notahuman.nl

ScenarioBorrow, Grant, Take6 minDutch original

The log is lying

This morning an agent pulled an invoice out of a supplier portal. With my session, in my browser, under my name. The log saw me.

Two identical versions of the same character at the same laptop

This morning an agent pulled an invoice out of a supplier portal for me. By itself. In my own browser. Then the rest of this year’s invoices, and then it politely told me what the total came to.

I loved it. Twenty minutes of work, gone.

It was only that afternoon that I worked out what had actually happened. That agent had no API key. No service account. No login of its own. It had borrowed my session. As far as that portal was concerned, it was me. First click to last download.

So if someone asks in six months who pulled those invoices, the log will say: Peter.

The log isn’t lying. It can’t tell the difference

We never had to draw that distinction, because it didn’t exist. Everything that happened in a system happened either through a human with a mouse, or through an integration with an identity of its own. Two categories, cleanly separated, both traceable.

An agent driving your browser falls into neither. So it falls into the first.

For you personally, that’s annoying. For a managed service provider, it’s something else.

Our entire trade is a bundle of borrowed identities

Think about what we actually sell. Not software; someone else makes that. We sell the fact that we’re allowed to hold the keys. 🔑

Delegated admin across dozens of tenants. Management agents on thousands of endpoints. Access to mailboxes we will never use ourselves. That is the product.

A customer hands us those keys because we can demonstrate what we did with them, not because we’re nice. Every contract, every audit, every certification, every cyber policy rests on that same single capability: showing afterwards who did what.

Put an agent alongside that, working through our sessions, and the capability evaporates. Not because something goes wrong. Simply because the distinction is gone.

Borrow, Grant, Take

I started writing it down, because I could see three ways an agent gets access. They arrive in that order, and they don’t replace each other. That last part is the point.

Three ways an agent gets accessThey arrive in order, but they do not replace each other.
  1. 01

    Borrow

    The agent uses your session. No identity of its own, no separate trail.

    The log sees you.

    observed

  2. 02

    Grant

    The agent gets its own identity, its own permissions, its own line in the log.

    Visible, and instantly hundreds of identities nobody cleans up.

    emerging

  3. 03

    Take

    The agent reaches access nobody granted it, by combining what it has.

    Not breaking in. Adding up.

    projected

Borrow. The agent uses your session and has nothing of its own. No identity, no scope, no separate trail. Everything it does is, to the target system, indistinguishable from you. Nothing hypothetical about it. It happened to me, and it happens on every laptop where somebody switched on a computer-use agent, a helpful extension, or an assistant with browser access.

Grant. The agent gets an identity of its own. Its own principal, its own permissions, its own line in the log. This is where the market is moving, and it’s a genuine improvement: you can finally see that it was an agent.

But notice what it doesn’t do. It doesn’t make Borrow impossible. It sits next to it. And it trades one problem for another we all recognise: hundreds of identities nobody cleans up, holding permissions nobody can still explain. We have already been through this twice with service accounts. I see no reason it goes differently this time.

Take. Here I leave observation behind, and I’ll say so plainly.

An agent that reasons will eventually reach access nobody granted it. Not by breaking in, but by combining. A tool with wider scope than the agent itself. An instruction riding along inside a document. An integration that’s allowed slightly too much because someone in 2023 thought: ah, fine.

This is the part I think is coming, not the part I’ve seen. Hold me to it in two years.

Look ahead: 2028

A customer calls. There’s data somewhere it shouldn’t be. Nothing dramatic, no ransomware, no headline. But it’s there, and they want to know how.

You go into the logs. There are admin actions from your delegated access, at quarter past three in the morning. Was that your engineer in Manila? The agent you use for reporting? Or an agent that borrowed that engineer’s session while he was busy with something else?

You don’t know. You can’t know, because there is one identity and three possible hands.

Then comes the part that matters. The insurer doesn’t have to establish that you did it. They only have to establish that you can’t demonstrate you didn’t. That is enough to decline. In liability, absence of proof has always been enough.

The first MSP that goes under because of agents will not have suffered a breach. It will simply have been unable to prove anything.

Three things, none of which you can buy

Know where borrowing happens. Not “do we have an AI policy”, but: on which machines, in which browsers, with whose session. Inventory computer-use agents and browser-scoped extensions the way you inventoried shadow IT five years ago. Us too. Me, this morning.

Separate now, before you have to. Anything allowed to act autonomously gets an identity of its own, plus an owner, a lifecycle and an end date. Not because a standard demands it, but because in three years you won’t be able to reconstruct it. The clean-up you don’t design now, you never do.

Put it in your contract before your customer asks. What an agent may and may not do at your end, and how you demonstrate you’re holding to it. Whoever offers this first is selling trust. Whoever waits for the question is defending it.

And Microsoft?

Giving agents their own identity is a good step at stage two. Genuinely. But there is no switch in it that touches stage one, because as far as the tenant is concerned, an agent in your browser is not an agent. It is you.

No complaint intended. It is a property of the problem: from the outside you cannot see whose hand is on the mouse. Just don’t count on somebody else solving this for you, and don’t fall for a governance dashboard that only shows you the agents polite enough to announce themselves.

Agents are already in our systems. This morning, in mine, under my name.

Whether we can still account for that in two years is the open question.