Logo
Home
Archive
Tags
About
Search
Sign in
Get The Context
Logo

Aug 28, 2026

4 min read

SHARE

‍

Journey to the edge of the earth

Antarctica

Edition No.5

‍

Step into a world of untouched beauty and icy grandeur. From towering glaciers to vast, silent expanses, explore the last great wilderness on Earth. Begin your Antarctic adventure today.

‍
Discover now
‍
Prompting Trust
‍
‍

Welcome back!

Some identities need to remain for years. Their permissions rarely do.

That distinction played out when CISA had to follow one exposed administrator across every environment they could reach. Revoking the credentials found in a public repository was only the first step; the agency also had to discover and rotate access elsewhere.

CoSAI approaches the problem from the design side. Its guidance gives an agent a stable identity for attribution, while making each task's credential short-lived and narrowly scoped. The record persists; the permission ends.

Transport for London's recovery shows the institutional burden when access cannot be unwound neatly. After a four-day intrusion, 27,000 employees had to reset passwords in person before disrupted digital services could recover.

These are not three versions of an AI incident. CISA and TfL involved conventional identity and access failures. They matter because they expose the operating conditions that autonomous systems will inherit: incomplete reach maps, persistent entitlement and revocation designed under pressure.

My perspective: accountability persists; authority expires. An organisation proves control when it can establish who sponsored an identity, what it may do, where it can act, what it did and when its permission ended.

This week's Big Read, The containment debt of permanent privilege, examines the operating liability created when any part of that chain remains unknown.

Context update

‍

Once access is granted, can the organisation still trace its reach, limit its scope and withdraw it without reconstructing the system under pressure?

Security Operations
‍

Reach defines the response

‍

The obvious response to credentials appearing in a public repository is to revoke what is visible. CISA's May response shows why visibility and reach are different problems.

After a contractor's AWS GovCloud credentials appeared on a personal GitHub account, CISA disabled the repository and development environment, removed the contractor's access and replaced the disclosed credentials.

The agency then rotated credentials across every environment where the same individual held administrator rights. The leak identified a starting point. The administrator's cross-system reach determined the containment boundary.

‍

Lesson: A leaked secret shows where exposure began. The identity's full reach determines what must be contained, rotated and independently verified.

Agent Security
‍

Identity should persist; authority should not

‍

Rather than discovering the authorisation reach during an incident, it really should be part of the access design process. CoSAI's 2026 agentic identity guidance recommends treating an agent as a first-class identity, distinct from the human or role it represents.

That identity is stable because attribution needs a durable reference point, but not a permanent credential.

For action, CoSAI recommends short-lived entitlement tied to a defined task. Scope should narrow at each downstream hop, and the final system should enforce what the token actually permits instead of relying on an earlier gateway decision.

The distinction is important because stable identities preserve the record of who or what acted. Expiring authority prevents that identity from carrying yesterday's permission into tomorrow's task.

‍

Lesson: Keep the identity durable enough to attribute action, but make its entitlement short-lived, task-bounded and enforceable at the destination.

Resilience
‍

Recovery tests the shape of authority

‍

Transport for London's 2024 breach shows what recovery looks like when compromised internal access cannot be withdrawn selectively. Court records, law-enforcement material and TfL disclosures describe a four-day intrusion followed by an institution-wide reset exercise.

All 27,000 employees had to reset their passwords in person. Digital booking and accessibility services were disrupted for weeks, while buses and the Underground continued to operate.

Password revocation alone did not preserve transport operations here; what carries over is the scale of authority that had to be unwound before digital recovery could proceed.

‍

Lesson: Recovery burden reveals prior access design. If revocation becomes an institution-wide manual exercise, authority was easier to grant than to withdraw.

In Focus

‍

The authority chain must exist before the incident

‍

The mechanism beneath these cases is not merely credential hygiene. It is the absence of an organisation-controlled authority chain: a live record connecting an identity to its sponsor, purpose, reach, actions, expiry and revocation path.

Start with sponsorship. Every agent, integration, service account and administrator should have a named owner who remains responsible for the identity's validity. The record should also identify the person or organisational role on whose behalf it acts.

Purpose comes next. A role label such as “automation” or “administrator” does not explain why authority exists. A useful purpose statement names the task, the permitted actions and the condition that ends the permission.

Reach must be positive and current. The organisation should know every system, environment and data boundary the identity can access without asking the identity, its holder or a vendor to reconstruct the answer.

Action evidence belongs at the systems where work occurs. Gateway logs can show that a request entered. They cannot prove that a downstream resource honoured its scope or record what the final system allowed.

Duration is where a temporary grant becomes standing privilege. An expiry date is useful, but task completion is the stronger boundary. Revocation then needs one accountable owner and a tested route across every place the entitlement was accepted.

These elements turn accountability from a policy claim into an operating capability. CoSAI's recommendations supply a useful architecture for agents, including narrower downstream scope, final-system enforcement and tamper-evident provenance.

Harvard Business Review's analysis of outsourced AI risk adds qualified pressure. Its liability framing varies by jurisdiction, contract and facts; it is not universal law. The practical governance question nevertheless survives: can the deploying organisation reconstruct what acted in its name from evidence it controls?

If the answer depends entirely on a supplier's records, accountability is conditional on the supplier's visibility. If expiry cannot be established, the authority chain has no ending.

This week's Big Read

‍

The containment debt of permanent privilege

‍

Why effective accountability depends on making authority temporary.

‍
Read the Big Read

Poll of the week

‍

Which authority fact would take longest to establish in your organisation today?

‍
1. The full reach of a privileged identity across every environment
2. The current purpose that still justifies its authority
3. A complete revocation path wherever its entitlement is accepted
4. The person who owns the decision to end its access

Cheat Sheet

‍

Four artefacts make the authority chain testable before recovery forces the exercise:

‍
01

An identity register.

‍

Name the sponsor, represented principal, current purpose, full reach and expiry condition for every privileged human or machine identity.

02

Task-bounded entitlement.

‍

Separate the durable attribution record from temporary credentials issued for defined work, and narrow scope at each downstream system.

03

Independent action evidence.

‍

Record what the final system allowed on an access path the acting identity cannot alter.

04

A rehearsed withdrawal route.

‍

Test who can revoke authority across every environment, including when the usual sponsor or vendor is unavailable.

‍
Get the full sheet

Standing privilege is deferred containment work. Its daily convenience is visible; its accumulated cost appears only when an organisation must locate, narrow and revoke access faster than its records allow.

The size of that bill was fixed before the breach. Each undocumented system, inherited entitlement and missing expiry condition added another dependency to an exercise nobody had scheduled.

Good governance keeps identity attributable while making authority disposable. The institution should retain evidence of action, not permission to repeat it indefinitely.

Choose one agent, service account or administrator this week. Trace every system it can reach, then find the record that says when its authority ends.

If the second step takes longer, reply and tell me where the trail stopped.

Use the referral page to pass the test to a colleague responsible for access or agent governance.

Until next week,

David

Recent
Set the blast radius before granting autonomy

Spotlight
AI hackers vs. zombie PCs

Jul 10, 2026

AI hackers vs. zombie PCs

AI hackers vs. zombie PCs

Aug 3, 2026

AI hackers vs. zombie PCs

Turning Big Ideas into Real-World Achievements

Jun 9, 2026

Turning Big Ideas into Real-World Achievements


Read next

Stay in the Loop

Get The Context

How AI systems behave. Where they fail. Why it matters. In your inbox, most weeks.


What it takes to trust AI at work

Pages

Home
Archive
Tags
About
Contact

Tools

Login
Update Password
Reset Password

Mechanism first Consequence second No noise
Security in Context Practical Analysis Trust in AI
© 2026 Prompting Trust.
beehiivPowered by beehiiv