Cloudflare proposes an Agent Access Model (AAM) for software agents that act as principals on behalf of people and organizations. The post argues that BeyondCorp-style Zero Trust was designed around a human using a device at human speed, while agents may be ephemeral, long-lived, highly automated, and able to move data much faster. Existing controls may therefore fail quietly by granting excessive permissions, providing insufficient observability, and maintaining trust for too long. The article outlines AAM components, a concrete example, and the distinction between single-principal controls available today and the more difficult problem of multiplayer access control.
No heat snapshots are available in the last 24 hours.