Agent identity and access control
Plain English. Who is this agent, on whose behalf is it acting, and what exactly may it touch? A decade of enterprise identity infrastructure — single sign-on, device posture, session risk — assumed a human at a device, acting at human speed. Agents break every one of those assumptions: they are ephemeral, numerous, fast, and hold delegated authority that current systems can only represent as "it's basically the user", which is how an agent ends up with every permission its owner has.
Why it moves money. This is the precondition market for the whole agent-labour thesis: enterprises will not deploy agents at scale until they can scope, monitor and revoke them, so identity primitives gate everyone else's revenue. The infrastructure layer has noticed — multiple hyperscale providers shipped agent-credential primitives within the same week, and Cloudflare's published design argument (shrink the capability, not the judgement: short-lived credentials for short-lived tasks) is becoming the reference architecture. Over-permissioned agents plus prompt injection is the standing breach recipe.
What to watch. Whether capability-scoped, short-lived credentials become defaults rather than options, and the incident reports — breaches traced to an agent holding permissions no task required.
From the signals. Cloudflare on agent permissions: shrink the capability, not the judgement. Cloudflare and AWS shipped agent-identity primitives in the same week.
Further reading. Simon Willison, "The lethal trifecta for AI agents".