# AI Agents Are Getting Their Own Logins. Here's What That Means for Your Business

Block's new Buzz platform gives AI agents cryptographic identities and permissions. Here's what the shift means for SMBs evaluating AI tools.

Published: 2026-07-24
Updated: 2026-07-24
Author: Oshane Spencer
Category: AI-Powered Operations
Tags: AI agents, AI employees, Block, AI governance, small business AI
Canonical: https://ariostech.ca/ai-insights-hub/ai-agents-cryptographic-identity-block-buzz

---


## TL;DR

On July 21, 2026, Block, the payments company behind Square, Cash App, Afterpay, and Tidal, [launched a free, open-source workspace called Buzz](https://siliconangle.com/2026/07/21/block-launches-buzz-open-source-workspace-humans-ai-agents/). It lets human employees and AI agents share the same channels, the same codebase, and the same task list, each carrying its own verifiable identity. That detail, an identity and not just an instruction, is the part worth an SMB owner's attention, not the group-chat app itself.

## What did Block actually launch with Buzz?

Buzz is a [free, Apache 2.0-licensed workspace](https://www.tftc.io/buzz-block-nostr-ai-agent-workspace-launch), at buzz.xyz, that merges team chat, code hosting, and workflow automation into one tool. Employees and AI agents join the same workspace as members, each with an individual account, and Block has already replaced its own internal Slack and GitHub with it.

Desktop clients ship for macOS, Windows, and Linux; a mobile app is still in development. The software runs on [Nostr, a decentralized messaging protocol](https://www.techtimes.com/articles/321242/20260722/block-launches-buzz-open-source-workspace-where-ai-agents-sign-their-own-work.htm) better known in the Bitcoin and social media world than in enterprise software. That choice is deliberate: no single company's server has to hold the keys to who said what.

I've sat through enough vendor pitches that use "open" as a synonym for "trust us" to be skeptical by default. Buzz's claim is more specific than that. The code is inspectable on GitHub, and a team can run its own message relay instead of routing everything through Block's servers, which is a checkable claim, not a slogan.

It's the same test we walk clients through when we help them build an [AI-ready tech stack](/ai-insights-hub/how-to-build-an-ai-ready-tech-stack): can you see and modify what's running, or are you trusting a vendor's word for it.

## How does an AI agent get its own identity inside Buzz?

Each agent, whether it's running Claude Code, OpenAI's Codex, or [Block's own Goose framework](https://www.tftc.io/buzz-block-nostr-ai-agent-workspace-launch), gets a cryptographic keypair the moment it joins a workspace. A second signature ties that keypair back to the human who deployed it, so every message, code review, or automation the agent runs is traceable to both the agent and its owner.

Nothing about this requires a specific AI model. Buzz connects to agents through the [Agent Client Protocol](https://www.tftc.io/buzz-block-nostr-ai-agent-workspace-launch), an open standard, which is why Block markets it as model-agnostic rather than tied to one AI provider.

In practice, a manager can look at a channel and see exactly which actions a human took and which an agent took, and under whose authorization, without asking IT to pull server logs. I'd put this the way I explain multi-factor authentication to a client who thinks it's overkill: the value isn't stopping every bad outcome, it's making every outcome attributable to someone. Buzz applies that same logic to AI agents instead of just human logins.

## Why is Block ripping out its own Slack and GitHub for this?

Block is already running Buzz internally, in place of the Slack and GitHub instances its own engineering teams relied on. [Bradley Axen, Block's head of AI capabilities, put it plainly](https://siliconangle.com/2026/07/21/block-launches-buzz-open-source-workspace-humans-ai-agents/): every company, in his view, is going to need a shared place where humans and agents work side by side.

That's Block eating its own cooking, on a live production company, not shipping a demo and moving on. [Jack Dorsey, Block's co-founder, described Buzz](https://techcrunch.com/2026/07/21/jack-dorsey-is-taking-on-slack-with-buzz-a-group-chat-platform-for-teams-and-their-ai-agents/) as "model-agnostic, decentralized, self-sovereign, and open source," the same language he's used for a decade about Bitcoin and Nostr.

When I talk to SMB owners about vendor lock-in, this is the pattern I point them toward. Block isn't betting a startup's roadmap on its own internal workflow, it's proving the model on itself first. That's the bar I'd want any vendor to clear before I recommended their AI tool to a client.

It's also worth noticing what Buzz replaces: chat, code review, and workflow triggers, three of the same repetitive internal processes we list among the [most automatable processes in every company](/ai-insights-hub/the-7-most-automatable-processes). Block just automated its own back office before selling anyone else on doing the same.

## Is this actually new, or is "AI employee" doing a lot of marketing work?

Some of this is real infrastructure, and some of it is a nascent product still finding its feet. Buzz is [still in its early stages by its own admission](https://techcrunch.com/2026/07/21/jack-dorsey-is-taking-on-slack-with-buzz-a-group-chat-platform-for-teams-and-their-ai-agents/), has no mobile app yet, and lacks the approval gates most businesses would want before letting an agent run a workflow unsupervised.

Here's where I'd push back on most of this week's coverage. The headline nearly every outlet ran, that AI agents are becoming employees, oversells what a permissions system buys you.

A keypair and an audit trail don't make an agent trustworthy. They make its mistakes traceable after the fact, which is a different thing.

[PYMNTS reported](https://www.pymnts.com/news/artificial-intelligence/2026/dorseys-block-turns-ai-agents-into-real-employees/) that 31% of business leaders already think of AI as teammates, not tools, and nearly 1 in 4 say agents appear on a formal org chart. An identity system without human-reviewed approval gates, which Buzz doesn't have yet, is bookkeeping for accountability. It is not a substitute for deciding what an agent should be allowed to do in the first place.

That distinction matters more to a thirty-person accounting firm than to Block's own engineering org. A small business has far less room to absorb an agent's mistake, even one it can trace back afterward.

## So what does this mean for your business?

Buzz itself likely isn't a tool most SMBs will adopt directly. It's built for engineering teams, not a receptionist or a scheduler. The standard it sets is what matters: any AI agent doing real work for your business should carry its own identifiable account, clear permissions, and a traceable line back to the accountable human.

That standard is a concrete filter for evaluating any AI vendor, including the [AI-powered tools](/services/ai-powered-solutions) we build. Does each agent have its own account, rather than a shared login or API key? It's the same identity-permissions-accountability structure at the center of our own [AI Operations Blueprint](/ai-insights-hub/the-ai-operations-blueprint).

Can you see exactly what it did and under whose authorization, without waiting on IT to pull the logs? If a vendor can't answer that plainly, that itself is the answer.

For a small business, that filter is what lets you extend an agent's responsibility. A dental practice that can prove which agent sent which no-show reminder, and to whom, can hand that agent the entire follow-up queue instead of reviewing every message before it goes out. That's the difference between an agent that saves a few minutes and one that runs a whole process end to end, adding capacity without adding a person to run it.

It also changes what a mistake costs you. A reminder sent to the wrong customer, or a workflow triggered on bad data, is expensive to fix and worse for trust when nobody can say which system did it or why. An agent with its own identity and a visible trail turns "something went wrong somewhere" into a specific, fixable fact: which agent, at what time, approved by whom.

I've sat with clients staring at "the AI made a mistake" as a dead end, because nobody could say which automation ran or who had approved it. That's not an AI problem. It's a missing paper trail, and it's exactly the gap identity-and-permissions thinking closes, at Block's scale or a ten-person shop's.

Once that trail exists, you stop needing a person to check every single agent action before it happens, because the accountability is verifiable afterward instead. That's what saves time at scale: less babysitting each action, not less work getting done. It's also the bar we hold our own agent work to at Arios, including [Perpetua](https://useperpetua.com), because an "AI employee" should mean one you can audit, not just one that never asks for a raise.

<Callout variant="tip" title="Want a second set of eyes on what your AI tools can actually reach?">
  That's exactly the kind of gap we look for in a free AI Opportunity Call, before anything more
  formal. [Book a free consultation](/contact).
</Callout>

## FAQs

### Is Buzz available for small businesses to use today?

Yes, technically. It's free and open source at buzz.xyz. Treat that as a "not yet" in practice: Block itself describes it as early-stage, without a mobile app or the workflow approval gates most businesses would want before trusting an agent with real tasks unsupervised.

### Do I need to understand Nostr or cryptography to benefit from this trend?

No. The detail worth knowing is the outcome, not the protocol. Any AI tool worth adopting should let you see which agent did what and under whose authorization, so ask vendors that question directly rather than researching the protocol yourself.

### Does this replace tools like Slack or Microsoft Teams for most businesses?

Not yet, and maybe not soon. Block is running Buzz internally as an engineering tool, and it isn't ready for most teams to switch over wholesale, so treat this as a signal about where agent identity is headed rather than a ready swap for your current stack.

### What should I do about this if I'm not a software company?

Start asking any AI vendor, including for tools you already use, whether each agent has its own account and audit trail rather than a shared login. That single question tells you whether you can trace a mistake back to its source before you ever have one.
