當 AI Agent 從回答問題走向呼叫 Tool、MCP 與 API 執行任務,企業該如何確認它是誰、代表誰,又憑什麼採取行動?本系列將用 30 天拆解 Agent Identity、Delegation 與 Authorization,從工作負載身分、使用者委派、逐次授權與 Human Approval,一路談到撤銷、稽核及可驗證證據。內容採 vendor-neutral、architecture-first 的方式,搭配本機可重現的 PoC,建立一套企業可落地的 Agent 權力治理架構。
Core Question 短效 authority 如何降低 Agent credential 洩漏風險,又不破壞多步任務? 今天的問題 客服 Agent 取...
Core Question 如何讓 authority 綁定 task goal、計畫或 workflow instance,避免被挪用到另一個任務? 今天的問...
Core Question 當 read Action 合法時,架構如何限制 Agent 將結果送往不允許的 Tool、domain 或 recipient?...