Skip to main content

Service account

Every agent runs under the organization's service account — never under the account of the person who triggered it.

Why not your account​

A schedule fires at three in the morning. An HTTP address is called by a system, with no person involved. If the run depended on your session, it would stop when you went on holiday — or, worse, keep acting in your name after you left the company.

The service account settles that: the organization answers for its agents' actions.

One per organization​

There is one service account per organization, configured by whoever administers the organization in Imaginne. It has to be active for agents to run.

With no active service account:

  • agents with AI steps do not publish;
  • runs fail right at the start, with an explicit message.

What it decides​

DecisionConsequence
Who answers for the actionThe audit trail records the organization as the executor
Which policies applyThe organization's policies resolved for that identity
What the AI can reachThe skills and integrations permitted for that identity

The three axes, never mixed​

AxisWhat it records
Who askedThe person who triggered it, or the run that called it
How it was triggeredManual, schedule, address, another agent, re-run
Which identity it ran underThe service account

No client request can alter those values: they come from the session and from the organization's configuration, never from a header or a body field.

Permissions granted during a run​

Each run receives a short-scoped authorization, valid only for that run, containing exactly what the published version declared.

Two properties:

  • No step adds capability. What a step asks for is checked against what the run received; asking for more is refused.
  • The authorization is issued at run time, not when the run is created — a run that sat in a queue does not start with an expired authorization.

When something goes wrong​

SymptomMeaning
Failure because no service account is configuredThe organization has no service account
Failure because the account is disabledIt exists and is inactive
Failure because of a divergent identityThe run was created under another identity
Failure because the authorization was revoked or expiredThe run lost its authorization mid-work

In every case, the run fails rather than continuing with less than it should have.

Next steps​