PT EN

Your AI agent needs its own identity

Why an AI agent needs its own phone, e-mail and WhatsApp, like a secretary, and what is still missing for it to act with your approval

7 min read

Your AI agent needs its own identity

SpaceXAI’s Grok Bot now has its own e-mail. The official announcement says the bot can use that e-mail to sign up for services, contact businesses for you, or schedule time with someone. In the announcement, the address is on mail.grokbot.com.

I found this step really interesting, because it points to a kind of autonomy you still barely see. The agent stops signing into your account and gets its own ways to be reached. The e-mail stops being a login to your inbox and becomes its address.

This changes the agent’s role. It stops being a tool you open when you need it and becomes someone who can be reached. A company replies to it. A service signs up the address that belongs to it, and you step in when the decision is yours.

The old path is to lend your identity. The agent uses your e-mail, your WhatsApp and your contacts, and what it does goes out in your name. That works for a one-off task. It does not work for the day to day, because your life gets mixed with its work.

The path I want is the opposite. The agent has its own ways to talk to the world, and you stay the owner of your accounts. The split is what makes the autonomy real. Without it, the agent only pretends to be you.

Like a secretary

The central point is identity. The agent needs its own phone, its own e-mail and its own WhatsApp, so it can work like a secretary.

The agent with its own phone, its own mail and its own message channel

You do not hand your phone to your secretary so she can reply in your place. She has her own phone, and people know who they are talking to. The same goes for e-mail and WhatsApp. Each channel is hers, and yours stays yours.

Today, the common path is the opposite. The agent signs in as you: into your e-mail, your WhatsApp, your contacts. That can get a task done, but it mixes your life with the agent’s work. What it does goes out in your name.

With its own contact, the conversation is its own. It can talk to a company, receive a reply, and bring you only what needs your decision. You approve what matters and get on with your life.

A real secretary does not live inside your account. She has her own phone, her own e-mail and her own way of introducing herself. The agent needs that in order to work without taking your place.

Her name is Claudia Romano

Claudia Romano
Claudia Romano

My agent has a first name and a last name. Her name is Claudia Romano. She has a phone, an e-mail with her own name, and a WhatsApp with a profile photo. People who talk to her think they are talking to my secretary.

The name makes the contact real for the other side. It is not an ownerless login in the conversation. It is Claudia, with a phone, an e-mail and a photo on the profile. The person on the other side knows who they are talking to, and I know that conversation is not mine.

I do not hand over my WhatsApp for that. The profile is hers, the photo is hers, and the reply goes out in her name. When I need to decide, she brings me the point. The rest of the conversation stays on her contact.

This is what a secretary has always had, and what an agent almost never has. A name people use, a phone that is hers, and an e-mail that carries her name. Without that, the agent is still you on another login.

Claudia already takes part in WhatsApp groups with suppliers. She interacts, takes actions, gathers information and bridges one party to the other, like an administrative assistant working with the accounting firm.

What I have already seen work

My Grok Bot already has its own contacts. It talks to businesses and handles tasks for me, always with my approval. I will not go into how that was set up. What matters is the role: it acts as itself, and I confirm what goes out.

With the agent acting as itself, you can organize your life and get time back. Asking for a refund is one example of the kind of task: it talks to the company, and you approve what matters. The conversation with the company does not have to take over your WhatsApp.

The limit is still your approval. It runs the contact, gathers the reply and shows you what needs a yes. What goes out in your name, or what touches your money, waits for you.

A card and an account, with your yes

The next step is for the agent to have its own card and its own bank account, both with human confirmation.

The agent presents a payment and a human hand approves it

It is not the agent spending on its own. It prepares the payment, and you say yes first. The card and the account are its own, and the amount leaves only after your confirmation.

Link, from Stripe, already does the confirmation. The person authorizes the agent on their Link wallet. The agent creates a spend request, with an amount and context, and the person approves each request on the web or in the app. Only then does Link hand over a one-time card, or a payment token, for that purchase. The agent never sees the real card number. The credential stays backed by the cards and bank accounts already in the person’s wallet.

Today, each request goes through the person’s review before the agent receives the credential. Stripe says it plans, later, to allow spending limits and cases where the agent can act without a fresh approval. I prefer an explicit yes on what matters.

What I want, beyond what Link already does, is for the account to belong to the agent. Its card, its account, and my confirmation before any amount leaves. Link confirms a charge on top of what is already yours. The step after that is the agent having its own way to pay, still with your yes.

My bottleneck, today, is simpler, and very Brazilian. The bot still cannot schedule boletos for me to approve. A boleto is a Brazilian bank payment slip, and it is the same kind of payment: the agent prepares it, I approve it. Until that exists, a large part of financial life stays in my hands.

Access that is its own, not your login

The same applies to other doors. For programmers, the agent needs access to code repositories. Much of this already exists. The usual use is the agent logged in as you, with your account and your permissions.

I want the other model. The agent comes in with its own identity, you delegate what it can see and do, and you approve what is sensitive. The history makes clear what was the agent and what was you.

While the access is your login, every commit and every read goes out as if it were yours. With its own identity, you choose the reach and confirm what must not go out alone. The repository treats the agent as someone, not as a session of yours.

Products will have to open the door

For the bot to work with more autonomy, products will have to adapt. Three things become necessary: an identity for the agent, delegated access with approval, and APIs instead of screens built only for a human to click.

Product doors opening for the agent

While the only path is the screen, the agent pretends to be you. It clicks where you would click, with your session open. That breaks as soon as the product asks for a confirmation only the account owner should see, or when the screen changes and the click no longer finds the place.

When there is a door made for it, with permission and with your yes, autonomy stops being a borrowed login. It introduces itself with its own identity. You delegate what it can do. What is sensitive comes back for your approval.

Products that only have a screen will keep pushing the agent into your account. The ones that offer an identity, delegated access and an API will let the secretary work. It organizes, it talks, it prepares, and you decide.