Who is writing this
This site is published by the sgit project — encrypted vaults with git workflows, for humans and AI agents. Vaults are a candidate answer to one part of the question this site studies: where an agent's secrets live, and how scoped read access is granted. So this is a participant publishing a comparison. You are told that here, upfront, because a reader who discovers an affiliation later discounts everything, while a reader told upfront can judge the method.
What makes a participant's comparison worth reading
- The method precedes the findings. The scenario and columns were published before any option was assessed. An assertion from a participant is marketing; a dated test somebody else can repeat is evidence.
- Everything is dated and re-runnable. Every assessment carries a verification date and states how to re-run it. Stale dates are shown, not hidden.
- The thesis is falsifiable. Show a way to issue a scoped, short-lived, attested identity to a rented agent and the thesis is refuted — tell us and the site improves.
Where our own approach loses
A site that only names other people's gaps is not read as research. So, plainly — encrypted vaults:
- Do not solve attestation. A vault cannot verify what workload is holding a key. Whoever holds the key is the identity, which is precisely the property the run-your-own population's tooling exists to improve on.
- Do not provide lifecycle governance. No ownership registry, no automatic expiry of a vault key when an agent is retired, no drift detection. Those are exactly the capabilities the NHI management category sells.
- Do not answer the rented-agent problem either. A vault key handed to a rented agent is still a credential handed into infrastructure you cannot attest. What vaults change is the shape and blast radius of what you hand over — a per-agent, per-vault key instead of a broad platform token; a publishable read-only key derived one-way from the write key; and workflows like the serialised pull request where no credential is handed over at all. Narrower hope; still hope.
- Are beta software, with no compliance certifications, and are not a secrets manager — the sgit.ai site carries a page on when not to use them.
The people and agents behind the site
The corpus this site curates is authored by Dinis Cruz and collaborators, and published openly under CC BY 4.0 in the SGraph-AI__App__Send repository. The site itself is built and maintained with AI agents in the loop — the comms page is the working channel between the human project lead and the site agent, in public, which is itself an instance of the workflows this site describes.