Seven Laws of AIdentity: A Framework for Governed Agent Identity
Patrick Parker's Seven Laws build on KuppingerCole's AIdentity framing—an architect-facing summary with proper attribution.
AIdentity is Martin Kuppinger and KuppingerCole's framing for the intersection of AI and identity. The Seven Laws are Patrick Parker's working paper that applies and extends that framing. Canonical publication URL pending.
Human identity matured over decades: joiner-mover-leaver, certification, SoD, audit. Agent identity is repeating that journey in compressed time—with higher blast radius if we skip the laws.
The seven laws (summary)
- Every agent is an identity—with an owner, not a shared service account
- Authority is purpose-bound—not perpetual session scope
- Delegation must be explicit, bounded, and revocable
- Trust signals can invalidate authority before token expiry
- Consequential actions require Governed Execution at the boundary
- Credentials are mediated—agents receive results, not custody
- Evidence must be causal—decision, action, and outcome linked for audit
From framework to platform
Laws without enforcement are compliance theater. EmpowerID Agent Governance & Execution operationalizes these laws alongside established Identity Governance—one Fabric, two growth stories, shared proof discipline.
Read the LinkedIn article for narrative depth, Karl McGuinness's Answering the Laws of AIdentity for related analysis, or read Authority in Motion for EmpowerID's full product-architecture perspective.
Related
Authority in Motion →