Agent access should expire with the task
Cloudflare binds an agent credential to one task and narrows it as the task runs. A seed investor argues the same rule two days later.

A standing credential is the wrong shape for work that ends. Cloudflare published the Agent Access Model on 2026-08-05. Its first principle is lifetime. An agent receives a credential minted for the task and expiring with it. A seed investor made the same argument to enterprise buyers two days later, from the other side of the purchase order. Two unrelated first-party sources reached the same rule inside one week.
An agent here means software that carries a task through several steps by choosing models, tools, and actions. A harness is the software layer that runs it and executes its tool calls. Both terms matter below, because the whole argument turns on where authority lives.
Four ways human-shaped controls miss
Cloudflare names four properties that make service-account and user-shaped controls a poor fit:
- Credentials outlive the work. Long-lived service-account keys applied to short-lived agents remain in memory, logs, or environment variables where they can be replayed.
- Agents act at machine speed. One with a database connection and an outbound path can read a table and POST it to an external endpoint before a sampling control reacts. Detection tuned for human activity may react too slowly.
- A prompt cannot hold a boundary. Injected content can steer a model past its instructions, so Cloudflare says a boundary you can talk your way past is not a boundary.
- Authority blurs across hops. An agent can invoke a tool that invokes another agent, which calls an API on behalf of the original human. That chaining is multi-hop delegation, and Cloudflare says the answer to who the work is for can disappear somewhere in the chain.
Two of those failures are about time, one is about where enforcement lives, and one is about who the work serves. A better model closes none of them, because every one of them is decided outside the model.
The credential expires when the task does
At dispatch, an Agent Identity Broker issues a short-lived, verifiable credential scoped to the task. An identity broker is the service that mints that credential. Task-scoped means the credential names three things: the agent, the person it acts for, and the one task it may do. Cloudflare states the lifetime rule flatly. That credential expires no later than the task ends.
Expiry alone still leaves a stolen token useful for its window, so the credential carries a second binding. Cloudflare says it is bound to a proof key held by the harness, and that a leaked token alone cannot be replayed without that key. A proof key is a secret the harness keeps, and the model never receives it.
Change the lifetime and the operating burden changes with it. A standing key has to be discovered, rotated, reviewed, and defended forever. A task credential has to survive minutes.
Capability narrows during a task and never widens back
Cloudflare’s second move makes trust stateful. It calls the mechanism a Trust Ratchet, and the mechanical image is the whole idea: its capability state can only narrow during the task. When a declared protected event occurs, the ratchet removes capabilities across the run according to policy. Nothing inside the task can put them back. Cloudflare gives one recovery path: authority removed by the Trust Ratchet returns only in a newly authorized task.
Read that last sentence as an operations rule rather than a security slogan. An agent that hits a wall mid-task cannot be waved through by an approver, because the wall is the task’s own state. Recovery means dispatching a new task with a new grant. Anyone who has approved an exception at 2am to keep a job moving will feel the cost of that rule, and the point of it.
Enforcement with no record leaves nobody able to answer for it later. So Cloudflare pairs the active controls with an Agent Activity Log. Cloudflare describes an append-only, queryable record fed by five control points. Those are the identity broker, the harness, the ratchet state store, the network enforcement point, and the engine that authorizes each action. Append-only means an entry can be added and never edited or deleted. Cloudflare notes that the log does not depend on the model’s account of its own behavior.
What makes it useful is the join it preserves. Each record ties each covered enforcement event back to the task and its initiating principal. An initiating principal is the person or system whose authority started the work. Two questions then have real answers: what did this agent do, and what was done on behalf of this person.
An investor argues the same case from the buying side
Ed Sim of boldstart ventures recorded a CXOTalk episode on 2026-08-07, two days after the Cloudflare post. Asked about the agent attack surface, he questioned whether an agent acting under your login should get forever access to Salesforce. His answer arrives in the segment that starts at 10:32: “It should be granted access dynamically, and it should be granted access that kind of dies out very quickly when the task is over.”
The reason he gives is containment. When thousands of agents run inside one company, a narrow authorization keeps the blast radius contained after something gets hacked. He also calls the runtime version of this very hard to build and very hard to deliver.
Weigh that source for what it is. Ed Sim invests in this category, and he named a portfolio company working on agent access in the same answer. Treat the claim as an interested first-party opinion rather than a neutral survey. It still lands on the rule Cloudflare had written down two days earlier, and the two were not talking to each other.
Cloudflare will not claim the multiplayer case
The most useful line in the post concedes a limit. Cloudflare writes: “We are not comfortable saying that multiplayer access control can be built end to end today.” One human authorizing one task has usable primitives today. Several people sharing one agent’s context does not.
Cloudflare cites measurement behind that caution. It reports that CI-Work found privacy-violation rates of 15.8% to 50.9% and leakage up to 26.7% in simulated enterprise workflows. Simulation is not production, and a spread that wide tells you the category is unsettled. It is still the bar an honest version of this architecture has to clear.
Cloudflare, CXOTalk, Ed Sim, and boldstart ventures appear here as public evidence. None of them is a Muniment customer or endorser.
Join the waitlist if your fleet still runs on credentials that outlive the work they were issued for.
Both sources stop at the same place. Cloudflare says it does not know of a widely deployed end-to-end system that closes the whole chain. Ed Sim says the runtime version is hard to deliver. Two parties with nothing in common agree on where the boundary belongs. Neither has finished putting it there.
Sources
- Cloudflare: The Agent Access Model blog.cloudflare.com
- CXOTalk episode 928: Top VC Perspective: Where Enterprise AI Is Headed www.cxotalk.com
- CXOTalk episode 928 recording, segment starting at 10:32 www.youtube.com