<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Identity on Danilo Falcão da Silva</title><link>https://falcao.org/tags/identity/</link><description>Recent content in Identity on Danilo Falcão da Silva</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 15:14:57 -0300</lastBuildDate><atom:link href="https://falcao.org/tags/identity/index.xml" rel="self" type="application/rss+xml"/><item><title>Your AI Agent Is a Service Account That Can Improvise</title><link>https://falcao.org/posts/ai-agent-service-account-that-can-improvise/</link><pubDate>Tue, 11 Aug 2026 15:14:57 -0300</pubDate><guid>https://falcao.org/posts/ai-agent-service-account-that-can-improvise/</guid><description>&lt;p>An AI agent with production credentials is an identity problem before it is a model problem.&lt;/p>
&lt;p>The model gets the attention. The credential decides the blast radius.&lt;/p>
&lt;p>Once an agent can call an API, assume a cloud role, query a database, push an image, or open a pull request, IAM already has a category for it: non-human identity. Calling it an assistant does not change what appears in the audit log. A credential was presented, a policy was evaluated, and something happened.&lt;/p></description></item></channel></rss>