Organisations should govern identity as runtime infrastructure, not as a static user directory. That means aligning policy, entitlement control, and capacity planning to machine-speed activity so the programme reflects the actual actors consuming access and resources.
Identity governance must move from directory logic to runtime control
In the agentic enterprise, identity infrastructure stops being a back-office directory problem and becomes a live control plane. The governance question is not just who has an account, but which actors can acquire authority, when that authority exists, how far it reaches, and how quickly it can be constrained when behaviour changes.
That shift matters because machine-speed activity compresses the time available for approval, review, and revocation. The operating model has to account for delegation, task scope, and policy decisions that happen per action, not only at onboarding or periodic review.
What identity infrastructure has to govern in an agentic operating model
The practical scope includes policy, entitlements, credentials, approval paths, and the services that broker those decisions. It also includes the surrounding lifecycle: registration, ownership, rotation, offboarding, and exception handling. If those controls still assume a human employee model, they will miss the realities of transient agents, short-lived access, and delegated execution.
That is why governing identity infrastructure means treating access as something that is assigned, evaluated, and retired in motion. A useful benchmark is whether the organisation can explain, for any active actor, what it is allowed to do, which resource it is consuming, and what condition would immediately narrow or remove that access.
For agent-heavy environments, the strongest control patterns are least privilege, just-in-time access, and strong attribution of action to principal. NHIMG’s AI Agent Authorisation Guide is a useful reference for task-scoped access and per-action policy decisions, while the Agentic AI Identity Guide covers delegation, registration, and retirement as lifecycle controls rather than one-time setup steps.
What good governance looks like when agents are the consumers of access
Good governance starts with a clear ownership model. Every non-human actor should have an accountable owner, an explicit purpose, and a defined expiry or review point. Access should be expressed in terms of tasks and services, not broad role labels that silently grow over time.
It also requires capacity thinking. If agents can generate high volumes of requests, token exchanges, or resource consumption, identity governance must coordinate with platform limits and operational safeguards. Otherwise, entitlement policy may be correct on paper while still allowing excessive load, noisy failure, or broad blast radius in practice.
The right operational question is whether the control plane can keep pace with the actors it governs. Zero Trust for AI Agents is a useful companion here because it frames the problem as verify principal and request, remove standing privilege, and enforce policy per action. For architecture teams, Agent Identity Standards Tracker helps map the standards landscape that influences how those controls are implemented across systems.
Risk and Threat Considerations
Identity infrastructure becomes a high-value target when it governs autonomous or semi-autonomous actors, because a single weakness can create durable, high-speed access across many systems. The main risk is not only account takeover, but over-scoped authority, stale access, and weak revocation paths that let an agent continue acting after its business purpose has changed.
Failure mechanism: Standing privilege, weak delegation controls, or poor lifecycle management allow an agent to retain access longer or more broadly than intended, which increases blast radius and makes abuse harder to contain.
Impact: Organisations can lose control over what their agents may read, change, or trigger, and the result can be data exposure, unauthorized actions, or rapid lateral movement through connected services.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agentic identity governance must prevent unauthorized or excessive authority. |
| ASI02 — Tool Misuse | Identity controls must constrain what tools an agent can invoke under policy. | |
| ASI10 — Rogue Agents | Governance must detect and contain unmanaged or unsanctioned agents. | |
| Recommendation — Apply ASI03 to enforce bounded agent authority and revoke unsafe privilege paths. Apply ASI02 to scope tool access and block unauthorized action paths. Apply ASI10 to discover, quarantine, and retire rogue or unsanctioned agents. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | The question centers on continuous verification and removal of standing privilege. |
| Recommendation — Enforce zero trust by verifying each request and eliminating standing access. | ||
| NIST SP 800-53 Rev 5 | IA-9 — Identification and Authentication (Service Accounts and Devices) | Agentic infrastructure depends on service and machine authentication. |
| Recommendation — Use IA-9 to authenticate non-human actors and constrain their access paths. | ||
Practitioner Guidance
What to prioritise: Start by inventorying which identities can act autonomously, which ones depend on human credentials, and which ones can request privileged operations on behalf of someone else. That inventory should drive entitlement cleanup before any broader policy redesign.
What to verify: Check that every high-impact actor has a named owner, a bounded scope, and a revocation path that can be exercised quickly. If you cannot prove who can stop an actor and how fast, the control is not mature enough for agentic use.
Common mistake: Treating agent governance as a one-time provisioning exercise. In practice, the harder problem is keeping access aligned to actual behaviour as tools, prompts, workflows, and business tasks change.
Practitioner takeaway: Govern identity infrastructure as a live authority system, not as a static account inventory, because the quality of delegation, scope, and revocation determines whether agentic automation stays bounded or becomes uncontrolled access at scale.
Related resources from NHI Mgmt Group
- How should organisations evaluate agentic identity management for enterprise access control?
- How should organisations govern identity risk when using AI assistants like Microsoft 365 Copilot with enterprise data?
- How should organisations govern identity at enterprise scale when they connect hundreds of systems and tens of thousands of users and roles?
- What is the Agentic AI identity governance framework organisations should adopt?