Free instrument
Know Your Agent
Not whether the model is safe. Who this agent is, who owns it, who authorized it, what it may read, write, delete, publish and spend, whether it may create another agent, what requires a person, where the audit record is, and how it is revoked. About twenty answers produce an Agent Authority Record you can keep.
What should a record of an AI agent's authority contain?
Eight things: identity, authorization, delegation, limits, human approval, logging and audit, revocation, accountability. Each one is either present, partial or missing, and for each the record names the published standard, draft, guidance or law that says why it matters. Where no published instrument settles a control, the record says so rather than inventing authority. Autonomy requires attributable authority; this is the page that writes it down.
16 questions left before the record can be produced. Text fields are optional.
Agent Authority Record
The record appears here as soon as every question on the left has an answer: a tier, one line per authority, and a finding for each of the eight controls naming the ledger record it rests on.
The grounding, stated plainly
The Agent Authority Record is GAGE's own instrument. It is not a standard, and no page on this site says it is one. What it rests on is published work, each item a record on the Agent Authority Ledger with a verdict and a date: 22 records as of this build, from NIST's concept paper and digital identity guidelines, the Model Context Protocol authorization and security sections, the OAuth RFCs, the IETF agent passport and web bot auth drafts, OWASP's lists, the agent to agent protocol, the payment network protocols, the EU AI Act's record keeping, oversight and deployer articles, ISO/IEC 42001, and the ledger's own absent and open records where nothing settles a question.
The tier is decided by rules you can read: an agent that writes nothing, sends nothing, spends nothing and runs nothing is an observer; one that acts only when a person approves each consequential action is an assistant; one that acts on its own within limits the system enforces and with an independent log is an operator; one with authority that can cost money, destroy records, reach the outside world or touch production without approval is a consequential autonomous actor; and one with uncapped money, unbounded delegation, no log or no revocation path is unbounded. The proof script runs planted agents through those rules before any change ships. What happens when a control is missing is documented, case by case, on the Agent Incident Ledger; a tool server the agent reaches is scored by the MCP Permission Risk Checker.
Questions people ask
What is Know Your Agent (KYA)?
The question that follows Know Your Customer and Know Your Business. An agent that communicates, purchases, executes code, moves information and acts on delegated authority needs a record of who it is, who it acts for, what it may do, what requires a person, where the log is and how it is revoked. This page produces that record for one agent from about twenty answers.
What is an Agent Authority Record?
A one page statement of an agent's authority: a tier (observer, assistant, operator, consequential autonomous actor, or unbounded), a line per authority with a yes or a no and the limit, and a finding for each of eight controls saying whether it is present, partial or missing, why it matters, and the published standard, draft, guidance or law the finding rests on. It is a GAGE instrument, not a standard.
Is there a standard for AI agent identity and authorization?
Not a finished one. NIST published a concept paper on agent identity and authorization in February 2026, the Model Context Protocol specification carries normative authorization rules, the OAuth RFCs bind tokens to audiences, an IETF Internet-Draft proposes agent passports, and the EU AI Act binds deployers through oversight and logging duties written for AI systems. The Agent Authority Ledger records each with its verdict; this checker cites them by record.
Does this page store what I type?
No. The answers and the record exist only in your browser until you copy them. There is no route, no storage and no email. The only thing sent is an anonymous signal that the checker was started and finished, which carries no answers.
What are the five authority tiers?
Observer: Reads and reports. Writes nothing, sends nothing, spends nothing, runs nothing. Its exposure is what it can read and where that reading can leak. Assistant: Acts only when a person approves each consequential action. The person is the authority; the agent proposes. Operator: Acts on its own within limits the system enforces, with an independent record of what it did. This is the tier most production agents should be documented at. Consequential autonomous actor: Acts on its own with authority that can cost money, destroy records, reach the outside world or touch production, without a person approving each action. Every missing control below is a live exposure. Unbounded: Consequential authority with no enforced limit, no independent record or no revocation path. The agent's authority cannot be stated, so it cannot be governed.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.