Know Your Agent (KYA) — Glossary

Know Your Agent (KYA) is the practice of establishing and verifying the identity, principal, permissions, and trust history of an autonomous AI agent before it is allowed to act.

KYC verifies the customer; KYA verifies the agent.

Why it matters

An agent is software that acts on behalf of a person or organisation, often with initiative across many steps. The service on the other side must decide, per request, whether the agent is genuine, who is accountable for it, and whether this action is within its authority. KYA is the name for doing that deliberately rather than implicitly.

It draws on established practice: digital identity assurance (NIST SP 800-63), per-request evaluation (zero trust, NIST SP 800-207), verifiable claims (W3C Verifiable Credentials), delegated authorization (OAuth), and the due-diligence mindset of KYC.

The need is now a formal work programme, not a thought experiment. NIST’s NCCoE is developing standards-based approaches to identify, authorise and govern software and AI agents, and the OpenID Foundation notes that today’s identity frameworks were not designed for recursive delegation chains or cross-domain trust.

What KYA covers

  • Agent identity — a verifiable identifier for the agent.
  • Principal — the accountable human or organisation.
  • Delegation — the explicit, scoped transfer of authority.
  • Credentials — verifiable proof of identity and rights.
  • Permissions — what the agent may do, up to what limits.
  • Audit trail — a record of actions and their authority.
  • Revocation — a fast, precise way to withdraw authority.

How it works in practice

A KYA check runs at the moment of action, not only at onboarding. The canonical flow has five steps:

  1. The principal grants the agent a scoped, time-limited delegation.
  2. The agent presents a verifiable credential to the service it wants to use.
  3. The service verifies the agent’s identity and that this action is inside its mandate.
  4. The action is written to an audit trail together with the agent, principal and authority.
  5. If something goes wrong, the delegation is revoked and the agent stops.

For a worked version of this sequence, see the guide How to verify an agent and the runnable snippets in the code examples. For the wider context, start with What is Know Your Agent?.

Common confusion

KYA is not a single ratified standard; it is an emerging umbrella term. Vendors often use it loosely. The useful test: how many of the items above does a given approach actually establish with verifiable evidence? For how the three disciplines compare, see KYA vs KYC vs KYB.

Related terms

Sources

  1. NIST, SP 800-63-4, Digital Identity Guidelines (accessed 2026-10-03)
  2. NIST, SP 800-207, Zero Trust Architecture (accessed 2026-10-03)
  3. W3C, Verifiable Credentials Data Model v2.0 (accessed 2026-10-03)
  4. IETF, draft-klrc-aiagent-auth-00, AI Agent Authentication and Authorization (accessed 2026-10-03)
  5. FATF, The FATF Recommendations (accessed 2026-10-03)
  6. NIST NCCoE, Agentic AI Identity and Authorization Resource Hub (accessed 2026-10-03)
  7. OpenID Foundation, Identity Management for Agentic AI (accessed 2026-10-03)

Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.