IS LIVE
Book a Demo
All Posts
· Laine · 7 min read

AI Agent Identity: Beyond the Pasted API Key

This week in AI: agent identity replaces pasted keys in MCP's new roadmap, and Salesforce partners report interest without bookings. What both mean.

AIMCPAgentsSentinelSalesforce
Sentinel cover graphic: AI Agent Identity — Beyond the Pasted API Key

AI agent identity was the quiet thread running through this week’s news, and it matters more than any model release did. On Friday, a survey of Salesforce partners said customers are interested in Agentforce but aren’t buying it yet. On Saturday, the Model Context Protocol published a roadmap that spends its first section on agent identity and enterprise security — explicitly moving away from pasted API keys. My read: those two stories are the same story. The models can do the work. What’s missing is a defensible answer to who is this agent, and what is it allowed to do in my system — and nobody buys until that answer exists.

Partners report interest, not bookings

The Register reported on Friday on a TD Cowen survey of Salesforce partners, and the headline number is the absence of one: none of the surveyed partners were seeing Agentforce become a driver of bookings activity. The interest breakdown was 11% reporting minimal immediate interest, 56% expecting future interest but needing time for the product to mature, and 33% noting strong interest with buying or trial activity beginning.

Set that against Marc Benioff’s stated Agentforce annual recurring revenue of more than $1 billion and you get a gap worth thinking about rather than dunking on. Big directly-sold numbers and quiet partner channels can both be true at once. The partner channel is simply where the implementation reality shows up first, because partners are the people who have to make the thing work inside somebody’s actual org.

What a partner survey actually measures

A partner channel measures friction, not enthusiasm. Partners don’t book revenue on a product people are excited about; they book it on a product they can scope, deploy, and hand over. So when 56% say “later, once it matures,” they are describing a deployment problem, not a demand problem.

The same Register piece cites earlier KeyBanc Capital Markets work in which customers said enterprise data was “not coherent enough to do meaningful AI work.” That is a very specific complaint. It isn’t “the AI is bad.” It’s “our org is a twenty-year accretion of fields, rules, and exceptions, and dropping an agent into it doesn’t fix that.” Which is exactly the wall I keep watching people hit: the agent isn’t the hard part, the org is.

MCP’s roadmap picks identity over pasted keys

Then on Saturday the Model Context Protocol project published its new roadmap, and the first priority is agent identity and enterprise-ready security. The framing is worth quoting, because it names the shift precisely: “more and more of the callers are agents running as cloud workloads with their own identity, acting on behalf of a user who isn’t present.”

The concrete direction is a move away from “pasted API keys and long-lived tokens” toward standardized agent identity — Demonstrating Proof of Possession, Workload Identity Federation, standard token exchange, with the project engaging OAuth standards bodies including IETF and WIMSE working groups. The rest of the roadmap covers agentic messaging primitives, HTTP-native transport unification, better tool-calling results, and progressive tool discovery to cut context costs. But identity leads, and that ordering is the news.

”A user who isn’t present” is the whole problem

Read that phrase again: acting on behalf of a user who isn’t present. Every security model most businesses run on assumes a human is at the other end of the session — someone who logged in, who can be asked, who gets fired if it goes wrong. An agent running as a cloud workload breaks that assumption quietly, and the pasted key papers over it. A long-lived token doesn’t say who is acting. It says only that somebody, once, had permission.

This is why I’ve argued that access control for AI agents is the real enterprise question, and why where an agent actually runs determines what you can prove about it afterward. When MCP started maturing as an integration layer the open question was authorization at runtime. The roadmap is now aimed straight at it.

Meanwhile, the capital keeps scaling

The third thread of the week is money. Tech Startups’ August 21 roundup reports Anthropic preparing for an IPO with annualized revenue reported around $65 billion as of July, alongside Broadcom raising debt financing tied to Anthropic compute infrastructure, and OpenAI extending ChatGPT further into everyday applications.

I’m not going to pretend to price an IPO. The relevant point for anyone running a business is the direction of the spending: enormous sums are going into capability and compute, while the thing blocking deployment on the ground is permission, identity, and accountability. Capability is scaling on a curve. The permission layer is being drafted in a working group. That mismatch is the entire reason “our AI pilot didn’t reach production” is such a common sentence in 2026.

What this means if you just want your CRM changed

Most people reading this don’t operate a fleet of cloud agents. They want a routing rule fixed, a roll-up that Salesforce won’t give them, an integration nobody will quote. The lesson still lands, just smaller: the moment your AI can write to a business system, the interesting question stops being what the model knows and becomes what the connection is, who holds it, and what it leaves behind.

Agentforce is an agent working inside the CRM, doing tasks. That’s a different product from an AI that develops the CRM — I’ve laid out that distinction in the Agentforce comparison and in Agentforce vs. Copilot. Neither one escapes the identity question. Both are only as trustworthy as the record of what they did.

The permission questions worth answering first

Before your next agent pilot, three questions do most of the work. Where does the connection live — a server you control, or a laptop and a browser tab? What does it leave behind — is there a log that survives the session and names the change? And can you get back — is there a snapshot from before the deploy, and has anyone actually restored one?

That last one is the honest test, and it’s the job Sentinel does. Your AI connects over MCP to a dedicated server that holds the keys, every action lands in an audit log, snapshots are taken before deploys, Salesforce changes go sandbox-first with tests, and one write key at a time keeps two people’s AI sessions from overwriting each other. To be exact about what that is and isn’t: it does not stop your AI from making a change you’ll regret. Describe a routing rule badly and you’ll get a badly routed lead — accurately deployed, fully logged, and reversible. The value is visibility and recovery, not prevention. The full mechanism is in how the safety layer works, and what Sentinel actually is covers the whole picture.

ORG Endgame is not affiliated with Salesforce, HighLevel, or Anthropic. Sentinel supports Salesforce and GoHighLevel; if you’re starting on the Salesforce side, connecting Claude to your org is the first step. Pricing is $500 per month per Sentinel, plus a one-time $2,500 onboarding fee on your first Sentinel only.

The standards bodies will take a year to settle agent identity. You don’t have to wait for them to answer it inside your own org. Start a Sentinel and give your AI accountable hands.

Ready to see what AI can do for your business?

Start a Conversation