WG-UMA
Threads by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
August 2026
- 2 participants
- 1 discussions
Hi all, wanted to share this post from Eve.
It highlights recent UMA work in the AI authorization space by Nick G at
Strata Identity. Direct link to the webiste: https://u4a.ai and repo:
https://github.com/nickgamb/uma4agents
There has been a lot of progress since this post a couple of months ago!
If you're interested in discussing this work, let me know so we can
schedule a meeting.
Best,
- Alec
Alec Laws
CTO
Engineering | IDENTOS Inc.
[image: mobilePhone] (647)-822-1529
[image: emailAddress] alec(a)identos.ca
[image: twitter] <https://twitter.com/identos_inc>
[image: linkedin] <https://www.linkedin.com/company/identos-inc/>
---------- Forwarded message ---------
From: Eve Maler <eve(a)vennfactory.com>
Date: Wed, Jul 15, 2026 at 5:01 PM
Subject: A decade-old standard just got agent-shaped
To: <alec(a)identos.ca>
A working prototype answers the question every agent protocol dodges.
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
͏ ͏ ͏ ͏ ͏ ͏
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
[image: LinkedIn icon]
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
[image: Website icon]
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
[image: Website icon]
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
[image: YouTube icon]
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
Hi superfriend,
Almost exactly a year ago, I wrote about whether User-Managed Access (UMA)
— the standard I founded and ran for years at Kantara — had anything to
offer the AI agent moment. I called it Alice-to-Bob and Alice-to-Bot
sharing, and left it as an open question. This week, thanks to Nick Gamb,
it's not open anymore.
*UMA for Agents*
Every agent protocol available today answers one question: is this my
agent, doing my task, accessing the right digital stuff of mine? None of
them answer the harder one: is *your* agent allowed to touch *my* digital
stuff?
Most identity and security thinking about agents still models the solitary
case — one person, their own agent, the digital footprint they already have
— when the actual shape of an agent economy is Bob's agent showing up at
Alice's door, asking for a resource that's hers.
Alice's brokerage dashboard at Meridian Wealth — the actual resource Bob's
agent is asking to touch. Source: uma4agents
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
project.
Nick and I have spent months trading ideas on how old standards tech holds
up under agentic weight, and the proof-of-concept that answers it is his —
built directly out of that back-and-forth. It carries UMA 2.0 into
agent-shaped mechanics, paired with Dick Hardt's AAuth for agent identity
and proof-of-possession.
UMA was built for exactly this kind of asynchronous, policy-based consent —
what I described last year (for those of you who remember O.G. web access
management) as solving “WAM for people”: Alice gets access management
controls of the sort only enterprises normally use, and Bob's agent is told
how and where to ask for access instead of simply being denied.
In the demo, Alice is a brokerage client and Bob is her financial advisor.
His firm's agent asks for her holdings summary: granted automatically,
purpose-bound and expiring, decided against terms Alice set in advance. Her
transaction history: granted too, under stricter terms she dictated. Then
the agent asks to place an actual trade — Alice's policy says *“ask me”* —
so the request pends, her phone buzzes, and she approves that one trade,
and only that trade, from her couch. Every connection, every promised term,
every action taken lands in her activity ledger, and she can revoke any of
it, any time.
Every promise, every touch, every approval — tracked live in Alice's
activity ledger. Source: uma4agents
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
project.
This is at the heart of the mutual agency problem I describe in Chapter 11
of *Mastering Digital Identity*. For the standards backstory — requesting
parties, resource owners, why delegation matters here — my year-ago
post “Whither
User-Managed Access in the AI agent era?”
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
has the details. To see it just work, check out Nick's repo
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
*A 17-year-old sketch, made real*
The prototype does one more thing worth knowing about: it implements
MyTerms (IEEE Std 7012-2025), the new standard for machine-readable consent
terms, extended to cover the kinds of permissions agents actually request
and the terms an owner like Alice is willing to grant.
Applying MyTerms in this way descends directly from UMA's “Requesting Party
Policy” concept, which I developed along with original UMAnitarians like
Paul Bryan and Domenico Catalano. The UMA group was sketching
resource-sharing contracts back in 2009.
A 2009 mockup for fictional authorization service "CopMonkey"; the UMA
group’s earliest sketch of a resource-sharing contract picker. Source:
Kantara’s UMA Experience
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
wiki page.
Nick checked the prototype directly against the published 7012 standard:
Alice's terms live at a stable, dereferenceable address, and both sides
walk away holding the identical, signed record of exactly what was agreed.
*Come find me*
Here's the full roundup of stops in the next two months:
-
*July 16* — Book signing, North Texas ISSA Lunch 'n' Learn, Texas Star
Country Club, Euless, TX. Register on EventBrite
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
-
*July 21* — Talk, Q&A, and book signing, Silicon Valley ISSA, NetApp
offices, San Jose, CA. I'm bringing 100 complimentary copies courtesy of
Cyber1Armor. Register on Luma
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
-
*August 3* — Talk and book signing at Ross Young's CISO Retreat, Las
Vegas, NV. For CISOs and Deputy CISOs only. Register at CISO Tradecraft
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
-
*August 14* — Speaking, Kwaai.ai
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
virtual Friday public meeting. Details here
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
-
*September 1* — Panel and book signing, The Deepfake Summit, Washington,
DC. Convened by The Prism Project and Acuity Market Intelligence. Event
details
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
*Need identity strategy advice?*
If your organization is working through the tough questions of agent access
control — or any other identity strategy question — reach out. I've got
some advisory capacity available starting in October.
Talk to Eve about advisory work
<eve(a)vennfactory.com?subject=Advisory%20engagement&body=I'm%20interested%20in%20exploring%20your%20advisory%20services.%0A%0AOrganization%3A%20%0AKey%20advisory%20questions%3A%20%0ATimeframe%3A%20%0ABudget%3A%20%0AOther%20details%3A%20>
All my best,
Eve
P.S. If you haven't picked up *Mastering Digital Identity* yet, find out
where to buy it and get your free bonus chapter at the same time, at
*masteringdigitalidentity.com*
<https://vennfactory.us9.list-manage.com/track/click?u=e0aa8680af271a6c83ca2…>
.
*You’re receiving this email because you signed up to hear from me.*
Update your preferences
<https://vennfactory.us9.list-manage.com/profile?u=e0aa8680af271a6c83ca25927…>
or unsubscribe
<https://vennfactory.us9.list-manage.com/unsubscribe?u=e0aa8680af271a6c83ca2…>
View in browser
<https://mailchi.mp/vennfactory/julyb-uma4agents?e=816e8eca63>
2
1