They only test the user’s direct entitlements, not the broader actions the user can trigger through an agent. If the agent holds wider privileges in finance, ERP, or operations, the effective access is much larger than the review shows. That is why auditors need to examine delegated execution paths, not just the human account.
Why access reviews miss the real risk with AI agents
An access review usually asks whether a person should still have a named entitlement. That works for direct human use, but it can miss the larger blast radius created when that person can invoke an agent that acts with separate permissions. The real control question is not just who can log in, but what execution paths that account can trigger.
That distinction matters because an agent can become an amplification layer. The human may appear low-risk on paper, while the agent can reach finance workflows, ERP objects, operational tools, or API actions that the reviewer never sees in the user’s direct role list.
What the review is actually measuring
Traditional user access review processes are built around entitlements, roles, and direct access. They are good at spotting stale user accounts, obvious excess privileges, and missing approvals. They are much weaker at representing delegated execution, where a user can indirectly cause actions through a bot, assistant, workflow, or other agentic path.
This is why the unit of review needs to shift from “what can this user open?” to “what can this user cause?” If the agent has wider permissions than the person, the effective access boundary is the union of both, not the human account alone.
A practical way to think about it is that the user review shows ownership, but not operational reach. The agent may hold tokenized access, service credentials, workflow permissions, or privileged integrations that were provisioned for convenience and never show up as a normal user entitlement.
How delegated execution expands the attack and abuse surface
Once an agent can act on behalf of a user, the risk moves from simple over-entitlement to delegated authority abuse. That can create approval bypasses, hidden write access, and actions that look legitimate in logs because they were technically initiated from an approved account.
In practice, the dangerous gap is often between human intent and system effect. A reviewer sees a sales manager with ordinary access, but the agent attached to that user can create invoices, export data, modify records, or trigger downstream changes outside the manager’s direct job scope.
The control failure is especially sharp when the agent reuses broad organizational integrations. The person’s account may be clean, while the agent inherits broad application scopes, persistent tokens, or standing access that were never designed for per-action scrutiny.
Risk and Threat Considerations
AI agents can hide privilege concentration behind a benign-looking user identity, so the review outcome understates both exposure and abuse potential. The main failure mode is that the human account is certified, while the delegated path remains effectively unreviewed and can still move money, change records, or exfiltrate data.
Failure mechanism: Reviewers validate direct entitlements on the person, but do not inventory the agent’s separate scopes, tokens, or downstream tool access. That leaves a gap between approved user access and the higher-impact actions the agent can execute.
Impact: Excessive effective access persists even after a seemingly clean review, which increases fraud, data loss, operational error, and the chance that a compromised account can be used for broader business abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Directly addresses agent authority exceeding the human user's direct role. |
| Recommendation — Enforce per-action authorization for agent capabilities and limit delegated privilege. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The agent's broader permissions create effective overprivilege beyond the reviewed user account. |
| NHI-07 — Long-Lived Secrets | Delegated paths often rely on persistent tokens or credentials that escape user-centric review. | |
| Recommendation — Reduce agent scopes to the minimum needed and remove standing privilege. Rotate and shorten the lifetime of credentials that power agent actions. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | User reviews must measure the combined privilege actually exercised through delegated paths. |
| AU-6 — Audit Review, Analysis, and Reporting | The answer depends on reviewing logs that attribute actions through the agent path. | |
| Recommendation — Limit agent and integration permissions to the minimum required for each action. Correlate user and agent activity so reviewers can see the true action origin. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access reviews must cover direct and delegated access paths that affect the real control boundary. |
| Recommendation — Review access based on actual authority and system reach, not account labels alone. | ||
Practitioner Guidance
What to verify: Review the delegated execution graph, not just the user record. The key question is whether the agent can reach finance, ERP, admin, or production actions that the human entitlement review never enumerated.
Decision rule: If the human can trigger privileged agent actions, treat the combined path as the access object of record. If you cannot explain the agent’s authority, approval model, and audit trail in one review, the access is not yet governable.
What good looks like: The review packet should show the human entitlement, the agent scope, the tools or systems it can invoke, and the approval or policy gate for each meaningful action. Anything less leaves auditors looking at only half the control boundary.
Practitioner takeaway: The right review target is not the user in isolation, but the full set of actions that user can cause through agents, because that is where the real privilege lives.