CAPABILITY≠ACCOUNT
Wait: if something is allowed to do a job, isn't it a user?
No. A component can be allowed to do one narrow job without ever becoming a permanent user.
- A smaller blast radius when something goes wrong.
- Less persistent identity to protect.
- Less user state piled up in one central place.
- Fewer credentials that turn into master keys.
- Components take part without joining one giant account system.
- Removing or replacing a component doesn't mean moving an identity around.
An agent gets one narrow job, and each thing it does is allowed one at a time, by the box doing the work. It never becomes a user. You never sign up for anything: no accounts is one consequence of this, not the whole idea. Built