Leadership1 distinct publisher3 min readPublished
Uber built its internal agent platform in early 2025 and opened thousands of services to agent calls, then spent the rest of the year rebuilding identity because a pull request could not say which engineer asked for it.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The gap Uber describes is a category error in the identity model rather than a missing feature. Its existing scheme knows humans, and it knows workloads carrying credentials such as service accounts or API keys [6]. An agent, in Uber's own definition, is an entity authorized to act for or in the place of another, usually running as a workload doing something on behalf of a person [c6b]. That relationship is exactly what neither category encodes, so the strongest true statement the system can make about an agent-authored change is which workload made it.
Uber's illustrative incident involves one human and three named agents, with three handoffs: the engineer to the Oncall Agent, the Investigation Agent to the Monitoring Agent, and the Monitoring Agent to the code review system, where the artifact a human will later be asked about is created [11]. That is the small case. Because context is dropped at each hop [7], the number of places provenance can go missing scales with workflow composition, which Uber says is the normal shape of agentic work [13], and not with model quality.
The cost that compounds sits in the authorization layer. Uber notes that incomplete provenance limits its ability to apply consistently the fine-grained access policies downstream systems already have configured [7]. Those policies were written to evaluate a caller. When the caller resolves to a shared workload credential, the policy can only rule on what it is handed, and the organisation keeps the audit obligation while losing the use of controls it has already built and paid for.
The tradeoff Uber names is verifiability against velocity: it chose to extend the Zero Trust architecture it already ran rather than gate agents behind something new, explicitly to avoid slowing developers [8], with the stated aim of verifiable cryptographic identity plus enforced authorization downstream [9]. Note the order of operations. Platform first, in early 2025 [1], identity and access work through the rest of the year [3]. Teams walking the same path should expect the retrofit bill roughly a quarter or two behind the first successful demos.
A skeptic's objection is fair, and Uber raises it before anyone else can: this is one company describing its internal architecture and controlled production environments, and it says design choices and security controls may vary elsewhere [12]. That properly limits how much of the implementation transfers. The problem statement transfers further, because it follows from making existing service APIs agent-callable over MCP [2], which is the same move a great many enterprises are making with the same assumption that the caller is either a person or a service.
The board-deck version of this is a maturity story, and Uber frames the accountability question in board language itself: auditing, compliance and executive trust [4]. What the deck cannot yet carry is enforcement. The published material stops after the Agent Registry [15], described as the source of truth for agent-to-workload registration and consumed by a Security Token Service that verifies the agent [10]. On how a delegation chain is minted and checked in practice, this record does not say, and a registry is not by itself a check. Until that half is visible, the honest reading is that attribution here is designed for, not yet demonstrated, and the difference is what an auditor will eventually test.
Ranked by verification strength, evidence, and original report placement.
Uber says its microservices tech stack, comprising thousands of services, was made AI-ready by enabling MCP (Model Context Protocol) support over existing service APIs.
Uber says the architecture focuses on establishing verifiable cryptographic identity within the agent ecosystem and enforcing authorization for accessing downstream systems.
In Uber's motivating example, an Investigation Agent determined that a system was functioning correctly and the alert was misconfigured, then passed the task to a Monitoring Agent, which adjusted the alert threshold through a pull request; the pull request shows the Monitoring Agent introducing the change while the identity of the responsible on-call engineer remains untraceable.
Uber says the Oncall Agent started a session on behalf of the on-call engineer to investigate and fix a specific issue.
The published material supplied ends partway through the agent identity section, immediately after the description of the Agent Registry, without setting out how delegation chains are enforced.
Uber says that in early 2025 it built an internal Agent platform allowing teams to compose, deploy and operate production-grade agents at scale.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-sourced and self-reported
The architecture, problem statements and motivating example are described in unusual concrete detail, but everything rests on one first-party engineering post with no metrics, no external validation, and a text that breaks off before delegation-chain enforcement is specified.
Production at one large org, unquantified
There is credible disclosure of real production deployment — an agent platform in use since early 2025, thousands of MCP-enabled services, and named identity components wired into that path — but no counts, volumes, coverage percentages or third-party adopters, and adoption is confined to a single company's internal environment.
Title promises more closure than the text shows
Framing the work as solving the agent identity crisis runs ahead of what is demonstrated: the problem statements and component tour are solid, but the delegation-propagation mechanism is not shown in the supplied text, part of the work is a 2026 roadmap, and no audit, incident or test results are offered. The overstatement is modest because Uber includes an explicit scope caveat and concedes the untraceability that motivated the rebuild.
First-party engineering-brand publication
The only source is the subject's own engineering blog, a channel with recruiting, platform-credibility and security-posture incentives, and it is the same party that defines the problem, reports the deployment facts and grades its own remedy. Countervailing factors: it publicly admits an unattributable production change and states scope limits, and no product is being sold here.
Moderate-low
Facts about what Uber says and deployed are well attested by the primary document, so descriptive confidence is decent; confidence that the attribution problem is actually solved is low given single sourcing, no measurements, and truncation before the enforcement details.
product
Agent protocols now share one landlord: A2A joins MCP and AGENTS.md at the Linux Foundation1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
product
Canva's forecast cut turns model routing into a product line item1 distinct publisher
product
Baidu's AI line grew 25 percent and still lost the arithmetic1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026