alltio.
Blog · Identity and agents

Who keeps the record?

Fixed telephony connected places. Mobile connected people. IoT connected devices. Agents are next, and they break the pattern.

By Carl Gunell · August 5, 2026 · 4 min read

For most of my career, the industry has been answering one question: what are we connecting?

Fixed telephony connected places. Mobile connected people. IoT connected devices.

Agents are next, and they break the pattern.

A device reports. An agent decides. It calls a tool, spends money, and negotiates with other agents on behalf of a person or a company.

Four eras of connection: fixed telephony connected places, mobile connected people, IoT connected devices, and AI agents, which govern actions rather than move information. Beneath the agent layer sit identity, authorization, delegation, provenance, accountability and settlement, marked unclaimed.
The first three eras moved information. The fourth governs actions, and the layer underneath it is still unclaimed.

That moves identity out of the login and into liability.

Every action now has to answer four questions:

  • Who authorized it?
  • What were the limits?
  • What data informed it?
  • Who is accountable when it goes wrong?

This is not a theoretical problem. FIDO has a working group on it. The Decentralized Identity Foundation has a specification. Mastercard, Visa and Google are each pushing a framework of their own. These are separate efforts, not one standard.

The layer will be built. The open question is what it gets anchored to.

Europe has an anchor. Bank-issued eID has operated for years, and the European Digital Identity framework is creating a common wallet infrastructure across member states.

The United States has no equivalent national identity layer. The closest thing most people have is a driver’s license stored in a phone wallet. It is a holder for a document. It does not create a network where machines can verify authority, delegation and accountability.

This is where operators matter, but the usual argument is wrong.

Operators should not become identity providers. They have tried that before, and identity ownership is not their business.

What operators do have is unique: the ability to attest that a real, identity-checked, billed subscriber is bound to a device at national scale.

That is valuable, but authentication is only the beginning.

Knowing that a human is present tells you nothing about which agent that human delegated to, what permissions were granted, how long they last, or what happened after the action was taken.

The missing layer is not identity. It is the persistent record of agency: who acted, under what authority, using what information, and with what accountability.

In the past month, I have spoken with two people who reached the same conclusion from completely different directions. One arrived through ticket fraud. One through content provenance. I arrived through chain of title in licensing.

Three routes. One requirement: a verified principal, machine-readable permissions, and a trusted record of what happened.

Nobody is shipping that at scale. Not here, not in Europe.

So the question I would put to this industry: if operators authenticate and wallets identify, who keeps the record?

Put your knowledge on the record.

Free during the founding period — fingerprinted in your browser, never uploaded.

Register an asset