Service account
Every agent runs under the organization's service account — never under the account of the person who triggered it.
Why not your account
A schedule fires at three in the morning. An HTTP address is called by a system, with no person involved. If the run depended on your session, it would stop when you went on holiday — or, worse, keep acting in your name after you left the company.
The service account settles that: the organization answers for its agents' actions.
One per organization
There is one service account per organization, configured by whoever administers the organization in Imaginne. It has to be active for agents to run.
With no active service account:
- agents with AI steps do not publish;
- runs fail right at the start, with an explicit message.
What it decides
| Decision | Consequence |
|---|---|
| Who answers for the action | The audit trail records the organization as the executor |
| Which policies apply | The organization's policies resolved for that identity |
| What the AI can reach | The skills and integrations permitted for that identity |
The three axes, never mixed
| Axis | What it records |
|---|---|
| Who asked | The person who triggered it, or the run that called it |
| How it was triggered | Manual, schedule, address, another agent, re-run |
| Which identity it ran under | The service account |
No client request can alter those values: they come from the session and from the organization's configuration, never from a header or a body field.
Permissions granted during a run
Each run receives a short-scoped authorization, valid only for that run, containing exactly what the published version declared.
Two properties:
- No step adds capability. What a step asks for is checked against what the run received; asking for more is refused.
- The authorization is issued at run time, not when the run is created — a run that sat in a queue does not start with an expired authorization.
When something goes wrong
| Symptom | Meaning |
|---|---|
| Failure because no service account is configured | The organization has no service account |
| Failure because the account is disabled | It exists and is inactive |
| Failure because of a divergent identity | The run was created under another identity |
| Failure because the authorization was revoked or expired | The run lost its authorization mid-work |
In every case, the run fails rather than continuing with less than it should have.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.