For every service account in a modern estate there will soon be three to ten AI agents — each one able to call tools, assume roles, and reach data on its own. Most are spun up with no identity of record, no stated purpose, and no expiry. An agent that drifts outside its mandate looks exactly like one doing its job, until it has already moved.
The outcomes, not just an alert.
- A signed Agent Passport per agent: scoped purpose, tool ceiling, and expiry — issued, not assumed
- Behavioral detection of agentic attacks — agents acting outside their granted mandate are flagged for your review
- Built on real standards: W3C Verifiable Credentials 2.0 and did:key, revocable via a Token Status List
- Every grant and revocation lands as a Verifiable Trust Receipt anyone can check offline, with no TrustFix account
- Honest boundary: this is detection and notification, not inline enforcement — you decide the response
Three steps to a provable result.
Each agent receives a signed Agent Passport stating its purpose, its allowed tools, and when it expires — a verifiable identity of record instead of an anonymous process.
Agent activity is measured against its own stated mandate, so the ones drifting toward recon, escalation, or exfiltration surface as a notification you can act on.
Every grant, flag, and revocation is written as a Verifiable Trust Receipt at a public URL — so the record of what an agent was allowed to do is checkable, not a screenshot.