Discussion about this post

User's avatar
Dr Peter McCann Strain's avatar

Useful start. Keyless identity helps, but runtime authority is the harder test. A valid agent can still be doing the wrong thing for this workflow. I would shape permissions around resource, operation, human context and expiry, so the verifier can tell whether the credential stayed inside its intended bounds.

2 more comments...

No posts

Ready for more?