Traditional applications generally have well-defined boundaries. They interact with a known set of services using credentials provisioned specifically for those connections.
Agents are different.
Their value comes from their ability to work across systems. An agent may need intelligence from a model, tools exposed through APIs and MCP servers, and context from enterprise data and event streams.
As agents become more capable, their access surface expands.
Without an identity layer sitting between the agent and those resources, that can quickly become:
**Agent → GitHub credential**
**Agent → Jira credential**
**Agent → Slack credential**
**Agent → Snowflake credential**
**Agent → Internal API credential**
**Agent → …**
Now consider what happens when that agent is compromised, manipulated, or simply behaves in a way you didn’t anticipate.
The problem is no longer just what the agent can do.
It’s **what credentials the agent possesses.**