TEKIMAXALOS

Short sign-ins, from places you allow.

A sign-in that never expires and works from anywhere is what actually goes wrong with agents. So the powerful ones here are the shortest lived, and you can say which countries and which networks any of them may be used from.

an engineer working at two screens

The more it can do, the sooner it ends

Sign in from a terminal and what you get by default is read-only, good for ninety days. Ask for enough to run a project and it lasts thirty. Ask for full access and it lasts a week. The reasoning is plain. A full sign-in that leaks costs you far more than a read-only one, so it is given far less time to be found.

  • Read-only: ninety days.
  • Enough to run a project: thirty days.
  • Full access: seven days.

A registered agent's sign-in lasts minutes

Those numbers are for a person at a terminal. An agent registered with the platform gets something far shorter: a sign-in good for five minutes, replaced as it works. A sign-in that short is worth very little to anybody who steals it. It is the reason stopping an agent has to act on the agent rather than on any one of its sign-ins.

How an agent keeps one name

And only from where you say

Your organization can say which countries and which networks any of its sign-ins may be used from.

The same rule for every kind of sign-in

There are three ways in. Your organization can mint a long-lived sign-in, or issue a key to a partner. The third is issued to a named person or a named agent when they sign in. The place rules apply to all three. A rule that held for two of them and not the third would be a rule that reads well and stops nothing.

Only a person creates one

Creating a sign-in, or stopping one, asks for a real person signed in at that moment. A machine sign-in cannot do it, however much it is allowed to do otherwise. That closes the loop an agent would otherwise have: reaching the thing that governs it and quietly issuing itself another.

a figure against a city window

Work in the background gets its own

When the platform runs a job for you in the background, it gives that job a sign-in of its own. It retires the previous one for the same job in the same step, so there is never a moment when both are live. The agent's name does not change with it, so the record still follows one agent across every run.

A connection that runs away is slowed

One connection gets sixty tool calls a minute. Past that the next call is refused, told plainly to stop looping and batch the work, and the refusal is written to your record. An agent stuck in a loop is a bill and a mess. It should hit a wall rather than a limit nobody notices until the invoice.

Two things worth saying plainly

A machine sign-in can be set never to expire. We would rather you did not, and the default is ninety days. And there is no single button that swaps one sign-in for another. Replacing one means creating the new one, moving what uses it, and stopping the old one, in that order.

Ask us how long your agents' sign-ins should last.

Talk to us