000
// issuing credentials…
TRUST LAYER · AGENT ERA · BY PRIMETHOUGHTS ↗

Every AI agent will need papers.

Verifiable identity, guarded access, and proof of every action — for the agents doing real work in your company. Built on open standards. No blockchain.

verified — admitted unknown — turned away
RIDING WITH THE AGENTS…
You're about to pass
the gate verified.
scroll to enter
01 · THE PROBLEM

Your company can't answer
three questions about its AI agents.

Q1

Who is this agent?

Agents borrow human passwords and share API keys. Impersonating one is trivial — and nobody can prove which agent did what.

Q2

What may it do?

Access is all-or-nothing. An agent allowed to read can often also write, delete, and spend. Delegation hands over far too much.

Q3

What did it do?

No tamper-evident record exists — nothing that would satisfy your security team, let alone a regulator asking questions.

JUL 2026

An autonomous agent ran an end-to-end intrusion of Hugging Face's production infrastructure — 17,000+ recorded actions. It defeated no identity architecture; it found static secrets and a network to cross.

Hugging Face disclosure, Jul 2026 ↗
DEC 2025

An AI coding tool with operator-level permissions reportedly deleted and recreated part of a production environment at Amazon — a thirteen-hour outage, and no approval workflow in its way.

AI Incident Database #1442 ↗
AUG 2025

Attackers stole the OAuth tokens of one AI chat integration and reached 700+ corporate Salesforce tenants. No password cracked, no MFA bypassed: the trusted integration itself was the credential.

Mandiant · UNC6395 ↗

// none of these was a model failure — each one is an identity and authorisation failure

0%
of security leaders say security concerns are slowing their AI-agent adoption
Okta / AlphaSights, Jan 2026 · n=150
0%
had at least one security incident caused by an AI agent in the past year
CSA & Token Security, Apr 2026 · n=418
0:1
machine identities per human employee — 79 of them AI agents
Palo Alto Networks, May 2026 · n=2,930
0%
have immutable audit logging of what their AI agents actually did
Palo Alto Networks, May 2026 · n=2,930
02 · THE ANSWER

Identity. Control. Proof.
One trust layer.

L1

Passport

Every agent gets a verifiable, forgery-proof identity anchored in your own domain — who built it, who runs it, what it's trusted to do. Think KYC, for agents.

VERIFIED IN MILLISECONDS · REVOKED IN ONE CLICK
L2

Gateway

A doorman in front of the systems you already run. Your rules, enforced on every call: least privilege, spending limits, human sign-off where it matters. And delegation only narrows — helpers an agent sponsors get a smaller slice of its authority, and suspending the parent cuts off every child in minutes.

YOUR SYSTEMS STAY UNCHANGED · 15-MINUTE SETUP
L3

Proof

A tamper-evident record of every action — who, on whose authority, under which rule. Each entry fingerprints the one before it, so the past can't be rewritten quietly. One click turns it into an evidence pack for an auditor.

EU AI ACT ART. 12 · AUTOMATIC EVENT LOGGING
03 · NINETY-TWO SECONDS

Watch an agent get its papers.

how-it-works.mp4● REC

Want the whole argument? ▶ Watch the full concept film · 6:17

Read the transcript instead (8 steps, ~2 min read)

Three questions every company fails today. Meet Aria, an AI agent that buys parts for Acme. Today she has no ID — like every agent, she borrows keys and passwords. Nobody can prove who she is.

  1. Identity. Aria gets a passport — a digitally signed ID proving who built her, who operates her, and what she may do. It's locked to her private key: a stolen copy is useless.
  2. The request. Every request now goes through the gateway — the doorman. Aria presents her passport plus a fresh signature proving she holds the key.
  3. Verify. In milliseconds, locally: signature genuine? Issuer on our trust list? Passport revoked? No blockchain, no phone-home — just math.
  4. Policy. Then the rules: "agents below Tier 1 never delete", "orders over €50,000 need a human". Written once, enforced on every single call.
  5. Scoped access. All checks pass, so Aria gets a five-minute token for exactly this task — not a master key. Helpers she delegates to get even less. Power only shrinks.
  6. The record. Every step lands in a tamper-evident record. Each entry fingerprints the one before it — change the past and the chain visibly breaks.
  7. When things go wrong. Aria compromised? One click revokes her passport, and within minutes every door in the ecosystem rejects her. No password rotations across 40 systems. One cut.
  8. The proof. When the auditor comes, one click turns the log into a regulator-ready evidence pack — who did what, on whose authority, under which rule. Article 12, answered.

Identity → Enforcement → Proof. A doorman in front of what you already have — installed in 15 minutes.

04 · FEEL THE DOOR

Two agents knock.
Only one gets in.

Pick an agent and send its request through the gateway. Watch the doorman work.

┌─ KNOWMYAGENTS GATEWAY ── awaiting request…
05 · ADOPTION

Fifteen minutes.
Nothing rebuilt.

01

Run the doorman

One container, in front of the systems your agents already use.

02

Issue passports

One command per agent, anchored in your own domain.

03

Watch first

Observe mode: nothing blocked, everything visible. Zero risk.

04

Enforce

Flip the rules live when you're ready. Your CTO can finally say yes.

FOR ENTERPRISES

Enter through the open-source gateway and govern your own agents first. The verdict stream — every admission and refusal, attributed — is yours from day one.

FOR AUTHORITIES

Pilot observe-only on a single rail: nothing blocked, everything visible. The same verdict stream those gateways already produce is the supervisory signal.

// setup is a container and one command per agent — no SDK, no code changes on your side

06 · NOTHING PROPRIETARY

Open standards.
No lock-in. No blockchain.

OAuth 2.1 OpenID for VC W3C DID SD-JWT MCP A2A EU AI ACT ART. 12 / 14

The same identity rails the EU digital wallet runs on — applied to agents. Anchored in DNS and cryptography, the trust roots the internet already accepts. EU data residency from day one.

Two obligations in the EU AI Act name what this layer produces. Article 12 requires systems to technically allow the automatic recording of events over their lifetime. Article 14(4)(e) requires human oversight that can interrupt a system through a stop button or equivalent — which is what revoking a passport does. Under the 2026 amendments, Article 50 transparency obligations apply from 2 December 2026, and the high-risk logging and oversight obligations from 2 December 2027 — the window to get evidence-ready.

07 · EARLY ACCESS

Someone has to issue the papers,
check them, and keep the record straight.

We're onboarding a small group of design partners — agent platforms and EU enterprises piloting agents.

$ knowmyagents verify --agent yours@your.domain