SIGNAL//DESK
C4AIL/governancesrc: C4AIL canon

Agent-as-Principal

Think of an AI agent like a temporary employee who is given a specific, limited set of keys to do one job. They have their own digital ID, so we know exactly what they did, and we can take those keys away at any moment. They are never treated as the boss or the owner of the account.

Agent-as-Principal is a governance model where AI agents are assigned unique, non-human identities rather than operating under a human's credentials. This ensures that every action is logged to a specific agent ID and restricted by least-privilege access controls, allowing for granular auditing and immediate revocation without impacting the human user's own permissions.

The principle that each agent is a principal: a distinct, revocable non-human identity with least-privilege scoped credentials, so its actions are traceable and revocable and never inherit a human's full access (the Intern Test applied to agents). (C4AIL, agentic governance spec.)


← all terms