Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

  • Home
  • Blog
  • AI
  • Beyond Static Secrets: Building Trust for the Next Generation of Workloads and AI Agents

Beyond Static Secrets: Building Trust for the Next Generation of Workloads and AI Agents

AI

Today, Keyfactor officially closed its acquisition of Cofide. We’re excited to welcome Matt Bates and the Cofide team to Keyfactor, but I think the bigger story is what brought our two companies together in the first place. 

We’re at an important transition in how enterprises establish digital trust. 

Cloud and DevOps have already changed the scale and speed at which machines interact. Now AI is accelerating that shift. Workloads and AI agents don’t simply sit within one application or environment. They communicate across services, call APIs, move between clouds and trust domains, and increasingly take actions without a person directly involved. 

Yet we’re still securing many of these systems using an approach designed for a very different world: give something a credential and trust whoever possesses it. 

But that model doesn’t scale to where we’re headed. 

The industry is moving from credentials to cryptographically verifiable identity 

The distinction between possessing a credential and proving an identity may sound subtle, but it’s increasingly important. 

Static secrets, long-lived tokens, and hard-coded keys prove that a system has access to a credential. They don’t necessarily prove that the system presenting it is the system that credential was intended for. If the credential is copied or stolen, that distinction disappears entirely. 

As the number of workloads grows, the problem becomes harder to contain. AI agents raise the stakes further because these systems may be authorized to initiate actions and interact with other systems autonomously. 

We can’t take the identity practices that already struggle at cloud scale and replicate them across potentially enormous populations of AI agents. 

Instead, workloads and agents need identities that are unique, cryptographically verifiable, short-lived, and governed throughout their lifecycle. 

The good news is that the industry has already made meaningful progress toward that model. 

The standards exist. Operationalizing them is the challenge. 

Open standards such as SPIFFE give the industry a foundation for establishing workload identity without relying on long-lived secrets. 

That’s important because we don’t need another proprietary identity model for every new cloud, platform, or type of workload. We need standards that allow trust to work across increasingly heterogeneous environments. 

But there’s a significant difference between having the right standard and making it practical for a large enterprise. 

That’s the problem Cofide has been focused on solving. Enterprises don’t operate like hyperscalers with unlimited engineering resources dedicated to building identity infrastructure around open-source implementations. They have Kubernetes pods, virtual machines, bare metal, serverless applications, multiple clouds, and legacy environments that all have to coexist. The Cofide solution provides workload identity management securing application workloads and AI agents across any cloud environment. 

As Matt explains, that complexity is only growing: 

“There’s an explosion in the number of applications, the numbers of replicas of applications to support scale. And of course, we’re now seeing in this era of AI, agents, and we’re going to see an explosion of those.” 

Standards give those environments a common foundation. The opportunity is to surround that foundation with the automation, governance, observability, and developer experience enterprises need to actually use it at scale.  

Why Cofide fits into the Trust Control Plane 

This is where I see a natural alignment between Cofide and Keyfactor. 

We’ve been building the Keyfactor Trust Control Plane around the idea that machine identities and cryptography can’t continue to be managed as a collection of disconnected security tools. 

Certificates are part of that infrastructure. So are keys, cryptographic algorithms and libraries, PKI, signing, and the policies governing how all those components are used. 

The Trust Control Plane brings those pieces into a continuous system for discovering, analyzing, provisioning, orchestrating, and governing trust across the enterprise. 

Cofide extends that vision into modern workload and AI agent identity. 

Its technology is built around open standards including SPIFFE, OAuth, and OIDC and is designed to give workloads unique, short-lived, cryptographically verified identities. That creates a path to extend trust deeper into Kubernetes, hybrid and multi-cloud environments, service-to-service interactions, and ultimately, the agent-to-agent and agent-to-tool interactions that will become increasingly important as AI adoption grows. 

That’s an important distinction. Workload identity shouldn’t become another isolated identity silo. It should be part of the same trust infrastructure organizations use to understand and govern machine identities and cryptography across the enterprise. 

AI makes getting this right more urgent 

Cloud and DevOps created enormous growth in machine identities. AI is accelerating that trend even further. 

The issue isn’t simply the number of identities organizations will need to manage. AI agents introduce a class of digital actor capable of accessing systems, calling APIs, communicating with other agents, but more importantlytaking actions on behalf of organizations. 

We can’t secure that future by repeating the practices of the past. 

Hard-coded keys, long-lived OAuth tokens, and credentials shared between systems create risk even in today’s environments. Applying the same model to autonomous agents operating at machine speed compounds that risk. 

Matt describes why runtime identity is so important: 

“You’re not providing some static key or token upfront that has standing privilege. Instead, what you’re doing is providing this credential at runtime, and you’re making sure that you can then use that identity together with some authorization to make sure the agent is doing as you’d expect.” 

Matt made the same point during a conversation with Dark Reading: “We can’t make the same mistakes with agents. We need to make sure that we’re building on standards.” 

That’s one of the most important principles for the next generation of machine identity. 

AI may be creating new use cases, but we shouldn’t respond by creating an entirely new set of proprietary security mechanisms around them. We should build on established standards, use cryptographic identity rather than persistent secrets wherever possible, automate identity lifecycles, and establish governance from the beginning.  

Trust must become part of the infrastructure 

Closing the Cofide acquisition is an important milestone, but it’s also the beginning of the next phase of our work together. 

Cloud-native architectures will continue to evolve. AI agents will become more capable, autonomous, and interconnected. And the number of non-human identities enterprises need to secure will continue to grow. 

For organizations adopting AI, this creates an opportunity to establish the right foundation now rather than repeating identity practices that were never designed for autonomous systems. Every workload and AI agent should be able to prove what it is, operate with the appropriate level of access, and have an identity that can be governed throughout its lifecycle. 

That requires more than another identity point solution. It requires open standards, cryptographically verified identity, and a unified Trust Control Plane capable of governing trust across machines, workloads, applications, and AI. 

With Cofide now part of Keyfactor, we’re extending that vision into one of the most important emerging areas of enterprise trust infrastructure. As AI changes what machines can do, we need to make sure trust is built in from the beginning. 

Read the full press release | What is trust infrastructure?