Agent Identity & Delegation
Know whose authority every agent uses.
Follow each action through users, agents, credentials, tools, roles, and data principals.
Agent Identity & Delegation
Connect purpose, identity, access, and outcome
Runtime evidence chain
The observed path behind this activity
Initiator
finance-user
Verified
Agent
finance-agent
Managed
Sub-agent
reconciliation
Delegated
Cloud role
finance-admin
Broader
DB principal
reporting_admin
Active
Authority expanded at the handoff
The delegated agent used a broader credential to reach records outside the initiating request.
One action. Several identities.
Connect local principals across every handoff.
Attribute the action
Connect the initiating user or service to the agent, cloud role, credential, database principal, and final action.
Follow every handoff
Trace agent-to-agent and MCP handoffs to see whether downstream authority remains consistent with the original request.
Preserve uncertainty
Surface human credentials used by agents, credentials shared across agents or services, and ownership that the available records cannot establish.
EFFECTIVE AUTHORITY
The final log hides the identity chain.
Trace users, agents, tools, cloud roles, and data principals as one chain.
Runtime context
Observed evidence chain
Agent-to-agent and agent-to-tool relationships
Original request retained with downstream activity
Scope expansion identified at the responsible hop
01 / DELEGATION PATH
Find where authority widened
Connect root agents, delegated agents, MCP servers, service accounts, cloud roles, and data principals. When a handoff broadens access beyond the original purpose, the risky transition is visible.
Runtime comparison
Expected and observed behavior
Expected
Observed
02 / CREDENTIAL USE
Separate machine and human use
Map credential fingerprints to the agents and services that used them, the destinations they reached, and their observed owner. Human-scoped or shared credentials are treated conservatively when machine ownership cannot be proved.
Reviewable finding
Runtime evidence · high confidence
Observed resources connected to each identity
Granted permissions compared with runtime use
Evidence for permission and credential reviews
03 / RUNTIME BLAST RADIUS
Measure actual reach
Combine identity relationships with observed APIs, models, tools, databases, and destinations. Investigators can see what an agent actually reached and which unused permissions or shared credentials widen the potential blast radius.
RUNTIME SIGNALS
Identity failures local logs miss
Aurva preserves uncertainty when provenance is incomplete instead of assigning an owner without evidence.
01
Delegation drift
A downstream agent or tool expands access beyond the initiating purpose.
02
Human credential use
An agent or service acts through a user credential and SaaS records attribute the action to a person.
03
Shared credential
The same credential appears across agents, services, or environments, weakening attribution and isolation.
04
Unresolved ownership
Credential use is observed, but available evidence cannot establish a machine owner.
Connect inventory to runtime activity.
See what exists, who acted, and what data moved.
Trace every agent action.
See where purpose or authority changed.
Inventory the AI estate.
Find models, tools, MCP servers, and vector stores.




