ControlAgent identityx, held

Agent identity: one per agent, admitted on evidence.

Per-agent credentials on open standards, an owner and a second approver before production, and tool access that expires.

How it works

Specs

Agent identity, in detail

Delivery and data

Delivery
SaaS, from one login.
Isolation
Each customer runs in an isolated workspace with its own database.
Certifications
None held. Frameworks are mapped to and assessed against.

Frameworks

OWASP Top 10 for Agentic Applications
Assessed per agent against: Identity and privilege abuse, ASI03, per agent.
See the frameworks

Last reviewed 6 Oct 2026

One agent, one credentialIllustrative

One agent, one credential: kyc-agent to ColossalX; same key found calling ColossalX (mismatch); ColossalX to provider A (allowed); ColossalX held for a person before payments.refund (person approves); ColossalX to incident (raised).

In shortPost-quantum agent identityPost-quantum agent identity is an agent credential signed with a post-quantum algorithm and a classical one together, so it stays trustworthy as quantum computers weaken the cryptography in use today. Built on open standards, it lets anyone verify which agent made a call and whether its credential has been revoked. In the glossary

AI agent identity in ColossalX gives each agent its own credential: a post-quantum hybrid identity on W3C open standards, with signed requests that cannot be replayed and delegation that can only narrow. Registered is not approved: an owner, a second approver and a guardrail profile come first, and extra tool access is granted until a date.

Agents share one service key, so a stolen key speaks for all of them, and nobody approved any.

ColossalX gives each agent its own credential, admits it on evidence, and flags a stolen key by behaviour.

How it works

From a new agent to an admitted one.

One agent gets its own credential, waits for an owner and a second approver, works inside its trust zone, and is verified by anyone who asks.

Workflow · a new agent, admitted on evidenceIllustrative

01 Credential issued

The agent gets its own credential; its private key stays with it.

02 Owner and approver

Registered is not approved: an owner, then a second person.

03 Zone and grants

A trust zone sets its limits; one extra tool lasts until Friday.

04 Verified anywhere

Anyone can check the credential and the revocation list, without an account.

What you see

Which agents can prove who they are.

The identity view lists each agent's key, its live credentials, signed requests and a behaviour check, beside a signed action trail you can verify offline.

  1. Its own credentialEach agent calls under its own key; a conflicting claim is refused.
  2. Post-quantum, open standardsHybrid ML-DSA-65 and P-256 keys, with W3C identifiers and credentials.
  3. Admitted on evidenceAn owner, a second approver and a guardrail profile come first.
  4. Access that expiresOne agent, one tool, until a date, approved by someone else.
Read the detail, step by step4
  1. Its own credential. A request on an agent credential is attributed to that agent whatever its body says. Short-lived signed hand-offs between agents are verified, and the private key can stay with the agent.
  2. Post-quantum, open standards. Signed requests are refused on replay, delegation can only narrow, agents carry signed A2A agent cards, and a signed revocation list can be checked by anyone without an account.
  3. Admitted on evidence. Admission rolls out monitor-then-enforce, with time-boxed exceptions. Agents can also earn their way from sandbox to staging to production through gates you define.
  4. Access that expires. The person who asks cannot approve. A grant ends on its date, when revoked, or when the agent is retired, and a written deny rule still wins.
The agent identity view in a demo workspace: the workspace issuer with its decentralised identifier and a public revocation list anyone can check, and a signed action trail with signed checkpoints that can be verified in full or exported for an offline check.
From a demo workspace
3notes
  1. Public revocation list
  2. Each checkpoint is signed
  3. Verify the whole trail

How it connectsx, held

Where an identified agent goes next.

An identity is what every other control reads. The same credential decides tools, carries test results and gives a stolen key away.

  1. Its credential decides which tools it may call, with default deny.

  2. Its record shows how it was found, who owns it and its history.

  3. A credential used with the wrong behaviour raises an incident.

  4. Its latest red-team result is carried inside its credential.

Honest by design

What it does, and what it does not.

Agent credentialIllustrative

Agent credential: Owner KYC team; Second approver Approved; Guardrail profile KYC baseline; Trust zone Restricted; Red-team result Not measured. Measured, or says so.

What it does not do

x, not measured

The behaviour check raises an incident on a mismatch; revoking the credential is what stops the key.

All 4 limits
  • Trust-zone breaches are recorded by default; refusing them is a setting you switch on.
  • Workload attestation is proven on GitHub Actions and AWS; other CI systems and clouds are built.
  • Sealed agent-to-agent messaging is opt-in, for agents that use the governed relay.

How we know

  • Delegation can only narrow: a delegated credential never holds more than its parent.
  • A credential states what the workspace measured, and says not measured where nothing was.
  • The signed action trail can be exported and verified without ColossalX.
  • The person who requests tool access can never approve it.

Questions

Questions buyers ask

What is AI agent identity?

AI agent identity is a credential that belongs to one agent and lets it prove who it is on each request, so actions can be attributed, limited and revoked agent by agent. In ColossalX each agent gets its own credential, and the gateway attributes a request to that agent whatever the request body claims.

Are AI agents non-human identities?

Yes, and they need more than a service account. An agent acts on its own, delegates to other agents and picks up tools, so its identity has to carry who owns it, what it may do and who it may act for. ColossalX credentials carry those facts, and delegation can only ever narrow.

Why does post-quantum identity matter for AI agents?

Credentials issued today may still need to be trusted for years, and signatures based only on classical cryptography could be forged once large quantum computers exist. ColossalX signs agent identities with a hybrid of ML-DSA-65, a post-quantum algorithm, and P-256, so they verify with today's tools and resist tomorrow's.

What does "registered is not approved" mean?

Registering an agent records that it exists. Approving it means someone is accountable: in ColossalX an agent reaches production only with an owner, a second approver and a guardrail profile. Workspaces roll this out monitor first, seeing what enforcement would refuse, with time-boxed exceptions for agents already running.

How does just-in-time tool access for agents work?

Instead of widening an agent's rules for good, a person requests one exact tool for one agent, with a reason. Someone other than the requester approves it with an end date, and the tool firewall honours it until then. It can be revoked early, and it ends when the agent is retired.

Related

Next step

Know your x.

See which of your own agents can prove who they are, and who approved each one.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start