By NHI Mgmt Group Editorial TeamBased on 1Password: “1Password Appoints Dr. Manoj Apte to Board of Directors” (April 7, 2026)

TL;DR: Identity programmes now have to govern runtime access use, not just static entitlements, across mixed actor types, as 1Password’s appointment of Dr. Manoj Apte to its board reflects a broader shift toward continuous access, delegated authority, and identity governance for humans, machine identities, and AI agents, according to 1Password.


At a glance

What this is: 1Password’s board appointment is a signal that identity security is being repositioned around continuous access governance for humans, machine identities, and AI agents.

Why it matters: IAM and NHI teams need to treat AI agents as delegated actors whose credentials, secrets, and runtime access require the same governance discipline as other non-human identities.

By the numbers:


Context

The article is about board-level signalling, but the governance issue underneath it is familiar: access models built for people do not fully describe how AI agents consume credentials, secrets, and delegated authority. Once agents act inside operational workflows, identity becomes a runtime control problem rather than a one-time provisioning problem.

For identity programmes, that shift matters because the control plane now spans human users, service identities, and agentic workflows at the same time. The article frames that transition as a Zero Trust-style change in access assumptions, where visibility and accountability have to extend to how access is used, not only whether it was granted.


Key questions

Q: How should teams govern AI agents that inherit human access rights?

A: Teams should treat inherited access as temporary and bounded to a specific task, owner, and expiry. The key is to govern the delegation chain, not just the agent itself, because the original human authority can persist far beyond the session that created it. If revocation cannot outrun execution, the governance model is already behind the risk.

Q: Why do shared credentials create risk in agentic workflows?

A: Shared credentials erase the line between requester and operator, so security teams cannot tell whether a Lambda invocation, database query, or EC2 session came from the right agent and task. That ambiguity weakens attribution, broadens blast radius, and makes revocation and investigation far harder than they should be.

Q: What breaks when identity governance is built only for human users?

A: Access review, joiner-mover-leaver processes, and periodic certification break down when the identity is a service account or autonomous agent. Those controls assume a visible human lifecycle and a stable review window. Machine identities and agents can outlive those assumptions, leaving access active after the programme believes it has been governed.

Q: What is the difference between delegated access and standing privilege in AI workflows?

A: Delegated access is meant to exist only for a specific purpose, time, and scope. Standing privilege persists beyond that purpose and can be reused in ways that are hard to justify or audit. For AI workflows, the practical distinction is whether the access disappears when the task ends or remains available for the next action.


Technical breakdown

Why continuous authorisation becomes the real control plane

Continuous authorisation means access is evaluated during use, not just at login or grant time. That matters when agents and automated workflows can invoke credentials repeatedly, combine tools, and act under delegated authority. In traditional IAM, entitlement review assumes access remains stable long enough to be certified. In agent-driven workflows, the interesting question is not whether access exists, but whether the current action still matches the delegated purpose. Practical implication: move governance closer to execution so that access use, not just access grant, is observable and auditable.

Practical implication: design controls that inspect runtime use, not only entitlement records.

Credentials, secrets, and machine identities in delegated workflows

The article points to a familiar NHI pattern: once a system can initiate work on behalf of a person, the value shifts from the user account to the secrets and machine identities that enable action. Those artefacts become the real enforcement point for privilege, session scope, and offboarding. If a workflow can reuse the same secret across tasks, the identity boundary becomes porous even when the human account is tightly governed. Practical implication: treat credential scope and lifetime as first-class governance objects for every delegated workflow.

Practical implication: inventory which secrets and machine identities each workflow can reach and how long they remain valid.

Zero Trust assumptions break when agents are the actor

Zero Trust was built on verifying each request, but agentic systems complicate who or what is making the request. An AI agent is not just another user; it can chain tools, select execution paths, and operate with delegated authority that is narrower than a person but broader than a single action. That creates a governance gap between human accountability and machine execution. Practical implication: align authorisation, logging, and review to the agent’s delegated purpose rather than to a human proxy account.

Practical implication: bind authorisation to the agent’s purpose and execution context, not to a reused human identity.


Threat narrative

Attacker objective: The objective is to exploit delegated access in a way that preserves operational reach while weakening accountability and control.

  1. Entry occurs when an agent or automated workflow receives delegated access to credentials, secrets, or machine identities needed to perform work.
  2. Escalation happens when that delegated access is broader than the task and can be reused across tools, sessions, or environments without fresh review.
  3. Impact follows when access use is no longer attributable to a clear actor or purpose, making misuse, overreach, or compromise harder to detect and contain.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity is moving from static entitlements to governed execution. That is the central implication of this board appointment. Access no longer describes only what a subject may receive at provisioning time; it increasingly describes how delegated authority is exercised across human, machine, and agentic workflows. The practitioner conclusion is that entitlement review alone is no longer the governing model.

Long-lived, person-centred access is the wrong default for agentic systems. Dr. Apte’s comments point to a shift away from centralized identity assumptions that were designed for durable human roles. When an agent can act ephemerally for a specific purpose, the governance question becomes whether the authority exists only for the task. The practitioner conclusion is that lifecycle controls must distinguish between person identity, machine identity, and delegated agent identity.

Identity blast radius is now a board-level risk variable. The more an organisation allows reusable credentials and broad delegated access inside automated workflows, the more a single identity compromise can spread across applications and environments. That is why visibility into access use matters as much as access grant. The practitioner conclusion is that identity governance now has to be judged by containment, not just compliance.

Zero Trust thinking is becoming an identity operating model for agents. The article uses the language of continuous access and accountability because the market is converging on a simple fact: agentic systems make trust conditional at runtime. That does not mean every agent is autonomous in the governance sense, but it does mean static policy snapshots are losing relevance. The practitioner conclusion is to re-evaluate identity control points around action, purpose, and traceability.

Delegated access without purpose binding creates governance debt. The strongest concept in this article is not AI novelty but delegated identity authority. When access is granted to support a workflow rather than a specific human, the control model must still answer who authorised it, what it may do, and when it expires. The practitioner conclusion is that purpose-bound delegation is now a core design requirement, not an edge case.

From our research library:

  • 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
  • Read next: Agentic AI Identity Guide

What this signals

Delegated identity authority: This article is really about who or what is authorised to act when work moves from a person to an AI-enabled workflow. Once that shift happens, the programme has to govern purpose-bound access and revocation, not just account lifecycle events.

Runtime access use becomes the control point. Access reviews that look only at granted entitlements will miss agentic misuse because the risky behaviour happens during execution. Identity teams should therefore prioritise auditability of credential use across tools, sessions, and automated workflows.

The gap between what an identity may access and what it should access is widening as organisations allow AI systems broader access than human employees in the same role, a pattern highlighted in NHI Mgmt Group’s research. That gap turns entitlement design into a containment problem rather than a compliance exercise.


For practitioners

  • Define delegated identity boundaries Separate human accounts, service identities, and agentic workflows in policy so each has a distinct purpose, scope, and expiry model.
  • Audit runtime access use Log what credentials, secrets, and machine identities are used during execution, not just which identities were granted access.
  • Shorten privilege lifetime for workflows Replace broad reusable access with narrowly scoped, ephemeral credentials that expire with the task or session.
  • Map accountability across agentic workflows Document who approves, who observes, and who can revoke access when an agent acts on behalf of a person or team.

Key takeaways

  • AI agents change identity governance because authority now has to be tracked during execution, not only at provisioning.
  • The practical risk is not just broader access, but weaker attribution and weaker containment when delegated workflows reuse credentials.
  • Teams need controls that separate human identity, machine identity, and delegated agent identity so that access can expire with purpose.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on delegated access that can exceed the task for humans, machine identities, and agents.
NHI-07 — Long-Lived SecretsThe article explicitly warns against long-lived access tied to people and reusable credentials.
NHI-10 — Human Use of NHIThe article addresses humans directing agents through shared credentials and delegated authority.
Recommendation — Scope delegated access narrowly and remove privileges that outlive the task or workflow. Shorten secret lifetime and tie credential validity to the smallest viable workflow window. Prevent humans from reusing NHI credentials directly when an agent or workflow should be separately governed.
NIST Zero Trust (SP 800-207)Continuous Verification — Continuous VerificationThe article frames identity security as continuous access governance rather than static trust.
Recommendation — Apply continuous verification to access decisions that occur inside runtime workflows.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about how permissions and authorisations must adapt to agentic and machine workflows.
Recommendation — Review authorisations for delegated workflows based on purpose, scope, and runtime use.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementThe risk pattern involves credentials and machine identities being reused across workflows and systems.
Recommendation — Map delegated credential abuse to credential access and lateral movement indicators in detection content.

Key terms

  • Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.
  • Continuous authorization: Continuous authorization is the practice of rechecking access as a session unfolds instead of trusting a single login decision. It matters for AI workflows because the request, context, retrieved data, and downstream action can all change between prompt and execution, making static approval too blunt.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Purpose-bound access: Purpose-bound access is permission limited to a defined task, dataset, or workflow, with revocation when that purpose ends. For AI systems, the control matters because broad reusable access creates unnecessary blast radius and blurs accountability across people, tokens, and connected systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org