pki.sgit.ai / documents / execution-broker

The Execution Broker: The Agent Never Holds The Credential

TypeArchitecture brief Versionv0.33.60 Date19 August 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

An execution broker that performs actions against external services on an agent's behalf, so the agent never receives the service credential. The unit of delegation stops being credential access and becomes authorised action: the agent presents an identity, a signed mandate, the specific action and its evidence; the broker verifies all of it, performs only the permitted operation using credentials held inside its own boundary, and returns a signed receipt. This closes a boundary three earlier pieces of work each named as the limit of their control — an authorised party misusing authority it legitimately holds — and it closes it by construction rather than by policy. Published here under a different name from the source document, which called it a Service Twin.

Key concepts

Key ideas

On this site

Became the execution page — renamed from Service Twin, because a digital twin represents a thing and this acts on one.

Read the document

📄 Original document · v0.33.60 · 19 August 2026 · rendered from the raw markdown (the source of truth)