Short sign-ins, from places you allow.
A sign-in that never expires and works from anywhere is what actually goes wrong with AI agents. So the powerful ones here are the shortest lived, and you can say which countries and which networks any of them may be used from.

The more it can do, the sooner it ends
Sign in from a terminal and what you get by default is read-only, good for ninety days. Ask for enough to run a project and it lasts thirty. Ask for full access and it lasts a week. The reasoning is plain: a full sign-in that leaks costs you far more than a read-only one, so it is given far less time to be found.
- Read-only: ninety days.
- Enough to run a project: thirty days.
- Full access: seven days.
A registered AI agent's sign-in lasts minutes
Those numbers are for a human at a terminal. An AI agent registered with the platform gets something far shorter: a sign-in good for five minutes, replaced as it works. A sign-in that short is worth very little to anybody who steals it, and it is the reason stopping an AI agent has to act on the AI agent rather than on any one of its sign-ins.
How an AI agent keeps one nameAnd only from where you say
Your organisation can say which countries and which networks any of its sign-ins may be used from.
The same rule for every kind of sign-in
There are three ways in: a long-lived sign-in your organisation minted, a key issued to a partner, and one issued to a named human or a named AI agent when they signed in. The place rules apply to all three. A rule that held for two of them and not the third would be a rule that reads well and stops nothing.
Only a human creates one
Creating a sign-in, or stopping one, asks for a real human signed in at that moment. A machine sign-in cannot do it, however much it is allowed to do otherwise. That closes the loop an AI agent would otherwise have: reaching the thing that governs it and quietly issuing itself another.

Work in the background gets its own
When the platform runs a job for you in the background, it gives that job a sign-in of its own and retires the previous one for the same job in the same step, so there is never a moment when both are live. The AI agent's name does not change with it, so the record still follows one AI agent across every run.
A connection that runs away is slowed
One connection gets sixty tool calls a minute. Past that the next call is refused, told plainly to stop looping and batch the work, and the refusal is written to your record. An AI agent stuck in a loop is a bill and a mess, and it should hit a wall rather than a limit nobody notices until the invoice.
Two things worth saying plainly
A machine sign-in can be set never to expire. We would rather you did not, and the default is ninety days. And there is no single button that swaps one sign-in for another: replacing one means creating the new one, moving what uses it, and stopping the old one, in that order.
Ask us how long your AI agents' sign-ins should last.
Also in Governance
- ApprovalsAnything that cannot be undone is assigned to a human.Read the page
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- AI agent securityA name, a limit, and somebody who can stop it.Read the page
- AI agent identityA human lets an AI agent in, and can stop it again.Read the page
- What an AI agent may doIt never reaches further than the human it works for.Read the page
- Approved modelsWhich models may run, who approved each one, and what it left behind.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page