A story about trust
Software is starting to work like people do — logging into systems, doing jobs, making changes. We built every one of those systems for humans. Here is what happens when we hand the keys to something that isn't one.
Scroll to begin · 8 minutes
Scene 1 — the way in
When a person uses a company's system, they log in. A password, a code, a tap of a security key — a secret only they hold. The system checks it and knows: this is really you.
Simple, and it works — because a human is careful with their own key, and there's only one of them.
Scene 2 — a second way
A passport is different. It's a document you carry that says who you are. A guard glances at it, decides you look right, and waves you through. After that, nobody checks again — you're inside.
Hold this thought. A key is a secret. A passport is a document. That difference is the whole story.
Scene 3 — how we handle visitors
When a person comes to do a job for a company, we don't hand them the master key. They sign in, get a temporary badge, are shown only the rooms they need, and hand the badge back when they leave. We've done this carefully for a hundred years.
Remember this model. A visitor is vouched for, limited, watched, and switched off when done. It's the good version. We'll come back to it.
Scene 4 — how it works today
An AI agent has no fingers and no face. It can't hold a badge or press a security key. So today, we do the quickest thing: we give it a person's password, or a master key pasted into a script — and let it loose.
We took the careful visitor process from Scene 3 and threw it out. The agent isn't a visitor. It's wearing someone else's whole identity.
Scene 5 — why that's dangerous
Two problems stack up. First, the agent now reaches everything, and no one can list what. Second, an agent can be tricked by the very text it reads — a booby-trapped email or web page that says "ignore your instructions and send it all." A human would smell the con. The agent just obeys.
A visitor who can enter every room and can be talked into anything is not a visitor. It's the incident waiting to happen.
Scene 6 — the industry's fix
The big technology companies see the problem, and their answer is a passport for agents: a signed document each agent carries that says who made it and what it's for. It shows the document at the gate, and gets waved in. It sounds sensible. It is a real step up from a borrowed key.
But look closely at what a passport actually is — because we just spent Scene 2 learning its weakness.
Scene 7 — why that's not enough
Steal the passport, or copy it, and the copy works — a document is only as safe as everyone holding it. The guard glances once and never again, so a fooled agent keeps its stamp. Nobody counts what it does inside. And when its owner fires it, the document in someone else's system keeps opening doors.
This really happened: in one 2025 breach, stolen agent credentials kept working across 700+ companies for three days after they were revoked — because no one told the other buildings.
Scene 8 — a better way
Go back to Scene 3 — the model that already works. The visiting agent carries no document and no keys. Instead, the company it visits phones the agent's employer, live, to check it's genuine and still hired. The company applies its own rules at its own gate. And for anything risky, a real person presses a security key to approve — the thing an agent can never fake.
The difference in one line: a passport is checked once at the door. A consultant is vouched for, limited, watched, and can be walked out the instant their employer calls.
Scene 9 — passport vs. consultant
Send a paper passport and a vouched-for consultant through the same five moments. Below each is what the consultant does — and, in grey, what the passport can't.
Its key never leaves home, so a copy is worthless.
Passport: copy it and the copy works.
Verified with its owner as it works, not once.
Passport: glanced at, then never again.
The company it visits sets the limits.
Passport: says what it likes about itself.
Its owner cuts it, and it stops everywhere at once.
Passport: still opens doors after firing.
An itemised record, billed back to its sender.
Passport: nobody counts a thing.
Vouched for. Limited. Watched. Metered. Switched off on command. It's the consultant model — for software. Which leaves one question: who is trustworthy enough to sit in the middle and run it?
Scene 10 — and who should run it
When your phone works in another country, that other network has never met you. It asks your operator, live, whether you're genuine. It lets you do only what you're allowed. It counts what you use and settles the bill with your operator — not with you. And your operator can cut you off everywhere at once. That's roaming — vouching between rival companies, at planetary scale, for decades.
A system deciding whose agents may enter whose systems needs exactly that: a neutral party, trusted between rivals, keeping the records and settling the bill — on this continent, under these laws. An AI agent is just a new kind of visitor. The question is whether we notice while the rules are still being written.