Desk live·
ForensicPost
AI/Method/File 25-0503

The Agent Is Authorised as You, and Nobody Asked Whether It Should Be

Identity systems were built to answer who is acting. An agent acting on a person’s behalf, partly on instructions from a document, does not fit the question.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetAgent authorisation models
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

This file records a gap in the identity model that the incidents elsewhere in this section depend on.

Authentication Answers The Wrong Question

Access control establishes who is making a request and what that identity may do. It is the foundation of every control in this database, and it works because the identity and the intent were assumed to be the same thing: a person authenticating is a person deciding.

An agent breaks that assumption. It authenticates as the user or as a service account, and its decisions are shaped by content it retrieved — a document, a page, a ticket — whose author is nowhere in the authorisation decision.

The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.

The Corpus Has Been Circling This

The identity theme in this database is built on the observation that intrusion increasingly means legitimate credentials used by the wrong party: the service desk at 25-0512, the recruited support agents at 25-0514, the compromised account at 25-0612.

The agent case is the same failure with nobody deceived and no credential misappropriated. The authorised party performed the action, and the intent came from elsewhere.

What Would Actually Address It

A permission model that distinguishes actions an agent may take on its own from actions requiring a human decision — not a confirmation dialogue that becomes reflexive, but a genuinely narrower credential for autonomous operation.

That means deciding in advance which operations are irreversible or consequential and treating those as a separate class. It is achievable and it is unglamorous, and this desk has found no evidence of it being widely deployed.

Graded medium: this is an argument about architecture supported by the research below, not a finding about a specific system.

How we reported this

This is a method file. It sets out an argument about authorisation models, supported by the research listed below, and is not an incident record. Corrections: corrections@forensicpost.com.

Sources
  1. A framework for formalizing LLM agent securityarXiv
  2. Prompt injection attacks in large language models and AI agent systems: a comprehensive reviewMDPI Information
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary