Skip to main content

Control human-to-agent-to-tool access

Preserve identity, delegation, consent, policy, credential custody, approval, evidence, and revocation through agent actions.

Learning outcomes

  • Preserve actor, subject, client, agent, tool, and target identity as separate facts.
  • Bind delegated authority to the intended audience, action, resource, and time.
  • Limit tool surface, credential exposure, goal hijack, and cascading failure.
  • Approve, audit, contain, and revoke agent actions at the correct layer.

Scenario

An employee asks an agent to read a repository and update an incident record. The design must preserve employee context, limit tools, keep upstream tokens away from the model provider, and deny actions outside the employee policy.

Ordered learning units

  1. Concept

    Agent and Tool Inventory

    Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.

  2. Concept

    Agent

    An agent is a software loop that uses model output and context to select steps or tools toward a goal.

  3. Concept

    Delegation Chain

    Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.

  4. Guide

    Prevent agent token passthrough

    Reject tokens issued for another resource and exchange or broker credentials instead of forwarding bearer authority through agents.

  5. Concept

    Tool Discovery and Schema Trust

    Treat tool names, descriptions, schemas, annotations, outputs, and discovery changes as untrusted supply-chain input.

  6. Concept

    Tool Misuse

    Stop an agent from using a legitimate tool with harmful targets, arguments, sequences, volume, or delegated authority.

  7. Concept

    Agent Goal Hijack

    Prevent untrusted instructions from changing an agent's objective, authority use, tool sequence, or target resource.

  8. Concept

    Rogue Agent

    A rogue agent acts outside its declared goal, approved policy, expected identity chain, or authorized operating boundary.

  9. Concept

    Agent Credential Custody

    Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.

  10. Concept

    Agent Cascading Failure

    Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.

  11. Guide

    Audit and revoke agent actions

    Trace one agent action through identity, delegation, policy, approval, credential, tool, target, result, and future revocation.

Evaluation questions

  • Which human, workload, application, and agent identity does each request represent?
  • Which server, method, tool, resource, and downstream action can that authority reach?
  • Where are delegation, approval, tool arguments, decisions, target effects, and revocation recorded?

Completion conditions

  • Trace one agent action from human intent to final target effect with distinct identities and decisions.
  • Prove wrong audience, unapproved action, poisoned input, copied credential, and revoked authority fail safely.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo