Opinion | The Architecture Of Permission
Opinion | The Architecture Of Permission
Aditya Vikram Kashyap
As AI agents become economic actors, the contest shifts from intelligence to permission. Future will be shaped by who controls the right to act—not just who builds smartest models
Somewhere in a bank’s operations department this year, a software agent will assemble a supplier payment. The amount will be correct, the beneficiary validated, the approval trail complete. Whether the money moves will have almost nothing to do with how intelligent the underlying model is. It will depend on whether the agent holds a credential the payment system recognises, scoped to that supplier, valid in that moment, issued by someone entitled to issue it. The most capable AI system in the world is inert without permission. A mediocre one holding the right credentials can move money.
For 20 years, digital infrastructure has been organised around identity: prove who a user is, and let the rest follow. The canonical reference, NIST’s Digital Identity Guidelines, finalised in its fourth revision in July 2025, is explicitly framed around proofing and authenticating users such as employees, contractors, and private individuals. People, in other words. Identity answers the question “who are you?" The question the agentic economy turns on is different: what are you allowed to do, on whose behalf, under what conditions, and who answers for the consequences? That is not an identity question. It is a question of delegated authority, and almost none of our digital institutions were built to answer it.
SCO, BRICS, UNGA: PM Modi Set For Diplomatic Marathon Month With Power-Packed Global Calendar
'Eww, This Isn't The Flex You Think It Is': Founder Fires Employee On Day 2, Gets Roasted Online
'I Have Anxiety': Boss Rejects Leave, Employee Quits On WhatsApp In Viral Chat
News18 Rising Bharat Summit South Edition: Decoding India's AI Agent Era
There is a rough historical pattern here, worth stating carefully. Industrial economies organised themselves around ownership: who held the land, the plant, the capital. The networked economy organised itself around identity: accounts, logins, profiles, the authenticated self as the unit of participation. If AI agents become routine economic actors, the organising question shifts again, from who you are to what you may do. Ownership, identity, permission. Each layer absorbed the previous one rather than replacing it, and each produced its own institutions, its own registries, and its own gatekeepers.
The population needing governance under that new question is already here. Palo Alto Networks’ 2026 Identity Security Landscape reports 109 machine identities for every human one, up from 82 a year earlier, and finds that nearly all surveyed organisations have now deployed AI agents alongside the familiar service accounts and API keys. Vendor figures deserve caution and estimates vary widely across studies, but every study points in the same direction. The detail worth sitting with........
