Learning outcomes
- Preserve actor, subject, client, agent, tool, and target identity as separate facts.
- Bind delegated authority to the intended audience, action, resource, and time.
- Limit tool surface, credential exposure, goal hijack, and cascading failure.
- Approve, audit, contain, and revoke agent actions at the correct layer.
Scenario
An employee asks an agent to read a repository and update an incident record. The design must preserve employee context, limit tools, keep upstream tokens away from the model provider, and deny actions outside the employee policy.
Ordered learning units
Agent and Tool Inventory
Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.
Agent
An agent is a software loop that uses model output and context to select steps or tools toward a goal.
Delegation Chain
Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.
Trace the human-agent-tool identity chain
Trace one agent action from human intent through agent, client, server, tool, credential, target resource, and evidence.
Delegate authority without losing identity
Preserve subject, actor, audience, action, and authority limits when a service or agent acts for another principal.
Prevent agent token passthrough
Reject tokens issued for another resource and exchange or broker credentials instead of forwarding bearer authority through agents.
Separate MCP transport security boundaries
Separate remote Streamable HTTP authorization from local stdio process, executable, environment, and operating-system security.
Tool Discovery and Schema Trust
Treat tool names, descriptions, schemas, annotations, outputs, and discovery changes as untrusted supply-chain input.
Tool Misuse
Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.
Agent Goal Hijack
Prevent untrusted instructions from changing an agent's objective, authority use, tool sequence, or target resource.
Rogue Agent
A rogue agent acts outside its declared goal, approved policy, expected identity chain, or authorized operating boundary.
Design human approval for agent actions
Present the real target, arguments, authority, effect, and uncertainty so human approval gates a concrete agent action.
Agent Credential Custody
Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.
Agent Cascading Failure
Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.
Audit and revoke agent actions
Trace one agent action through identity, delegation, policy, approval, credential, tool, target, result, and future revocation.
Evaluation questions
- Which human, workload, application, and agent identity does each request represent?
- Which server, method, tool, resource, and downstream action can that authority reach?
- Where are delegation, approval, tool arguments, decisions, target effects, and revocation recorded?
Completion conditions
- Trace one agent action from human intent to final target effect with distinct identities and decisions.
- Prove wrong audience, unapproved action, poisoned input, copied credential, and revoked authority fail safely.
