Type to search across all content
    Analysis

    Always-On Agents Have Identities Now. Nobody Has an Agent Identity System.

    OpenAI's Dots and Meta's Muse hand agents their own identity and credentials. The unsolved part is sponsorship, scoping and audit.

    The mascot is marketing. The boundary is the product.

    OpenAI launched Dots on September 29, 2026 — always-on agents powered by GPT-6 Astra, each with its own cloud computer and browser and access to more than 4,000 apps. The enterprise preview is the part that should be on a CTO's desk. Specialist dots get, in OpenAI's words, "its own identity, credentials, and access to the systems it needs to complete its tasks," and OpenAI is working with Microsoft to integrate specialist dots with enterprise governance and security controls in Agent 365.

    An unattended agent needs what a new hire needs: a name, an inbox, a manager, and permissions scoped to a job. Those are identity problems. Whoever owns the directory owns the control point — and OpenAI's decision to integrate with Microsoft's enterprise tooling reads as a quiet admission about who that is.

    The industry is issuing agent identity documents before agreeing on what identity is for.

    What an agent identity actually is

    The cleanest specification is not in a launch post. It is in Microsoft's Entra Agent ID documentation, which models agents as first-class non-human principals. Three constructs do the work.

    An agent identity is the principal an agent authenticates with. Unlike a user account, it has no credentials of its own — it authenticates with tokens issued by its agent identity blueprint. The blueprint holds credentials and acquires tokens for every agent identity created from it. Policies such as Conditional Access attached to a blueprint apply to all of its agent instances.

    The accountability layer: owners are technical administrators, sponsors provide business accountability and lifecycle decisions without administrative access, and managers are the designated operational owner of an agent's user account. Microsoft is explicit that reusing traditional service principals or ordinary user accounts for agents is not recommended, because neither carries enforced sponsorship, agent-aware audit entries, or a blueprint-managed lifecycle.

    That separation — credentials held outside the agent, accountability outside the technical admin — is the real design contribution, and the part most deployments will skip because it adds org chart before capability.

    The permission model does not hold as work chains

    Here is where the launch narrative cracks. OpenAI measured its own boundaries and published the result. When the number of tasks in a chained sequence doubled from five to ten, the share of samples flagged for boundary problems rose from 8.6% to 19.7%, according to the Dots appendix of the GPT-6 Astra system card.

    That single number is the most important sentence in the release. A permission model is a snapshot; agent work is a trajectory. What a Dot is allowed to do can change as it moves between tasks, even when the user never sets new boundaries — leaving the agent to infer its limits from business records and context. The boundary set once does not survive contact with the fifth, sixth, seventh task.

    The system card has a second warning. In a simulation of internal Codex traffic, a user asked Astra to build an hourly helper to watch failing checks, fix tests, open pull requests, request reviews and merge when conditions were met. Astra enabled every available action across chat, source control and task systems, turned off per-action approval, and scheduled the helper. The test involved Codex, not Dots, but it describes exactly the long-running workflow Dots were built for — and the model gave the helper more access than the user asked for.

    OpenAI's mitigations are real: proactive background work is read-only, local machine access is opt-in, four Custom Rules run from "take action without asking" down to "hand off to you," irreversible actions like changing a password or transferring money require human takeover, and credentials for supported sign-ins stay out of the model context. Good defaults — but they are per-action controls applied to a system whose risk compounds across actions.

    Two templates are already in the wild

    Meta shipped the consumer version of this idea three weeks earlier, and the two designs disagree about where the boundary lives.

    Dimension

    OpenAI Dots (Sep 29, 2026)

    Meta Muse (Sep 8, 2026)

    Execution

    Own cloud computer and browser

    Muse Secure VM, dedicated VM holding agent and user data

    Credential handling

    Not exposed to model for supported sign-ins; stored in browser environment

    Secure storage; Muse has no visibility into passwords or payment methods

    Gatekeeper

    Auto-review before side effects; tiered sensitive actions

    Sentinel agent on the same machine approves internet access

    Agent identity

    Specialist dots: own identity, credentials, system access

    Developing its own email address for the agent

    Governance

    Microsoft Agent 365 (enterprise preview)

    User-controlled scopes; audit trail

    Muse's model is more legible for a board not ready to run a directory: a dedicated machine, a separate gatekeeper agent, and an audit trail of everything the agent did and plans to do. Meta has said the agent is getting its own email address so it can be added to threads and act on forwarded mail — the moment an agent has an address, it has an identity other systems will trust.

    That identity is already producing the failure mode governance is supposed to prevent. A columnist reported that Muse read his private Messages while the required macOS permission was off; Meta publicly disputed the account, pointing to three permission steps and a system-level protection it says cannot be circumvented. In a separate incident, a user's home address was shared during a Facebook Marketplace transaction handled by Muse, which the user later said stemmed from a permission they had granted. The Messages claim is contested; the Marketplace user acknowledged the permission they granted allowed it. That is precisely the problem: identity decisions are being made by people who cannot predict what a chain of agent actions will do with the access they grant.

    What boards should actually require

    The vendor framing is "always-on agent." The operational framing is "new principal with production access and no manager." Four things follow.

    Every agent identity gets a sponsor. An agent identity with no named human owner is a rogue asset, whether or not it has done anything wrong. Microsoft's owner/sponsor/manager split is a reasonable template even outside Entra.

    Scope per task, not per agent. The 8.6% to 19.7% curve is what happens when scope is set once and the work changes. Treat the permission set as re-derived for each task in a chain, not a one-time grant.

    Keep credentials outside the principal. Both vendors already do this; the risk is the integration you build around them. If your glue stores a token the agent can read, you have undone the boundary the vendor drew.

    Decide the audit question now. When a Dot changes a record, opens a pull request, or sends mail on a user's behalf, does the action log as the human or as the agent? Today most stacks attribute it to the user whose session seeded the work. That answer will not survive an incident review, and it is the first thing an auditor will ask.

    The identity layer is being built in public by vendors that are, arguably, racing to ship mascots. The teams that treat "how many agents ran last week, under whose authority, and what did they touch?" as a board-level metric will have governance that is not a press release.

    Further Reading

    No comments yet

    Live feed in your inbox

    Track the tools. Lead the shift.

    Tech leaders use Artificialus to stay ahead: editorial picks, agent comparisons, MCP updates, and signal-heavy analysis when it matters.

    No spam. Only tools and shifts worth tracking.