Agent identity

Agents with their own identity, owner and access

Every Kosem agent has a badge: who owns it, which repositories it works on, where it may connect, which secrets it may use and which model it runs. It works in its own microVM, so there’s nothing to approve file by file.

Identity

Every agent gets a badge

Set up an agent like a new hire: a name, an owner, the repositories it works on, where it may connect and which secrets it may use. Nothing more, and every action is its own.

agent/billing
Fixes payment bugs
Claude Sonnet
Owner
Dana Levi
Payments
Repositories
billing-servicepayments-sdk
Network
github.comregistry.npmjs.orgapi.stripe.comEverything else is blocked.
Secrets, from the vault
STRIPE_TEST_KEY
A short-lived key for api.stripe.com, expires in 15:00
Questions go to
#payments
Recent activity, as agent/billing
  1. 12:01git clone billing-service
  2. 12:04npm test: 212 passed
  3. 12:06connect prod-db.internal:5432blocked

Autonomy

No approval prompts, because it has its own machine

An agent on your laptop asks before every command because it shares your machine and your keys. A Kosem agent works in its own microVM with only its badge’s access, so it can simply work. Move across the diagram to compare.

With Kosem
Runs as agent/billing, in its own microVM
microVM
agent/billing
  • billing-service repository
  • Every other repository
  • Stripe test API
  • Production database
  • Your SSH keys
  • Any website
  1. 12:01:04git clone billing-service
  2. 12:01:31npm test
  3. 12:02:12connect prod-db.internal:5432blocked
Without Kosem
Runs as you, with everything you can reach
your laptop
coding agent
  • billing-service repository
  • Every other repository
  • Stripe test API
  • Production database
  • Your SSH keys
  • Any website
  • Asks before every command
  • Sees every secret on the machine
  • Stops when the terminal closes

Give your agents badges, not keys

Kosem is in early access with a small group of engineering teams. Tell us about yours.