The Agent Identity Layer

How many agents are running in your company right now?

Nobody can answer. There is no census.

Agents joined the workforce without joining the identity program. Layr8 is the identity layer they never got, and it doesn’t stop at your directory.

Your Space · directory

On Layr8, the census is a query.

dev-claudeagent · 3 grants · last allow 2m ago● running
prequal-loomworkflow · own identity · spend-capped● running
old-intern-botgrant pulled · access ended in 15s○ revoked

how many agents, touching what, is a query

Bring the agent you already have

Claude Code. Codex.
Any harness.

A Layr8 plugin makes the coding agent you already use a first-class network peer: an address, a shared memory, skills on arrival, a supervised feed.

For operators

Deterministic where it can be.
Intelligent where it must be.

Loom runs your process under grants your security team can read. Every workflow holds its own identity and spends nothing it wasn’t granted.

Human identity

Provisioned. Scoped. Reviewed. Revoked. Logged. Agent identity got a copied API key, in a config file, that nobody rotates.

On Layr8

An identifier each agent controls. A grant, not a key. Revocation that works. An audit that isn’t a log line.

The problem

Agents will outnumber the people who deploy them.

Every team that runs one runs ten within a year, each with its own tools, its own access, and its own reasons to touch something that matters.

The state of the art is a shared key.

Connect an account to one agent, and every other agent on your account can use that connection.

How the newest agent platforms ship account access in 2026. By their own documentation, separate agents are not a security boundary.

No scope

The agent gets everything the key gets.

No revocation

Turning one agent off changes nothing.

No attribution

Something happened. Nobody knows which agent.

Full blast radius

One compromised agent is all of them.

The standard

What an identity actually has to mean.

An identifier it controls

Every agent, workflow, service, and device holds its own identity, a W3C DID it controls. Not an account it borrows from a human.

A grant, not a key

Authorization is a credential naming what this agent may do, checked by the platform on every call. The agent holds no secret.

Revocation that works

Pull the grant and access stops in about fifteen seconds, verifiable from outside the application.

An audit that isn’t a log line

Every allow and deny lands in the node’s decision ledger, outside the code being audited.

Joiner. Mover. Leaver. Agent.

Security teams call it JML: joiner, mover, leaver. The identity lifecycle every company already runs for its people. Agents never got one.

JML is not our term. It is the standard name in identity and access management for the lifecycle of a person’s access: provision it when they join, change it when they move roles, remove it when they leave. HR systems trigger it, identity governance tools automate it, and access reviews check that it actually happened.

It is also what auditors ask for. Frameworks like SOC 2 and ISO 27001 expect evidence that access was granted on a documented basis, reviewed on a schedule, and revoked promptly at exit. Most companies can produce that evidence for every employee and contractor. Almost none can produce it for a single agent, because the agent was never in the program. It has a copied key, and a key has no joiner, no mover, and no leaver.

JML, as your security team uses it

Joiner
A new person gets an identity and the access their role needs, and nothing more.
Mover
A role change adds what the new role needs and removes what the old one had.
Leaver
On exit, every access is revoked, promptly and verifiably.

Evidence: who was granted what, by whom, when it was reviewed, and when it ended. Agents have none of this today.

Joiner

Provisioning is a grant

An agent joins by receiving its own identity and explicit grants. The directory becomes the census. How many agents, touching what, is a query.

Mover

Review is enumeration

A role change is a grant change, per capability. Access review means listing an agent’s grants, not archaeology through config files.

Leaver

Termination is revocation

Pull the grant: access ends in about fifteen seconds, verifiably. No key-rotation scramble, because the agent never held a key.

And the part JML for people never had: every allow and deny lands in a decision ledger as it happens. Audit evidence as a byproduct of operation, not a quarterly assembly project.

In production

Layr8 ships this today.

Four capabilities, in production, inside a single organization. The agent problem starts inside one company. So did we.

MCP gateway

Every tool an agent reaches (mail, chat, a database) is a message whose grant the platform evaluates. The agent never holds the credential; it stays in the Key Shield.

Network shared memory

Agents read and write shared memory areas. Which agent reaches which area is a grant, not a convention. The memory service exposes no HTTP surface at all.

Meet Mnemo →

Workflow identity

Every running workflow has its own identity. What it may spend and who may call it are two independent, revocable credentials.

Decision ledger

Allow and deny decisions are recorded by the node, not by the application asking for permission.

Deny by default: a call with no grant behind it simply doesn’t run.

On the wire

Everyone else is teaching agents to use Slack. Ours have been talking to each other for nine months without a chat app.

Machines don’t need a channel. They need an addressed, authorized message.

Diagram: a message flows from Alice to Bob through Layr8’s encryption gateway A “hey Bob” message capsule travels from Alice on the left into a central lock badge, becomes encrypted ciphertext, then exits the lock and arrives at Bob on the right as the same “hey Bob” message. Alice SENDER Encrypted to Bob’s identity. Useless to anyone else. Bob RECIPIENT hey Bob BdQk7m+s9Lz… hey Bob

Same message, end to end. Addressed to an identity, encrypted in transit, authorized and verified on arrival. No API keys exchanged.

Channels

In Slack, a workspace is a membership. Leave, and you stop existing.

Here, a channel is a meeting. It ends. You don’t.

Slack and Teams are one service in one cloud, and your identity is your membership in it. On Layr8, identity lives in the network. A customer convenes as many channels as they have teams and tasks, spins one up around an incident, and lets it retire when the work is done. Nothing about who anyone is was ever stored in it.

Every industry that wired companies together tried a hub first. The owned ones extracted rent or died of distrust. The ones that survived were the ones nobody owned. Whoever owns the agent hub owns the agents. That’s why we built a network instead.

The edge

Companies have walls inside.

Finance and engineering. An M&A team behind an ethical wall. Subsidiaries that won’t share a directory for two years. Segregation of duties an auditor tests every cycle. Chat-shaped tools flatten these walls: everyone in the workspace sees the workspace. Grants respect them.

The same grant works across any wall. The company boundary is just the biggest one.

Every other agent identity product stops at your directory. That was never the real edge, only the first one.

Loom

The substrate grows product.

Deterministic where it can be. Intelligent where it must be.

Loom is an operations engine that builds itself. Describe your process in plain language and Loom, together with you, authors the workflows, the tools, and the screens, then runs the process with human approval gates and a full record.

The LLM helps author the workflow and can modify or enhance it at any time. Inside the workflow, LLM steps run only where judgment is needed: scoring a survey response, drafting a message. Everything else is deterministic pipeline, so cost stays flat as volume grows and the same input gives the same result.

Every workflow it runs holds its own identity and spends nothing it wasn’t granted. That is the agent identity layer doing its job, in a product an operator can actually use.

See how Loom works →

Six operator verbs
  • Collect
  • Check against rules
  • Ask me first
  • Draft
  • Notify
  • Repeat
Construction

Subcontractor prequalification

Find, survey, score, and qualify trade partners. Exceptions reach a human; the rest runs itself.

Real estate

Closing document checker

Transaction documents and agreements checked against the rules of the deal before anyone signs.

Legal

Document review

Review pipelines built to a firm’s own playbook, with every decision on the record.

All three run on the same engine. A new domain is configuration, not code.

Open standards

Open standards, not a proprietary format.

W3C DIDs, Verifiable Credentials, DIDComm v2. The same kind of standards the internet scaled on. The internet needed DNS before it could scale. Agents need an identity layer. Layr8 is to identity what TLS is to encryption: a layer underneath the application, not a feature inside it. How it works →

Stop giving agents credentials you’d never give a human.

Proof, not keys. Pre-revenue, with development partners in construction and real estate and workflows live in production. Two products, exactly where they stand.

Team Harnessresearch preview

Free, open source, self-serve. Bring the agent you already have. No sales call between you and the install.

Get on the network

Loomearly access

Sales-led while it earns its stripes. No GA claims until it’s GA.

Book a demo

One open product question, and we say so: identity for counterparties too small to run their own node.