Join our Newsletter — 33% off our NHI Course

Unmanaged agent

An AI agent or AI-enabled service that operates outside the organisation’s identity and access control mechanisms, such as IdP, PAM, or secrets management. When an agent is unmanaged, it cannot be reliably inventoried, reviewed, or continuously governed as part of the identity estate.

What Makes an Agent “Unmanaged”

An unmanaged agent sits outside the organisation’s control plane, so it cannot be consistently tied to an owner, policy, approval flow, or inventory record. That makes it fundamentally different from a sanctioned agent that has defined identity, scope, and oversight.

The practical distinction is not whether the agent is “AI” in the abstract, but whether the organisation can see it, classify it, and govern its access. If those basics are missing, the agent becomes an opaque actor rather than a managed part of the estate.

Why Unmanaged Agents Are a Governance Problem

Unmanaged agents break the assumptions behind identity governance because access decisions, review cycles, and offboarding controls no longer apply reliably. They may continue to operate after a project ends, a contractor leaves, or a prototype is copied into production without review.

That creates drift between what teams believe exists and what is actually active. A Shadow AI and AI Agent Discovery Guide is useful here because unmanaged agents are often discovered only after correlating OAuth grants, API keys, cloud footprints, endpoint signals, and other traces that reveal hidden usage.

It also means governance is no longer just about the agent itself, but about the trust chain around it. The agent may be using credentials, tokens, or delegated access that were never approved for that use case, so the real issue becomes control of authority rather than model capability alone.

How Unmanaged Agents Differ From Managed Ones

A managed agent is registered, assigned an owner, scoped to a purpose, and subject to policy and review. An unmanaged agent lacks at least one of those anchors, which is why it tends to fall outside routine security operations.

This difference is especially important when the agent acts on behalf of a person, team, or workflow. Without lifecycle control, the organisation cannot confidently answer basic questions about who approved it, what it can do, or when it should be removed.

That is why identity-centric guidance for agents matters. Agentic AI Identity Guide explains the lifecycle pieces that unmanaged agents typically lack, including registration, ownership, delegation, and retirement.

Why the Term Matters in Practice

“Unmanaged” is not just an administrative label, it is a security condition. Once an agent is outside identity and access controls, it becomes harder to restrict, harder to audit, and harder to retire cleanly.

That is why unmanaged agents often appear alongside broader shadow-technology problems. They may start as productivity experiments and later acquire real access, data reach, and operational dependence before anyone has formally accepted the risk.

When agent behaviour, access scope, and operational ownership are all unclear, organisations need visibility into both the agent’s permissions and the business process it supports. AI Agent Observability, Audit and Incident Response Guide helps frame the monitoring side of that problem, especially where attribution and revocation become part of the response.

Where Unmanaged Agents Show Up

Unmanaged agents commonly emerge in low-friction environments such as browser automation, coding assistants, internal productivity tools, and workflow connectors. They may also appear when staff experiment with third-party services that quietly inherit permissions from existing accounts.

That is why discovery and governance need to cover the surrounding ecosystem, not only the agent runtime. A useful reference point is the Agent Identity Standards Tracker, which shows how identity and delegation patterns are evolving across standards, protocols, and implementation approaches.

In practice, the unmanaged state is often temporary at first, then becomes tolerated, then becomes embedded. Once that happens, the organisation may have built a de facto agent estate without the controls normally expected for any other privileged software actor.

Risk and Threat Considerations

Unmanaged agents create exposure because they can retain access, proliferate through copying, and operate without review even after the original business need has changed. They are also attractive to attackers when hidden permissions, stale tokens, or weak ownership let an adversary reuse the agent as a trusted foothold.

Failure mechanism: The agent sits outside the approved identity and access lifecycle, so no reliable process exists to inventory it, recertify it, or revoke its access when risk changes.

Impact: That can lead to unauthorized actions, credential abuse, silent data access, and persistent shadow automation that survives longer than the intended use case.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 define the specific risk controls and attack patterns relevant to this term.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Unmanaged agents often persist after their intended lifecycle ends.
NHI-05 — Overprivileged NHI Unmanaged agents frequently carry access beyond their intended scope.
NHI-07 — Long-Lived Secrets Unmanaged agents often depend on secrets that outlive governance review.
Recommendation — Remove unused agent access promptly and revoke its credentials when ownership or purpose ends. Restrict agent privileges to the minimum scope needed for each approved task. Rotate and expire agent secrets so hidden automation cannot retain durable access.
OWASP Agentic AI Top 10 ASI03 — Identity & Privilege Abuse Unmanaged agents can operate with unreviewed authority and delegated access.
ASI10 — Rogue Agents An unmanaged agent is a classic rogue-agent condition outside oversight.
Recommendation — Constrain agent authority to prevent unapproved privilege use and delegated abuse. Detect and quarantine agents that operate without approved ownership, policy, or supervision.

Practitioner Guidance

Why practitioners should care: The unmanaged state is the warning sign that an agent has escaped normal governance, even if the underlying use case still looks useful. Treat it as a control gap, not a tooling preference.

Governance implication: Ownership, approved scope, and retirement criteria need to exist before the agent is allowed to operate, because after deployment those facts are much harder to reconstruct. The practical test is whether the agent can be clearly tied to an accountable owner and a revocation path.

Practitioner takeaway: If you cannot inventory an agent, you cannot confidently govern its authority, and if you cannot govern its authority, it is unmanaged by definition.