Agent-Owned Connections Need Builder Liability Labels
By wGrow Project Team ·
Microsoft’s Power Automate documentation, “Manage connectors in flows” and “Use run-only user connections,” and the Copilot Studio documentation, “Authentication for generative answers” and “Configure authentication for Power Automate flow actions,” draw the same line: a cloud flow or agent built against a maker-owned connection runs downstream actions through that stored connection’s identity, not the identity of whoever triggers the flow, unless the flow is explicitly configured for end-user authentication or its connection reference is set to run-only-user connections. Absent that configuration, whoever invokes the agent triggers actions under the builder’s stored connection, and the audit record can end up identifying the credential owner rather than the human requester. The system did exactly what it was told to do. That’s the problem. The audit log is still wrong for accountability purposes, because it answers “which credential fired the API call” when the question that actually matters is “who decided this should happen.”