Socure is gearing up to verify AI agents, not just humans — the right question isn't who the agent is, it's who clicked to authorize it
In an interview published August 16, 2026 by Biometric Update, Socure's chief product officer, Chung-Man Tam, describes a four-step chain of trust — the person's identity, delegated authority, the agent's identity and scope, and each action's compliance with that scope — and predicts that "verifying agents will become as routine as verifying humans." Socure measured a rise of more than 8,000% in AI-driven fraud attacks across its network in 2025. What the interview never says is how that "authorization" translates concretely, action by action, at the exact moment it matters.
On August 16, 2026, Biometric Update published a long interview with Chung-Man Tam, chief product officer at Socure — the identity-verification platform that closed the second quarter of 2026 at $364 million in annual recurring revenue, up 63% year-over-year, and that serves more than 3,000 clients across more than 190 countries, including 18 of the 20 largest US banks. Tam describes a structural shift, not a fad: the historical digital-identity question — "is this person real?" — is giving way to a broader one — "who or what is on the other side, and with what authority?" Autonomous agents are already opening accounts, moving money, and making decisions on behalf of employees and customers, and identity infrastructure built for humans doesn't yet know how to answer that reality. Socure measured a rise of more than 8,000% in AI-driven fraud attacks on its network in 2025 — a figure Tam attributes to a "force multiplier": a human fraudster has physical limits on how many accounts they can open in a day, an autonomous agent has none. The model Socure proposes is a four-link chain of trust: verify the person, verify they delegated their authority, verify the identity and exact scope of the agent they delegated it to, then verify that every action by that agent stays within that scope. "Today, we verify the person and trust the session," Tam sums up. "Tomorrow, we'll need to verify the person, verify they delegated their authority, verify the agent's identity and scope, then verify the action taken stays within that scope." Socure is betting on extending its existing identity graphs rather than building a separate trust stack for agents: "when we verify an agent's legitimacy, it benefits every organization on the network," he says.
This is serious infrastructure, built for a real problem — but not necessarily everyone's problem. On a platform that receives agents belonging to thousands of third-party organizations, there's no way to know upfront whether an agent presenting itself is really who it claims to be: that's exactly the ground where Socure's cryptographic agent identity, delegated authority, and network-wide behavioral monitoring make sense, and where AppH probably wouldn't have a better answer. But that's not AppH's ground. Every AppH account runs a single agent, written and operated by AppH end to end — there's never a question of "which third-party agent just connected," because there's only ever one, and it's already known who it is. So the question that really matters is never "is this agent authentically who it claims to be" — that's already settled by design — but "did a human actually click to approve this specific action before it went out." That's the logic behind AppH's Automations approval flow: an agent proposes a quote, a reminder, an accounting consolidation — and nothing goes out until the owner has clicked, action by action, logged in an append-only audit trail deployed since this summer across Automations, Fleet Maintenance, and Appointments. No encrypted authority token, no network trust graph — a button, and a human who has to press it. Simpler than what Socure is building, and for the specific problem AppH has, more than sufficient.
For AppH
- Socure's interview validates, from a completely independent angle, the instinct AppH has defended from the start: agent actions with real consequences need a real trust mechanism, not just technical capability. An 8,000% rise in AI-driven attacks in one year isn't an anecdote, it's a signal the whole industry is taking seriously — in a different direction from ours, but for the same underlying reason.
- The four-step trust chain Tam describes — person, delegated authority, agent identity, action compliance — shows up almost as-is in AppH's architecture, just solved differently: a single agent per account settles the first two links by design, and the owner's approval click on every action with real consequence settles the fourth in real time, not after the fact.
Against / the honest limit
- If AppH ever opens its platform to third-party agents — an integrations marketplace, agents built by other vendors — the problem Socure solves becomes AppH's problem too, and a simple approval button won't be enough anymore: it will be necessary to know, cryptographically, which third-party agent is acting and with what authority, before even asking the approval question. That day, AppH's current architecture won't suffice as-is.
- AppH's audit log traces what an agent did and when a human approved it — but it has nothing like Socure's network intelligence, comparing fraud signals across thousands of organizations. AppH only sees its own clients; a fraudster already flagged elsewhere by Socure's network would, for now, stay invisible to AppH until they've acted once against an AppH client.
There's a real temptation, reading this interview, to conclude Socure is building a component every AI agent vendor will soon need — and for part of the market, the multi-tenant platforms that host agents from multiple, unvetted origins, that's probably true: they can't settle for a button, they need to know cryptographically who's acting before even asking who authorizes it. But generalizing that need to any product that touches AI agents would be a category error, and an SMB buying an AppH agent for its bookkeeping doesn't have that problem: it has a single agent, operated by a single vendor, and the real question was never "who is this agent" but "who said yes before it acted." Socure is inventing identity infrastructure for a world where authority is delegated across chains of agents unknown to each other; AppH answers a narrower, more verifiable question: with us, there has never been an agent action without a human click, not because we promised it in a press release, but because that's literally what the product does, every time, with no exception that could be switched off. Agent identity depth is a real subject for the market Socure serves; it's never a substitute for the question of who pressed the button.
Reviewed by an AppH human