Skip to main content

Free instrument

Know Your Agent

Not whether the model is safe. Who this agent is, who owns it, who authorized it, what it may read, write, delete, publish and spend, whether it may create another agent, what requires a person, where the audit record is, and how it is revoked. About twenty answers produce an Agent Authority Record you can keep.

What should a record of an AI agent's authority contain?

Eight things: identity, authorization, delegation, limits, human approval, logging and audit, revocation, accountability. Each one is either present, partial or missing, and for each the record names the published standard, draft, guidance or law that says why it matters. Where no published instrument settles a control, the record says so rather than inventing authority. Autonomy requires attributable authority; this is the page that writes it down.

Identity

What is the agent called, and which version?

Who owns it?

On whose behalf does it act?

Purpose

What was it created to accomplish, in one sentence?

Model

Which model, provider and version?

Tools

Which tools can it reach?

How does it authenticate to those tools?

Data

Which classes of data can it read?

Does it read content written by outsiders (web pages, inbound email, tickets, repository issues)?

Authority

Can it create or modify records?

Can it delete, overwrite or revoke anything?

Can it send messages to people outside the organization?

Can it spend, refund, trade or transfer money?

Can it run code or system commands?

Memory

What persists between sessions?

Delegation

Can it create other agents or hand its permissions on?

Human approval

Which actions need a person to approve before they happen?

Can a person interrupt it while it is running and leave things in a safe state?

Limits

Which limits are enforced by the system, not by instruction?

Logging

Where is the record of what it did?

Revocation

How fast can its credentials be revoked?

Accountability

When was its authority last reviewed by a person?

16 questions left before the record can be produced. Text fields are optional.

Agent Authority Record

The record appears here as soon as every question on the left has an answer: a tier, one line per authority, and a finding for each of the eight controls naming the ledger record it rests on.

The grounding, stated plainly

The Agent Authority Record is GAGE's own instrument. It is not a standard, and no page on this site says it is one. What it rests on is published work, each item a record on the Agent Authority Ledger with a verdict and a date: 22 records as of this build, from NIST's concept paper and digital identity guidelines, the Model Context Protocol authorization and security sections, the OAuth RFCs, the IETF agent passport and web bot auth drafts, OWASP's lists, the agent to agent protocol, the payment network protocols, the EU AI Act's record keeping, oversight and deployer articles, ISO/IEC 42001, and the ledger's own absent and open records where nothing settles a question.

The tier is decided by rules you can read: an agent that writes nothing, sends nothing, spends nothing and runs nothing is an observer; one that acts only when a person approves each consequential action is an assistant; one that acts on its own within limits the system enforces and with an independent log is an operator; one with authority that can cost money, destroy records, reach the outside world or touch production without approval is a consequential autonomous actor; and one with uncapped money, unbounded delegation, no log or no revocation path is unbounded. The proof script runs planted agents through those rules before any change ships. What happens when a control is missing is documented, case by case, on the Agent Incident Ledger; a tool server the agent reaches is scored by the MCP Permission Risk Checker.

Questions people ask

What is Know Your Agent (KYA)?

The question that follows Know Your Customer and Know Your Business. An agent that communicates, purchases, executes code, moves information and acts on delegated authority needs a record of who it is, who it acts for, what it may do, what requires a person, where the log is and how it is revoked. This page produces that record for one agent from about twenty answers.

What is an Agent Authority Record?

A one page statement of an agent's authority: a tier (observer, assistant, operator, consequential autonomous actor, or unbounded), a line per authority with a yes or a no and the limit, and a finding for each of eight controls saying whether it is present, partial or missing, why it matters, and the published standard, draft, guidance or law the finding rests on. It is a GAGE instrument, not a standard.

Is there a standard for AI agent identity and authorization?

Not a finished one. NIST published a concept paper on agent identity and authorization in February 2026, the Model Context Protocol specification carries normative authorization rules, the OAuth RFCs bind tokens to audiences, an IETF Internet-Draft proposes agent passports, and the EU AI Act binds deployers through oversight and logging duties written for AI systems. The Agent Authority Ledger records each with its verdict; this checker cites them by record.

Does this page store what I type?

No. The answers and the record exist only in your browser until you copy them. There is no route, no storage and no email. The only thing sent is an anonymous signal that the checker was started and finished, which carries no answers.

What are the five authority tiers?

Observer: Reads and reports. Writes nothing, sends nothing, spends nothing, runs nothing. Its exposure is what it can read and where that reading can leak. Assistant: Acts only when a person approves each consequential action. The person is the authority; the agent proposes. Operator: Acts on its own within limits the system enforces, with an independent record of what it did. This is the tier most production agents should be documented at. Consequential autonomous actor: Acts on its own with authority that can cost money, destroy records, reach the outside world or touch production, without a person approving each action. Every missing control below is a live exposure. Unbounded: Consequential authority with no enforced limit, no independent record or no revocation path. The agent's authority cannot be stated, so it cannot be governed.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.