Learn
Securing AI agents in production
Straight answers to the questions security and platform teams ask when real AI agents start touching real systems: how to give each agent its own identity, how to scope and revoke access, how to prove who did what, and where existing tools stop short. Each guide is self-contained and practical.
Identity
-
Give each AI agent its own identity instead of a shared API key
Why a shared key can't tell your agents apart in logs, and how to issue a distinct, verifiable identity per agent.
-
Assign a human owner to an AI agent
Tie every agent to a named, accountable person, recorded in evidence you can hand to an auditor.
-
Short-lived credentials vs long-lived API keys
The real security tradeoff for AI agents, and whether the operational overhead is worth it.
Governance & accountability
Access & enforcement
-
Enforce least privilege for an AI agent calling internal APIs
Scope an agent to the smallest set of operations it needs, and enforce it on every request.
-
Revoke an AI agent's access immediately
A playbook for cutting off an agent the moment it starts behaving unexpectedly.
-
Operational boundaries, enforced at runtime
What a boundary is, and why enforcing it at runtime beats trusting a config file.
Standards & interop
-
Can Open Policy Agent handle AI agent authorization?
Where OPA fits for agents, what it decides well, and what has to sit in front of it.
-
SPIFFE/SPIRE and the agentic identity gap
Workload identity covers services; here's what's missing for an agent acting on a human's behalf, and how teams fill it.