Paola Estefania de Campos De Franco
Paola Estefania de Campos De Franco

A person hiring an assistant would not hand over every password, bank login, email account, and private file with no limits. The assistant would have a role. They would have a job description. They would have permission to do some things and not others. Their access could be removed. Their actions could be reviewed. Paola Estefania de Campos De Franco believes AI agents should be treated with the same seriousness.

"Do not become your agent," de Campos says. "Hire it."

That distinction may become one of the most important security questions of the AI era. As agents begin booking travel, sending emails, managing accounts, using tools, and touching business systems, many are still being granted access in a way that was never designed for independent software actors. They use a user's password, token, API key, or broad account access. The system then treats the agent's actions as if the human user personally performed them.

de Campos sees that as the wrong default.

"If you would not give a human assistant your full identity, you should not give it to software," she says. "An agent needs authority, not impersonation."

Her work on the Agent Auth Protocol turns that argument into infrastructure: agents should be recognizable, limited, reviewable, and removable. The point is not to make agents less useful. It is to make their usefulness safer, clearer, and easier to control.

The industry's excitement around agents has moved faster than the infrastructure needed to govern them. Product demos often focus on what an agent can do: complete a purchase, summarize information, respond to a message, write code, or trigger a workflow. de Campos is focused on what happens underneath that action.

Who granted the authority? What exactly was allowed? Which agent acted? Was the action approved? Can access be removed without breaking the user's own account?

"The question is not only what the agent can do," she says. "The question is who the agent is, who it represents, and what boundaries it must respect."

That framing changes the conversation from convenience to delegation. A user should not have to share identity with an agent in order to receive help. The safer model is to let the agent operate as its own actor, with its own identity, under delegated authority from the user.

This is where de Campos' language becomes deliberate. She does not want agents to "be" users. She wants them to act for users within defined limits.

"Pretend to be me has to become act for me under these conditions," she says. "That is the difference between handing over control and creating accountable delegation."

The accountability problem becomes obvious in records. A system that hides the agent behind the user's name is not really preserving accountability. It is taking a shortcut. That shortcut may seem harmless when an agent is doing low-risk work, but it becomes dangerous once agents handle email, financial accounts, production systems, private data, or company workflows.

If a user delegates a task to an agent, the record should reflect that delegation. It should not collapse the human and the software into one indistinguishable actor.

"Audit logs should not hide the most important part of the story," de Campos says. "If an agent did the work, the record should show that."

Her warning is partly technical and partly historical. Technology tends to repeat the same pattern. A new capability arrives. The industry celebrates what can be built. Security, privacy, and accountability are patched in later, after habits harden and users are already exposed.

de Campos believes AI agents are at that same turning point now.

"The early internet taught us what happens when trust infrastructure comes too late," she says. "With agents, the cost of waiting could be much higher because the actions happen faster."

AI agents are increasingly positioned as actors. They can initiate tasks, chain actions together, use external tools, and operate across systems. That makes identity more complicated. It is no longer enough to know that a user logged in. A platform may also need to know what software is acting, what it is allowed to do, and whether its authority is still valid.

Paola Estefania de Campos De Franco
Paola Estefania de Campos De Franco

de Campos' perspective is shaped by years in identity engineering, including financial-grade authentication work at Auth0, now Okta, and her current role at Better Auth. That background gives her a direct view of the gap between the way human-centric identity systems were designed and the way agentic software is beginning to behave.

"People reach for credentials because credentials are familiar," de Campos says. "But familiar does not mean safe. Password sharing was never a good delegation model."

A better model would make every agent legible to the systems it touches. The agent would have a unique identity. The user would approve specific limits. The platform would record what happened. The user could remove the agent's authority. The system could distinguish between the human and the software acting on the human's behalf.

de Campos compares that to a professional relationship. A company does not give every employee the owner's login. It creates roles, permissions, review processes, and access controls. AI agents should be treated with at least that level of care.

"The kill switch is not optional," she says. "If the user cannot remove the agent cleanly, the system is asking for too much trust."

That point is especially important for companies preparing to deploy agents in production. A personal assistant bot making a low-risk recommendation is one thing. An agent that updates production data, accesses sensitive documents, or acts across customer systems is another. The same convenience that makes agents attractive can also make their mistakes harder to contain.

de Campos is not arguing against agentic AI. She is arguing for the infrastructure that would allow it to mature responsibly. Agents can be useful. They can reduce friction. They can carry out work people do not want to repeat. They can help businesses operate faster. But they should not do that by hiding behind a human identity.

"If agents are going to take on real responsibility, they need real accountability," she says.

That is the line de Campos wants the industry to draw now, before improvised access patterns become permanent. Her preferred future is one in which people can use agents confidently because the boundaries are visible and enforceable.

Give the agent a name. Give it a role. Give it limits. Track what it does. Remove it when needed.

"Agents should work for us," de Campos says. "They should not have to wear our identity to be useful."

For more information, visit the Agent Auth Protocol website.