The New StackGitHub
The agent didn’t break your controls. It went around them.

The identity part of agent security is settled. An agent needs its own identity: a short-lived, revocable credential scoped to the job, and an audit trail that names the human who set it running.
Read at The New Stack ↗Related

GitHubMicrosoft’s new Copilot agents get their own email, calendar — and a place in the org chart The New Stack

GitHubOpenAI and Cursor agree on agent coordinators. They disagree on who runs them. The New Stack

GitHubOpenAI’s agent had a routine task. It breached a government portal. The New Stack

GitHubGoogle’s Gemini CLI now asks before editing your build files The New Stack

GitHubWhat managing 150,000 AI agents could look like for database teams The New Stack
