01 / The operating case
What changes in a real workflow?
A deployment creates a new workload identity for an agent and is later decommissioned.
- 01Owner
- 02Agent + workload
- 03Task context
- 04Action decision
02 / Decision contract
What the executor must check
Issue identity with an owner and purpose, rotate credentials, suspend on compromise and retire at teardown.
03 / Failure and evidence
What goes wrong, and what can be proven?
The workload disappears but its identity and grant remain active.
Capture issuance, rotation, use, suspension, retirement and failed post-retirement calls.
04 / Canonical scope
Why this reference stands alone
Credential lifecycle covers secrets and tokens; this page owns principal state.
Technical artifact
Principal state must outlive ephemeral credentials
CREATED → ACTIVE → SUSPENDED → RETIRED credential K1 rotated to K2 during ACTIVE principal P remains stable for audit joins RETIRED rejects both K1 and K2
Run the denial test
Decommission the workload, then replay its last unexpired token. Retirement must stop access even when token signature and expiry are valid.
Primary references