MeshIDLayer
An identity-aware gateway that propagates each user's SSO identity through the agent-to-tool boundary as short-lived on-behalf-of tokens, so every action an agent takes is attributable to a real person and checked against policy.
An enterprise wires Claude Code, Cursor, and Copilot to its GitHub, Jira, and internal MCP servers, and discovers the connections run on shared machine-to-machine secrets. The moment an agent crosses into a tool, the human who triggered it is gone -- every action looks like the same service account. Security cannot answer 'which user did this,' policy cannot scope an agent to one person's access, and the audit trail the new logging mandates demand simply does not exist. The pain is verbatim from practitioners: user auth context disappears at the server boundary.
Platform and security engineering at large enterprises (1000+ employees) -- the team that owns how agents are allowed to touch internal systems and who is on the hook when an auditor asks which user an agent acted as.
Enterprises need per-user identity at the agent-tool boundary exactly where the protocol drops auth context -- the on-behalf-of token-exchange and policy mechanism is born of that specific, quoted tension.
Multiple confirmed, dated triggers cluster in 2026: a token-exchange standard shipping in gateways, new state and regional logging mandates, and a large fund flowing into agent infrastructure.
Strong LLM agreement and five confirmed or strong signals, but the cross-references and connections are few -- the echo around this idea is recent and narrow rather than broad.
The temporal window and the productive tension are the strongest part of this idea, and they are well-sourced. The pain is real, recent, and quoted from a practitioner; the enabling standard for delegating identity across the boundary only landed in gateways in April 2026; and dated logging mandates give buyers a reason to act now. Five confirmed or strong signals with named sources back it.
It scored in the mid-range, not as a gem, because the gap is contested rather than blind. Open-source and incumbent motion is moving toward this exact problem, not away from it, so 'why nobody did it' is mostly 'it is too new' rather than 'nobody can.' The buyer is identified only at the role level -- no budget line, no current-alternative line -- and an enterprise-security sale sits in tension with the lightweight, self-serve leverage that makes a gateway cheap to run. Convergence was real but narrow.
Genesis doesn't invent in isolation — MeshIDLayer shares architecture with, or powers, these ideas.
Discussion
No comments yet — be the first to weigh in.
