Shared identity for agent tools.
We are exploring a shared identity layer for people and agents: fewer repeated sign-ins, explicit ownership, and access scoped to the task. Existing sys9 products continue to use their own authentication and authorization flows.
Scope is subject to change. No public release or API is announced.
A common identity, with explicit permissions.
The concept brings human sign-in and delegated agent access into one model. A participating service would decide which identities it trusts and what each identity can do. Account creation, recovery, and service adoption remain part of the design.
1. Identify the person or agent requesting access. 2. Authorize a specific action in a participating service. 3. Review, expire, or revoke that access.
Sign in. Delegate. Manage.
The goal is to simplify access without treating one login as permission to every resource.
Identity across services
Explore a common sign-in flow for participating services. Each product would still apply its own resource permissions; support across the stack is not available today.
A clear account lifecycle
Explore ways to connect an initial workspace to a verified owner, with explicit rules for account claiming and recovery.
Access for agent work
Explore scoped, revocable identities for automated work. CLI and API interfaces are part of the proposed direction, with details still to be defined.
Products with their own access controls.
Use each product’s current setup guide for authentication. These links describe existing products, not an auth9 integration.
Sandboxes
Create Boxes, execute commands, and fork filesystem snapshots with run9.
run9 → db9Postgres database
Create and query Postgres databases, with database branching for separate work.
db9 → drive9Shared filesystem
Store and share files using drive9’s filesystem interfaces and access controls.
drive9 → smith9Hosted agent sessions
Run agent sessions in managed environments with Smith9’s own authentication.
smith9 →Help shape agent identity.
Tell us where repeated sign-ins, account ownership, or delegated access gets in your way.