Section 18 of 102
17. Agent Identity
Stable section ID: S05-CON-010-SECTION-18 · 15 content blocks
Every System05 agent shall possess a unique, persistent, and verifiable identity before accessing protected information or performing authorized actions.
Agent identity should identify:
- The agent instance.
- The agent class or product.
- The responsible provider.
- The operating organization.
- The deployed model and relevant version.
- The active software configuration.
- The associated building, project, or operational domain.
- The credential issuer.
- The validity period.
- The current authorization status.
The identity shall support authentication, audit, permission assignment, incident investigation, suspension, and revocation.
A change to the underlying model, provider, security boundary, or safety-relevant configuration may require a new identity version or renewed qualification. Agents shall not impersonate users, engineers, devices, or other agents.
All consequential records shall identify whether an action was performed by a human, an agent, an automated deterministic system, or a coordinated combination of participants.