Person人
Principal · first-class identity主体 · 一等身份
Dana: own credentials, own rights.Dana:自己的凭证,自己的权限。
Every agent is bound to a real person, so everything it does can be traced and audited.每个 Agent 绑定一个真人,它做的每一步都可追踪、可审计。
Why do agents need an identity?为什么需要身份?
So we gave them one.那就给它一个。
And more than that,不止如此,
How does it sign in?它怎么登录?
Principal · first-class identity主体 · 一等身份
Dana: own credentials, own rights.Dana:自己的凭证,自己的权限。
Delegated · bound to a person派生主体 · 绑定一个真人
dana.agent: rights ⊆ Dana.dana.agent:权限 ⊆ Dana。
Identity Provider · GenAuth身份提供方 · 就是 GenAuth
Keeps credentials, authenticates subjects, issues tokens. Bindings and policy live here.保存凭证、认证主体、签发 Token;绑定关系和策略也放在这里。
Single sign-on, for people and agents单点登录 · 人和 Agent 共用
Authenticate once at the IdP, enter every app that trusts it. Revoke once, every session ends.在 IdP 认证一次,所有信任它的应用都能进;撤销时一起下线。
Classic login · person's token传统登录 · 认人 Token
Legacy apps have only this door: the agent signs up as a regular user, and the audit chain ties it back to its person.老应用只有这扇门:Agent 注册成普通用户进来,靠审计链接回真人。
Verifies the agent token认 Agent Token
Knows whose agent it is, who it acts for and what it may do. Every step is logged; escalations go to the person.知道这是谁的 Agent、代表谁、能做什么;每一步留痕,越权去找真人审批。
GenAuth keeps every action in check.GenAuth 管住每一次动作。
One example: Dana asks dana.agent to follow up with Acme.一个例子:Dana 让 dana.agent 跟进客户 Acme。
The agent inherits Dana's access, nothing more.Agent 继承 Dana 的权限,
只能做 Dana 允许的事。
Every step it takes is checked live.它干的每一步,
都被实时裁决。
Dana revokes it, and every step stays on record.Dana 一键撤销,
每一步都有据可查。
From then on,从此,
Sign in once. Every SaaS opens.认证一次,所有 SaaS 都能进。
Checked at the protocol layer. Bound to a real person, every step traceable and auditable.协议层把关。绑定真人,每一步可追踪、可审计。
All together,合起来,