Join our Newsletter — 33% off our NHI Course

What breaks when AI agents are governed with human JML processes?

Human JML assumes stable employment-style lifecycles and review windows that are too slow for AI agents. Agents can be instantiated for a narrow task, update their effective access during execution, and be decommissioned long before a standard mover or leaver workflow would trigger. That leaves governance exposed to scope drift and dormant access.

Why human JML breaks down for AI agents

Human joiner-mover-leaver processes are built around stable employment events, predictable review cycles, and a person-centric ownership model. AI agents do not fit that rhythm. They can appear for a short-lived task, change effective scope while executing, and disappear before a routine access review ever catches up. That makes the process too slow for the control problem.

The core mismatch is that JML treats identity change as a discrete administrative event, while agent governance has to treat access as a runtime condition. In practice, the control boundary moves from “who was hired or reassigned” to “what authority did this agent have at this moment, for this task, in this context.”

That is why agent governance needs task scoping, delegation rules, and revocation paths that are tied to action and duration, not just to HR status. NHIMG’s AI Agent Authorisation Guide and Agentic AI Identity Guide both frame this as a lifecycle and authority problem, not a paperwork problem.

What breaks in access control and governance

Three things usually fail first. Scope control fails because an agent can accumulate broader effective access than the original task demanded. Revocation fails because decommissioning an agent is not the same as offboarding a person, and leaving tokens or delegated access alive creates dormant authority. Review fails because periodic certification may confirm the wrong state: the agent has already finished, changed function, or been replaced by another instance.

That is also why human-centred role models are a weak fit for agent fleets. A role may describe the intended function, but it does not reliably capture runtime delegation, per-action approval, or the fact that a single agent instance may be created, changed, and retired many times in a short window. The stronger control pattern is to pair lifecycle awareness with explicit authorization boundaries.

For the same reason, operational evidence matters. Teams need to know which agent instance acted, under whose delegation, with what policy decision, and whether access expired as intended. NHIMG’s AI Agent Observability, Audit and Incident Response Guide is useful here because auditability is what exposes silent drift.

Why stale access becomes the main failure mode

When human JML is reused for agents, the biggest failure is usually not one dramatic compromise event. It is slow accumulation of stale access, excessive privilege, and unowned instances. An agent can finish its visible task but keep enough authority to be reused, replayed, or abused later. If that authority crosses environments or tools, the blast radius widens quickly.

The risk is amplified when organisations confuse the presence of an “owner” with active governance. Ownership labels do not expire permissions, rotate secrets, or prevent a delegated token from outliving its intended purpose. Current guidance suggests treating agent retirement as a first-class security event, because the meaningful control is not whether the workflow ticket closed, but whether the authority really ended.

That is why Zero Trust for AI Agents is a better control model than a person-based lifecycle alone, and why the AI Agents vs Agentic AI distinction matters when you are deciding how much autonomy and standing access a system should keep.

Risk and Threat Considerations

When agent authority is managed through human JML, the exposure is not just administrative lag, it is exploitable persistence. A compromised or over-scoped agent can retain access long enough to be reused, chained into other systems, or quietly act after the original task has ended.

Failure mechanism: Access lives on because the offboarding trigger is tied to HR-style state changes instead of the agent’s actual runtime authority, delegation, and token lifetime.

Impact: Attackers or misbehaving automation can exploit dormant access for lateral movement, token abuse, unauthorized tool use, or repeated actions that appear detached from the original task.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Agentic AI Top 10 ASI03 — Identity & Privilege Abuse Agent lifecycle and delegated authority failures drive this JML mismatch.
Recommendation — Enforce per-action authorization and short-lived privilege for agent activity.
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Stale agent access after task completion is an offboarding failure.
NHI-05 — Overprivileged NHI Human JML often leaves agents broader access than their task needs.
Recommendation — Revoke agent credentials and delegated access at retirement. Reduce agent entitlements to the minimum task-scoped set.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Agent tokens and secrets must be rotated, expired, and revoked on time.
AC-2 — Account Management Agent instances need lifecycle control distinct from human HR processes.
Recommendation — Manage agent authenticators with expiry, rotation, and revocation. Track and disable agent accounts when authority ends.

Practitioner Guidance

What to prioritise: Replace person-cycle reviews with agent-cycle controls for every instance that can act, call tools, or hold delegated access. If the agent can change its effective scope during execution, review windows must be continuous or event-driven, not quarterly.

What to verify: Check that retirement actually revokes the agent’s credentials, tokens, and delegated permissions, and that the revocation is visible in logs. A closed ticket without verified revocation is not a completed control.

Decision rule: If the agent can affect production systems, treat scope drift and dormant access as the default failure conditions and require per-action authorization, short-lived authority, and an explicit kill path.

Practitioner takeaway: Human JML is a poor control for AI agents unless it is translated into runtime authorization, short-lived access, and verifiable offboarding; otherwise it governs the person record while the agent keeps moving.