Harbour and Vine
One company, five agents, seven questions it cannot answer. No travel words this time.
In this episode
Transcript
No travel words this time
Passports for Agents. A series on identity and control for AI agents. Episode three: Harbour and Vine. Last time, the airport: every document checked, and why a photocopy gets you nowhere. This time, no travel at all. One company, and the agents it put to work this year.
Harbour and Vine, a Tuesday
Meet Harbour and Vine, an online retailer. This year it put agents to work. One handles refunds. One negotiates with suppliers, and increasingly with the suppliers' own agents. One writes campaigns. One reconciles invoices. One writes and ships code. Each of them spins up helpers for a task and lets them go. They call two model providers, a search service, the finance system, and the payment gateway. And on a laptop in the corner, someone has started an assistant of their own, using the company key, because it was there. Agents are not different from people in what they need. They are different in how many there are, how fast they act, and how easily they multiply.
The partner at the door
Then a call arrives from outside. I am your logistics partner's agent, here to move Thursday's deliveries. Nothing in the message says whether that is true. Meanwhile your own procurement agent is calling a supplier's agent, and the supplier is asking the same question about you.
The problem, in seven lines
Here is what Harbour and Vine cannot answer today. How many agents are running on our account? Nobody kept a list, and the laptop in the corner is not on it. Which agent issued that refund, and who approved it? All of them share one key with no name on it. Is this really our supplier's agent, or someone who copied its credentials? A copied key works from anywhere, forever. What did the campaign agent spend last night? The bill arrives as one number. Did customer data go out with that prompt? Nobody can see what left the building. Can we stop one agent without stopping all of them? There is one key to revoke. And when the auditor asks who did what, on whose authority, what do we show? A log file that anyone with the key could have edited.
The solution, in agent terms only
What would fix it, stated plainly. Every agent gets an identity that the company issued, with a named person who answers for it. Every agent is authorised for a purpose, with limits, for a time. Every agent has its own budget, and a way to pause or ask a person at the limit. Every request proves, freshly, that the real agent is making it, so a copied credential is useless. All checks happen at one place inside the company's own building, so the content never leaves. Every action is recorded in a ledger that shows tampering, with the responsible person first. Any agent can be switched off in one step. A partner can verify our agent without a project or a contract first, and we can verify theirs. The people stay in the directory we already run. We publish what papers a caller must show. And we can start by watching before we block. None of this is new. Every piece of it already exists, for people.
The fact, and the ask
Now the fact. In our own test, one run of five agents cost a quarter of a million tokens. Before passports, that arrived as one number, on one key. After passports, it arrived as five names, and one agent was responsible for nearly ninety percent of it. Nobody could have told you that the week before. Next time: six stamps we would rather not have. What travelling without papers has already cost other companies. Until then, count your agents. Take the ten-question passport check.
The product view: how the product answers this, on the home page
Watched elsewhere? Mark as watched
Captions and a full transcript are provided. The narration describes what is on screen.