Skip to content
bucker

Wedge three

Agents are principals, not a feature flag

What incumbents ship is an organization-level AI on/off toggle and a setting for whether the bot may open a pull request. That is not governance. After a year in which an over-scoped, long-lived integration token became one of the most expensive breaches in the industry, an enterprise asking “what could this agent do, on whose authority, and who can prove it” deserves an answer with a schema behind it.

What is actually enforced

  • claim · 01Shipped

    One identity spine, not a second system

    Humans, agents and service accounts are the same kind of principal, on the same tenancy, roles and audit spine — plus the things only an agent needs. An agent has a sponsor, and suspending that sponsor revokes the agent’s tokens and its delegations in one transaction rather than leaving orphans behind.
  • claim · 02Shipped

    Delegation chains you can read

    Token exchange follows RFC 8693, down to audience-bound short-lived tokens with nested actor claims. The token presented is itself the ceiling: a narrowed session cannot re-widen. The audit trail therefore reads “Claude Code, acting for alice@acme under incident #82” rather than a bare service-account name.
  • claim · 03Shipped

    Budgets that bite mid-flight

    Budgets are scoped to the tuple of agent, the human being acted for, and the incident, and the tightest one wins. The metered model provider reserves an estimate before each generation, so a run cannot overshoot its budget by the length of one completion — the failure mode of every check-afterwards meter.
  • claim · 04Shipped

    Blast-radius tokens

    An incident token binds an agent to one incident and its objects. It is verified by a handler that re-checks the Ed25519 signature itself, because it has to run before route-level authentication does, and it refuses any object outside the bound incident. This is what a break-glass grant looks like when it has an edge.
  • claim · 05Shipped

    Audit at the level of the action

    Not grant-level, not session-level. Nearly two hundred write sites across the API record what was done, by whom, on whose behalf, and under what basis — which is the difference between an audit log and a login history when a review actually happens.
  • claim · 06Shipped

    Kill switches, and revocation that fires itself

    AI can be disabled organization-wide, and agent pull-request creation separately, both checked before any policy row is read. Behaviour baselining learns an agent’s normal shape from its own audit trail — excluding the anomaly window, so an attack cannot teach the baseline — and revokes tokens on a high-severity anomaly, suspending the agent outright on two independent ones.
  • claim · 07Shipped

    SCIM for agents, not just people

    Directory sync covers users and groups, and also /scim/v2/Agents — so an agent principal is provisioned and deprovisioned by the same machinery that handles your employees, on every paid tier rather than as an enterprise upsell.
  • claim · 08Shipped

    Approval gates that are tiered

    Un-tiered approval gates become rubber stamps, so risk-class tiering is mandatory rather than configurable-to-zero. Approving a fix and merging a pull request are human-only before any policy is consulted, and any future action whose name ends in .merge is treated the same way by default.

The boundary we do not move

Read the documentation

Agent governance covers identity, delegation, budgets, approvals and audit; SSO and SCIM covers federation and directory sync including agents; and agentic observability covers watching your own AI application in the same issue stream as your crashes.