What is Identity Collapse?
Identity collapse is a failure mode in which a downstream service sees only a common agent or service identity and loses the originating user or actor relationship. Actions from different users then appear to come from one principal.
Why it matters
Shared identity can widen permissions, hide accountability, and stop the downstream service from applying user-specific policy.
How it works
- A user delegates a task to an application or agent.
- An intermediary replaces the user context with one shared credential.
- The downstream service authorizes and logs the request only as the shared account.
Example
Ten employees use one finance agent. The agent calls the finance API with one administrator token, so the API cannot apply limits for each employee or identify who requested a change.
Pomerium boundary
A verified Pomerium identity assertion or Pomerium MCP External Token can preserve authenticated user context on a protected path. The downstream service must validate and use that context.
Limits and non-claims
- Identity collapse is a descriptive failure mode, not a formal standards term.
- A service account can be correct for a truly autonomous workload with its own policy.
- Preserving identity does not replace least-privilege policy, consent, or audit review.
- Pomerium protects Model Context Protocol servers that use Streamable HTTP through a Pomerium route. It does not secure local stdio connections, the model runtime, tool code, or traffic that bypasses the route.
Evaluation checklist
- Which distinct users, services, agents, tools, or tenants become one downstream identity?
- Which excess permission and lost attribution result from that merge?
- Do unique identities, explicit delegation, target authorization, and correlated evidence preserve accountability?
