{
  "abstract": "A SharePlane systems thesis comparing Microsoft Agent 365 with GhostMesh, identifying where Microsoft's enterprise agent substrate should be consumed and where state-transition governance adds task-scoped authority, state-bound execution, temporary mutation claims, supersession, authority-aware reentry, evidence, and convergence.",
  "author": {
    "email": "tony@malott.ai",
    "email_url": "mailto:tony@malott.ai",
    "id": "person:tony-malott",
    "name": "Tony Malott",
    "resume_url": "https://malott.ai/resume/",
    "url": "https://malott.ai/"
  },
  "canonical_route": "/artifacts/when-agent-identity-is-not-enough/",
  "card": {
    "kicker": "Identity governs the actor. Execution authority governs the state transition.",
    "orientation": "Agent 365 validates the enterprise control-plane problem; GhostMesh explores the execution-governance layer beneath it.",
    "visual_motif": "state-transition-governance"
  },
  "claims": [
    {
      "caveat": "A governance principle derived from the distinction between identity authorization and execution authority, not a claim that Microsoft Agent 365 is defective.",
      "id": "claim:a365gm:identity-not-enough",
      "posture": "owner-architecture-synthesis",
      "support": [],
      "text": "A legitimate enterprise agent identity and valid standing permissions do not by themselves establish that a specific consequential state transition remains legitimate now."
    },
    {
      "caveat": "A proposed systems architecture assembled from established identity, distributed-systems, control-plane, and evidence concepts.",
      "id": "claim:a365gm:state-transition-governance",
      "posture": "owner-architecture-synthesis",
      "support": [],
      "text": "High-consequence agent systems benefit from explicit task-scoped authority, state preconditions, temporary mutation claims, supersession, authority-aware reentry, evidence, and convergence."
    },
    {
      "caveat": "An architectural integration proposal, not a Microsoft product commitment.",
      "id": "claim:a365gm:complementary-planes",
      "posture": "owner-architecture-recommendation",
      "support": [],
      "text": "Microsoft's enterprise agent governance and GhostMesh-style execution authority are potentially complementary when identity, runtime enforcement, execution legitimacy, and evidence/convergence remain separate control responsibilities."
    }
  ],
  "collections": [
    {
      "id": "collection:architecture-of-agency",
      "title": "The Architecture of Agency"
    }
  ],
  "dates": {
    "created": "2026-08-27",
    "published": "2026-08-27",
    "updated": "2026-08-27"
  },
  "featured": true,
  "format": {
    "depth": "Long-form architecture thesis with six explanatory figures and one hero visual",
    "interaction": "Responsive editorial reading experience with native figures, current-source references, provenance surface, related-work graph, author identity, and portable evidence",
    "label": "Systems thesis",
    "reading_time": "22 min"
  },
  "id": "artifact:when-agent-identity-is-not-enough",
  "lifecycle": {
    "authority_axes": {
      "creative_lock": "complete",
      "evidence": "complete",
      "native_image_ingress": "complete",
      "owner_acceptance": "complete",
      "public_corpus_admission": "complete",
      "relationships": "complete",
      "rendered_owner_uat": "complete",
      "semantic_lock": "complete",
      "source_authority": "complete"
    },
    "merge_authority": "granted",
    "owner_review": "accepted",
    "phase": "public-production",
    "production_authority": "granted",
    "state": "PUBLISHED",
    "terminal_target": "CANONICAL_PUBLIC_PRODUCTION_RELEASE_VERIFIED_AGENT365_GHOSTMESH_THESIS_V1"
  },
  "presentation_status": "owner-accepted-public-production",
  "production_promotion": {
    "authorityReceipt": "https://github.com/pinklon/shareplane-platform/issues/640#issuecomment-5447875534",
    "manuscriptMutationAuthorized": false,
    "nativeImageIngressComplete": true,
    "nativeImageIngressRequired": true,
    "ownerAcceptedVisualDirection": true,
    "preTerminalDisposition": "DEPLOYED_BUT_NOT_ADMITTED_AS_PUBLISHED_RELEASE",
    "preTerminalImmutableDeployment": "https://c37421dc.shareplane-platform.pages.dev",
    "preTerminalMainSha": "f3795ec4696d37ac7ef92e24dc4d0ee4c68aefed",
    "preTerminalProductionRun": 33138723367,
    "productionMutationBudget": 2,
    "productionMutationsUsed": 1,
    "visualRedesignAuthorized": false
  },
  "provenance": {
    "ai_assistance": {
      "role": "Collaborative research, architectural comparison, editorial refinement, measured-layout visual production, publication implementation, validation, and provenance serialization under Tony Malott's owner authority.",
      "used": true
    },
    "boundary": "Microsoft product statements are grounded in current Microsoft primary documentation. GhostMesh definitions are grounded in GhostMesh.ai. The comparison, state-transition governance synthesis, recommendations to Microsoft, and control-leverage framing are Tony Malott's architectural analysis.",
    "posture": "Owner-authored SharePlane systems thesis developed through direct review of current Microsoft primary documentation and the canonical GhostMesh architecture, with Microsoft product facts separated from Tony Malott's architectural synthesis and recommendations.",
    "sources": [
      {
        "id": "source:microsoft:agent-365",
        "locator": "https://learn.microsoft.com/en-us/microsoft-agent-365/",
        "publiclyExposed": true,
        "role": "Primary source for Agent 365 governance, Entra Agent ID, tool governance, Agent Framework checkpoints, human-in-the-loop behavior, and Agent Hooks.",
        "title": "Microsoft Agent 365 and Microsoft Agent Framework documentation",
        "type": "primary-vendor-documentation"
      },
      {
        "id": "source:ghostmesh:architecture",
        "locator": "https://ghostmesh.ai/architecture/",
        "publiclyExposed": true,
        "role": "Canonical source for GhostMesh closed-loop architecture, execution authority, state-transition governance, evidence, reconciliation, and provider-independent boundaries.",
        "title": "GhostMesh Architecture",
        "type": "canonical-owner-architecture"
      },
      {
        "id": "source:shareplane-platform:issue-640",
        "locator": "https://github.com/pinklon/shareplane-platform/issues/640",
        "publiclyExposed": true,
        "role": "Governs Tony Malott authorship, semantic and visual lock, SharePlane shell/trust-stack integration, exact native assets, merge authority, and canonical Production publication.",
        "title": "Publish When Agent Identity Is Not Enough — Agent 365 / GhostMesh SharePlane thesis",
        "type": "governing-owner-authority"
      }
    ]
  },
  "public": true,
  "public_route": "/artifacts/when-agent-identity-is-not-enough/",
  "public_safe_status": "owner-accepted-public-production",
  "relationships": [
    {
      "label": "Authored by Tony Malott",
      "target_id": "person:tony-malott",
      "type": "authored_by"
    },
    {
      "label": "Governed by SharePlane Platform Issue #640",
      "target_id": "issue:shareplane-platform:640",
      "type": "governed_by"
    },
    {
      "explanation": "The security-boundary thesis separates model capability from surrounding system controls; this Work extends the distinction into current execution authority, state, claims, and convergence.",
      "label": "Companion: The Agent Is Not the Security Boundary",
      "reader_group": "foundations",
      "target_id": "artifact:the-agent-is-not-the-security-boundary",
      "type": "companion"
    },
    {
      "explanation": "The control-plane thesis establishes the durable product around agents; this Work compares that principle with Microsoft's Agent 365 enterprise governance substrate.",
      "label": "Companion: The Agent Is Not the Product. The Control Plane Is.",
      "reader_group": "foundations",
      "target_id": "artifact:the-agent-is-not-the-product-the-control-plane-is",
      "type": "companion"
    }
  ],
  "route": "/artifacts/when-agent-identity-is-not-enough/",
  "schema_version": "2.0.0",
  "semantic_status": "locked",
  "slug": "when-agent-identity-is-not-enough",
  "source": {
    "content_status": "canonical-full",
    "format": "markdown",
    "path": "content/artifacts/when-agent-identity-is-not-enough/source.md"
  },
  "source_authority": {
    "accepted_visual_authority": "owner-accepted active-session thesis, six explanatory figures, and final hero",
    "governing_issue": 640,
    "native_publication_assets": [
      {
        "filename": "when-agent-identity-is-not-enough-hero.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/when-agent-identity-is-not-enough-hero.png"
      },
      {
        "filename": "01-four-control-planes-five-green-lights.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/01-four-control-planes-five-green-lights.png"
      },
      {
        "filename": "02-state-transition-governance.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/02-state-transition-governance.png"
      },
      {
        "filename": "03-authority-aware-reentry.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/03-authority-aware-reentry.png"
      },
      {
        "filename": "04-four-invariants-handshake.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/04-four-invariants-handshake.png"
      },
      {
        "filename": "05-microsoft-capabilities-ghostmesh-should-use.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/05-microsoft-capabilities-ghostmesh-should-use.png"
      },
      {
        "filename": "06-microsoft-next-strategic-frontier.png",
        "ingress_status": "CANONICAL_NATIVE_INGRESS_COMPLETE",
        "media_type": "image/png",
        "path": "static/artifacts/when-agent-identity-is-not-enough/assets/06-microsoft-next-strategic-frontier.png"
      }
    ]
  },
  "subtitle": "Microsoft Agent 365, GhostMesh, and the Emerging Problem of State-Transition Governance",
  "thesis": "Enterprise agent governance becomes insufficient when a legitimate actor can still attempt an illegitimate state transition; identity, runtime enforcement, execution authority, evidence, and convergence must remain distinct control layers.",
  "title": "When Agent Identity Is Not Enough",
  "topics": [
    "microsoft-agent-365",
    "ghostmesh",
    "state-transition-governance",
    "execution-authority",
    "agent-governance",
    "entra-agent-id",
    "agent-framework",
    "agent-hooks",
    "shareplane",
    "convergence",
    "control-leverage"
  ],
  "type": "systems-thesis",
  "voice": {
    "authority": "$write-in-tonys-voice",
    "reconciliation_receipt": "docs/publication/issue-640/tony-voice-reconciliation-v01.json"
  }
}
