The two identities answer different questions and must not be conflated. The agent label answers "which automation claimed to do this" and is useful, honest metadata, but it is a claim. The verified human answers "whose authority was this done under" and must be evidence.
The security property that makes the second half trustworthy is the absence of an input: if no request field, header, or tool parameter can carry the human identity, then it can only come from the authenticated credential, and a forged value has nowhere to land.
Dual attribution is what makes AI-driven audit trails legible to reviewers: a row can honestly say "the implementer agent made this change, under this person's session" instead of blending the two into a single unverifiable name.
Why not just log the user? Because when AI agents act, the person whose session it was is often not the one who chose the action. A single name either blames the person for every automated step or hides which automation acted. Two fields keep both facts, and keep the trustworthy one apart from the self-reported one. The distinction matters most after something goes wrong, when the first questions are what acted and on whose authority.