The Execution Broker: The Agent Never Holds The Credential
Summary
An execution broker that performs actions against external services on an agent's behalf, so the agent never receives the service credential. The unit of delegation stops being credential access and becomes authorised action: the agent presents an identity, a signed mandate, the specific action and its evidence; the broker verifies all of it, performs only the permitted operation using credentials held inside its own boundary, and returns a signed receipt. This closes a boundary three earlier pieces of work each named as the limit of their control — an authorised party misusing authority it legitimately holds — and it closes it by construction rather than by policy. Published here under a different name from the source document, which called it a Service Twin.
Key concepts
- The shift — from credential access to authorised action
- The boundary this closes — named three times, each as the stated limit of a control
- Receipts as the evidence chain — a fact with provenance, produced by the party that performed the action
- The concentration risk — the broker holds every credential, which inverts the property everything else depends on
Key ideas
- Encryption restricts who can read a mandate; the signature and subject binding establish who may exercise it.
- An agent that never holds a credential cannot leak one, whatever is injected into it.
- Enforcement is interpretation rather than proxying, so the broker is an interpreter per provider per capability.
- Self-hosting is the mitigation for concentration, not an enterprise upsell.
On this site
Became the execution page — renamed from Service Twin, because a digital twin represents a thing and this acts on one.