An agent and a person entering a server room through separate doors, each with its own badge and its own line in the access log

Agents as users of the infrastructure

Your agents write code, open PRs and maybe SSH into your machines. Stop and check what permissions they actually have while doing it, and don’t put your trust in policy files and the like. You will find the same access-control problems as always, the ones that show up the moment somebody who is not you starts logging into your servers. Why does it happen? Because you treat agents as tools and not as users. ...

September 4, 2026 · 6 min · Juanjo Payá