How do agents get their identity?

Each agent is its own principal with an organization role. When a run starts it is bound to the agent, the requester, and the policy, and its permissions derive from the people it acts for.

Every agent carries its own identity as a first-class principal: no shared service accounts, no standing secrets. When a run starts, Context binds it to three things, the agent, the requester, and the policy, so an agent's permissions derive from the humans and teams it acts for. Connector credentials are then brokered per action rather than held by the agent.

Written for it and security, developers. Last reviewed 2026-09-15.

Still need an answer?

Tell us what you were looking for and we reply within one business day.

Contact the team →

Running a security review?

Documents, controls, and the request form live in the Trust Center.

Open the Trust Center →

Something to report?

Security findings go straight to the people who fix them.

security@context.ai