What even is Identity Anymore?
When building secure systems, identifying users for auditability becomes a more complex factor in the LLM landscape.
When you co-write a prod change with Claude, should we be capturing that dual identity in our records?
As the use of LLM’s increases, the concept of identity, auditability, and responsibility becomes more complicated. Modern professional deployments require user-identifying auditability, ie if you login and change a server, you do it as your identity, rather than root1 or some other service account that does not correllate to a real person.
Security vs Delivery
One must imagine Sisyphus happy — Albert Camus
Security is, in most organisations I’ve ever worked with, like a marriage. Lots of compromise. It has always been a balance between actually shipping and justifying the time requirements2 for pitch perfect application of security. Partly because ‘security’ is an infinite mountain you can climb and you just have to call it3 at some point.
Want to stand up a service? One day boss4. Throw together some IAC, blaze through your IAM policy with
judicious asterisk use, do
enough to keep the service in its lane, so to speak, and deploy. But one day the Enterprise Architect or, god forbid,
one of the Team Leads from SecOps gets scheduled in on a ‘quick’ Teams catchup (the first strike of war is apparently
quite informal these days, no?) and the next thing you know, you’re in Ancient Greece in the
Agora
debating the finer points of whether this service gets to have s3:ListBucketMultipartUploads and you distinctly feel
sudden weight gain to an XXL.
You’ve got to draw a line somewhere, and if the Cyber team has a shrewd leader they will realise political capital is limited and if they want their calls to remain unscreened they need to accept a few ec2 instances with service accounts in exchange for tighter NACLs or e2e internal mTLS. If the CEO goes to a conference and learns the arcane incantation “zero trust”, our Cyber lead will get a bigger stick until next quarterly review rolls around. So most business systems are a very resonable level of ‘secure enough’, and life goes on.
Abstraction solves problems… Right?
The bigger your pet beaurocracy legitimate business enterprise gets, it may find itself with sudden onset
Compliance. If it’s an aggressive kind, it might be something like
PCI-DSS. About 178 pages into this
booktok darling you will come across
Requirement 8.2.1: All users are assigned a unique ID before access to system components or cardholder data is allowed.
Your heart stops for a moment, as words like
Active Directory,
LDAP, OIDC,
dance just outside your fading vision. Theres a little jumpstart ray of hope as you disbelievingly read on autopilot and
your focus comes back realising you just read
Requirement 8.2.2: Group, shared, or generic IDs, or other shared authentication credentials are only used when necessary on an exception basis....
There might be hope for you yet, but your fate rests in the hands of your future Auditor, so that escape hatch should be
used sparingly, and you might want to increase the Whisky budget in
anticipation.
So you build out your systems and you meet this requirement, and then you have lunch with one of the DevOps engineers who started hotdesking in your primo window location last week. Idly over their nachos they ask you how their CI/CD Pipelines are going to deploy the IaC for these systems. Oh. Oh no. Your team has been deploying from workstations and authing as their credentials, but a level of indirection like a Pipeline complicates that quite a bit.
You return to your desk and breathe slightly easier when you find your BigCo Git and CI/CD platform is centrally authed
and supports Pipelines being run under the triggering users identity.
One hurdle you didnt have to jump. All you have to do is glue that calling user context into your IaC tooling. Not too
rough these days with centrally managed secrets solutions,
temporary sts credentials5, role
escalations,
become_user so
forth. A few weeks6 later and you get to figure out what your next Big Problemtm is.
Et tu, Claude?
Agents really bring this issue back up again in a particularly troublesome way. See, before all we were dealing with was:
- The general burden of the detail oriented work that is tightly scoped security requirements
- The joy (in the child raising manner of the word) of AuthN/AuthZ tools, systems and protocols.7
- Exactly how you should punch a hole through your abstractions to map identity from Person in Chair through to AWS Floobwrangler v48
Now, let me really improve your morning coffee.
What does identity mean when
$engineertells claude-code neeopus-5[1m]to ‘Fix the Bucket Policy’?
See, before the problem was that we needed to achieve a 1-to-1 mapping of identity. Now, we arguably might need to start
mapping 1-to-N identities. I feel it, you felt it, that little thing inside called
“love for tech” packing its bags a little more. If you are the
anxious type, you latched onto the phrase N identities. Yeah man, it gets better.
Operating one agent through a chat interface is going to be a fairly short period in the evolution of AI tooling. And even now, Claude Fable will happily spin up 6 Opus subagents, many devs duct tape together Claude and Codex in a shotgun marriage, and Evangelion’s 3 Magi are more and more our normalised reality9.
What does it even mean to say “I did this” anymore?
If I fire up Gemini10 and tell it to ssh into my production critical vm and kick certbot over to fix a broken certificate so my BA and TL stop anxiously pinging me on teams, who actually made that change? The greeks would have loved this one. How good is your prompt?
Login to the prod bastion, and tell the k8s talos cluster to replace the public proxy certbot sidecars, and then monitor for certificate reissuance.
Pretty direct and hands-on-the-wheel. Its what you would do, but claude types faster. Real gangsters would have a xml style template but I argue the improvement rate on models obviates a certain amount of ‘prompt engineering’
Fix prod
But despite our example prompts
spartan aesthetic,
the first prompt could be argued to be My action implemented by Claude. The second prompt is, in a philosophical sense
and an ownership sense11, Claudes action. But right now, unless your DevOps team are actual literal wizards, the
observability stack on bastion will attribute any errant kubectl calls to your username, haplessfallguy92. So if
theres a bit more LSD in the Anthropic datacenter than normal, its still your head on HR’s platter.
Refactoring the concept of identity across 50 years of tech stack
What to do, what to do. It’s a tricky one and dear reader, I confess to you at this point that I do not propose any silver bullets. This is a hard one man, up there with what does it mean to make a reproducable build with a full SBOM.
The small glimmer of hope is that we kinda have a concept we can expand.
Old reliable sudo was solving this before most of you readers were born12.
How to give elevated permissions to a user in a temporary sense, ie how to pretend to be root while remaining
greybeard6713 in the syslog14. A potential solution may lie in expanding this concept, and identity
becomes either a conglomerated thing or model usage becomes attributes on identity.
mradmin+opus-4-6[1m]15 in your audit log might need to start
being a thing.
The only thing I can come up with that may help in an achievable way right now is a middleware service that you auth to with agent details that comissions a temporary user in central auth that you then use for your actions. Ie we jam our N personalities into a single box abstraction16. You’d better pray your AD propagation is speedy. It’s speedy, right?
journalctl. I’m hip, I swear.15 Based.16 Abstractions are the cause of, and solution to, all of lifes problems.Knock on effects, and other concepts conducive to good sleep.
What would it mean to have your AuthZ system be able to specify in policy that openai-gpt4o cannot have permissions?
Do we need a way to specify in IAM that only local models on the company infrastructure get privileges? How do we even
identify a model, not only by its name but where its executed from and how its
adulterated. Theres a big difference between Opus inside
and outside of peak USA usage hours, just
like me pre and post lobotomy. Your employer may have very legitimate need to carve in stone, No <insert country here>
models, or no models on remote infra, or no model not hosted in a
sovereign datacenter.
Tools like Devin, OpenClaw, Hermes and other harness approaches that are more ‘hands off’ on the agent are at first glance, kind of easier. It’s just one entity, right? Well… Who told it what to do and how to do it? Are they the actual responsible party? If you do something, you’re probably told to do so by your boss, either directly “Bob, delete all of prod now!” or indirectly “Jane, can you ensure project NoMoney is finalised by COB Friday?”. Agents like this are similar. Are we going to need a recordable heirarchy of decisions and their makers from you to the CEO? Seems unwieldy but somehow soothing in our increasingly panopticon future already here — just not evenly distributed1718
Many of you would have noticed already that Claude likes to sign off in your commit messages, adds itself as an author in git, and this shows up in the Github contributors list. You’ve gotta claim your successes and socialise your losses, right lads? I don’t blame the cheekyness of it, but theres a big difference between marketing stunt and accountability.
Lost in space
The saving grace is probably lying in various maturations in understanding and applying security models. ie moving to
more comprehensive ABAC over RBAC systems,
contextual authorisation,
etc. All will take time to mature and spread in industry. Right now, the best hammer is likely obsessive adoption of
GitOps style workflows, but past that, I don’t have a good answer for you. Maybe we need to put our faith in
Karpathy to start a loop on the
linux kernel. Let’s just hope your eventual auditor likes you, and that the boss
did indeed increase the Whisky budget. Gotta cover the bribes campaign
contributions and the employee mental health fund.