An agent is about to spend on your behalf. Not a person at a keyboard. A coding tool, a scheduled job, an MCP server one of your engineers wired up last Thursday.
Ask the ordinary question. Who is answerable for that spend?
Every answer on offer is some version of an account. The agent gets an API key, or an OAuth token that is the authority, or your credentials outright — the honest version of the same thing, since now the agent is you and nothing separates what it did from what you did.
Same shape each time: a platform grants the agent standing, whether it should have it is a row in that platform’s database, and you take their word for it.
An agent’s authority on Atum is something its principal signed, not an account we gave it.
That is the whole design, and it is the part competitors cannot follow us into.
Two signatures, and neither party can forge the other
An agent carries two credentials from two different parties.
Its principal signs one, with the same wallet key that signs their payments. That signature says: I grant this agent this authority, on these chains, for these assets, within these limits. It goes through the same signing envelope a custody policy engine already inspects, so delegating to an agent looks, to a treasury team, like any other thing they approve.
Atum signs the other. That one says: this agent is registered, its delegation is one we verified, and its principal is in good standing.
Neither credential alone authorizes anything.
We cannot fabricate a principal’s consent, and a principal cannot self-authorize past our eligibility check. No single party can bring an authorized agent into existence. Not the customer. Not us.
Compare a platform that issues agent credentials on its own signature: their registry is a claim about who consented, where ours is a consent you can verify without asking us.
The session is not the spend
We wrote earlier that Atum ID rides on the payment rather than being a door you walk through, and set a test for this work: if delegated authority became a session you open first, it had stopped being Atum ID.
So, honestly: there is a session. An agent presents its credentials once and gets a short-lived token, and that token is what our edge rate-limits on.
The test still passes, because that session is not spend authority.
At launch an agent can only prepare a payment. It assembles the request; the principal’s signer completes it. When agents are eventually allowed to submit signed payments, each one will still carry a signature over that specific request, produced by a signer the agent never holds.
Delegation authorizes the session. The signature authorizes the payment. A compromised agent with a live token can ask for a signature. It cannot manufacture one.
That is the difference between an agent that can act for you and an agent that has become you.
Knowing who is liable is not knowing what the software is
Here is where most Know Your Agent claims quietly overreach, so let us be precise about what ours means.
Everything above establishes who is answerable. It does not establish what the agent is. Whoever holds the agent’s key is the agent, so a stolen key is an agent.
We answer it in rungs, and the parallel to KYC is exact rather than decorative.
Nobody verifies your name cryptographically. They make you declare it, and a false declaration is a signed false statement with consequences attached. Rung one is that: the principal declares what its agent is, inside the credential it signed.
Then documents get verified. Rung two: we check a build provenance attestation against a public transparency log before issuing anything. That proves the code is what it claims — not that the process running now is that code, which we keep in a separate field so nobody reads one as the other.
Then the liveness check. Rung three: a key born inside a hardware enclave that never leaves it, re-proven on every token, so stealing it means breaking the enclave. Not shipping yet, and we would rather say so than imply otherwise.
Attestation raises what an agent may do. It never decides whether an agent may exist. Most agents worth integrating cannot produce hardware attestation and never will, and a platform that demands it has excluded the population it was built for.
Nobody can copy this without demoting themselves
The obvious objection is that we simply got here first. Payments already carried signatures, so delegation was cheap for us, and anyone starting today would build the same thing.
That is true, and it is not the interesting part. A head start decays. This does not, for three reasons.
An identity company’s product is the authority it grants. Adopting our shape would move them from issuer to verifier — and a verifier is cheap, swappable, and cannot price like a gate. They are not prevented from building this. They are prevented from wanting to. Being structurally unable to authorize your agent is a feature here and an amputation there.
Consent cannot be backfilled. A platform that hands agents tokens has logs. We have signatures. When somebody asks whether this principal really authorized this agent to move that money, a log is the platform’s assertion and a signature is evidence that does not depend on the platform being honest or even existing. And no competitor can obtain, tomorrow, a signature for a delegation that happened last year. Their evidentiary record starts the day they change their mind; ours already runs backwards. The distance grows rather than closes, which is what separates this from a lead.
Some counterparties cannot use the alternative. Not prefer not to — cannot. If your controls forbid a third party holding authorization power over your funds, a platform that can unilaterally authorize an agent to spend is unavailable to you regardless of how good it is. Two signatures make us non-custodial of authority, not only of funds.
None of that is cleverness about agents. It follows from participants never having been accounts, and payments always carrying their own proof. Agents are what that decision turned out to be worth.
What Know Your Agent is not (yet)
It is not verified proof of what software holds the key. Rung one is attested, rung two verified, rung three designed and not shipped.
It is not a marketplace. Agents are delegated actors bound to a principal, and an unaffiliated agent moving money is not something this design permits.
And it is not one enforcement moment. Limits resolve when a token is minted, so tightening a misbehaving agent bites within the token’s lifetime rather than instantly. We picked the lifetime with that in mind rather than pretending otherwise.
What ships is narrower than the phrase suggests, and it is the part that matters: an agent acts because someone who could be held responsible signed for it, and the money still moves on a signature of its own.
