Identity and ownership
Who may act, and on what?
The first three lessons establish the actors and what each one owns, before any money appears.
| # | Lesson | You will attack |
|---|---|---|
| 1 | Humans and agents | an agent trying to make itself an approver |
| 2 | Ash policies and ownership | an agent writing customers; reassigning ownership |
| 3 | Tenant isolation | proposing with another agent's customer |
Humans and agents are different Ash resources, not one user table with a role column. An agent authenticates with an API key and can never hold the approver role. Ownership is per agent, and an unknown id returns the same error as someone else's id, so ownership cannot be probed.
Compare with Part IV, where the wallet owner is likewise the presented API key and never a tool argument (C6 · Bind identity to capability).