the workflow validation report.
  • recipes_agent_identity_ledger - the MCP server tool that exposes the ledger to agent hosts, policy engines, and internal control portals.

Run it locally from the repo root:

python3 scripts/generate_agent_identity_ledger.py
python3 scripts/generate_agent_identity_ledger.py --check

CI runs the same --check command after the workflow control plane, gateway policy pack, and assurance pack checks.

What is inside the ledger

Section Purpose
identity_summary Identity count, workflow count, agent classes, MCP namespace count, default decision, and approval-required workflows.
agent_identities One identity contract per workflow and agent class, such as sr-agent::sast-finding-remediation::codex.
delegated_authority Allowed actions, MCP scopes, eligible findings, repository scope, branch prefix, and approval-required namespaces.
explicit_denies Actions an agent cannot perform: merge, deploy, release, publish, secret-store access, default-branch push, and policy edits without review.
identity_controls Credential model, no shared tokens, no model-visible secrets, audience-restricted sender-constrained run tokens, one-hour-or-run-end expiry, and required delegation-chain fields.
runtime_contract Required runtime attributes, egress default, session disablement, and kill signals.
enterprise_iam_contract The portable IAM checklist for issuing, auditing, and revoking agent identities.
delegation_graph A compact graph from accountable team to agent identity to MCP namespaces and reviewer pools.

Enterprise IAM contract

Treat every ledger identity as a non-human identity class. A production agent host should issue runtime credentials only when all of these are true:

  • The request names a known identity_id, workflow_id, agent_class, and run_id.
  • The workflow is active or explicitly approved for pilot execution.
  • The requested tool namespace exists in delegated_authority.mcp_scopes.
  • Branch writes use the declared remediation branch prefix and PR label.
  • Ticket writes are limited to the declared security or incident workspace.
  • Approval-required namespaces carry a typed human approval record.
  • Runtime tokens are audience-restricted and, when feasible, sender-constrained with DPoP or mTLS rather than reusable bearer secrets.
  • Runtime tokens expire at one hour or run completion, whichever is sooner, and are revoked when a kill signal fires.
  • Expired tokens are rejected at the gateway.
  • No user token is passed through to downstream tools.
  • Tokens are never written to logs, console output, cache directories, or artifact stores; detected exposure is a revocation and incident signal.

The ledger intentionally separates delegation from execution. It tells the platform what may be issued. The MCP gateway and IAM layer still enforce the decision.

Industry alignment

This feature is aligned to primary industry direction:

  • OWASP Top 10 for Agentic Applications 2026 calls out tool misuse, identity and privilege abuse, agentic supply chain risk, and rogue-agent behavior.
  • MCP Authorization defines the authorization flow for restricted MCP servers over HTTP transports.
  • MCP Security Best Practices emphasizes scoped authorization, confused-deputy prevention, token-passthrough avoidance, and session safety.
  • NIST AI RMF frames AI systems as governed, mapped, measured, and managed assets.
  • NIST IR 8587 (Protecting Tokens and Assertions from Forgery, Theft, and Misuse, final 2026-09-15) requires short-lived, audience-restricted workload tokens, expired-token rejection, sender-constrained presentation when feasible, and a ban on writing tokens into logs or build artifacts.
  • CISA Secure by Design anchors the product in secure defaults, transparency, accountability, and measurable security outcomes.

The forward-looking move is not another prompt. It is turning agent authority into an inspectable, enforceable, revocable artifact.

How agents use it

An agent or orchestrator should load the identity ledger before the first tool call:

  1. Match the finding to a workflow.
  2. Select the agent class and derive identity_id.
  3. Confirm the identity exists and the workflow status allows execution.
  4. Bind the run token to workflow_id, agent_class, and run_id, restrict its audience, prefer sender-constrained presentation, and expire it at one hour or run end, whichever is sooner.
  5. Evaluate every tool call against delegated_authority.mcp_scopes.
  6. Reject expired tokens and block every action in explicit_denies.
  7. Attach the required evidence records before the PR is reviewable.
  8. Revoke the identity when a runtime kill signal fires or when token exposure is detected.

The local MCP server exposes this flow through recipes_agent_identity_ledger. Query it with:

  • no arguments for the full summary and identity previews,
  • workflow_id for every identity allowed on a workflow,
  • agent_class for every workflow a given agent class may run,
  • identity_id for the full delegated-authority contract.

CI contract

The generator fails if:

  • Workflow IDs drift between the manifest and gateway policy.
  • Gateway policy is not default-deny.
  • Manifest defaults stop requiring human review.
  • An agent identity lacks reviewer pools, evidence records, or kill signals.
  • Identity token rules omit audience restriction, sender constraint, one-hour-or-run-end expiry, expired-token rejection, or the ban on writing tokens to logs and artifacts.
  • MCP namespaces use wildcards.
  • Branch-writing identities lack branch prefix or PR label controls.
  • Approval-required namespaces lack human approval metadata.
  • The generated ledger is stale in --check mode.

That is the review-ready bar: AI identities are not implied by tool access. They are declared, checked, versioned, exposed over MCP, and ready to enforce.

See also