By NHI Mgmt Group Editorial TeamBased on Visiq Labs: “Monitoring isn’t enforcement” (June 12, 2026)

TL;DR: Agent-security stacks often stop at traces, which only document harm after an agent has exfiltrated data or triggered a destructive API call, according to Visiq Labs; the real control is an enforcement layer in the request path that can deny risky actions and fail closed. Observability without enforcement is only retrospective evidence.


At a glance

What this is: This analysis says agent security is too often built around traces and dashboards, while the decisive control is request-path enforcement that can block harmful actions before they execute.

Why it matters: For IAM, NHI, and agentic AI teams, the key issue is whether policy is applied at the moment of action, because logs alone cannot stop privilege abuse or destructive tool use.


Context

Agent security is often described through monitoring, but monitoring alone only shows what an agent already did. In practice, the governance gap is that many control designs still treat agent behaviour as something to investigate after the fact rather than something to constrain before execution. That distinction matters because agentic systems can act quickly and across multiple tools, so retrospective visibility does not reliably prevent damage.

The article’s core argument is that policy enforcement belongs in the request path, where the system can evaluate the action, the context, and the policy state before a call is allowed through. That creates a direct intersection with NHI governance because agents are acting through credentials, permissions, and delegated access, not through simple logging events. When the control only records traces, it is tracking the incident rather than governing the identity performing it.


Key questions

Q: What breaks when agent security only produces traces instead of blocking actions?

A: The control breaks at the decision point. Traces tell you that an agent already acted, but they do not prevent exfiltration, deletion, or API misuse. If the security stack cannot deny the request inline, it is functioning as telemetry, not enforcement, and the incident outcome is already determined by the time humans see it.

Q: Why do agentic systems need policy enforcement in the request path?

A: Because agents can move from intent to action faster than human review can respond. Request-path enforcement lets the system evaluate identity, context, and authorization before execution, which is the only point where the outcome can still change. Without that placement, policy becomes retrospective governance rather than active control.

Q: How can security teams tell whether agent access is actually under control?

A: Look for evidence that the team can trace every tool call, secret use, and cross-system action back to a named owner and a valid approval path. If an agent can reach messaging, browser, and infrastructure tools without a revocation chain, access is not truly governed. Control exists only when the runtime can be stopped as fast as it can act.

Q: How should organisations govern agent-to-agent delegation?

A: They should treat delegation as a formal governance boundary, not just an integration pattern. That means defining what data can move between agents, how inherited permissions are recorded, and when delegated actions require review. Without that, one agent can extend another's access in ways the original control model never saw.


Technical breakdown

Why traces are not an enforcement control

A trace is an observation record. It can show that an agent called a tool, accessed data, or attempted an action, but it cannot change the outcome once the action has already been executed. In agent systems, that means dashboards, logs, and audit trails are necessary for investigation but structurally weak as the primary safety control. The policy question is not whether the behaviour is visible after the fact. It is whether the system can evaluate risk before the call leaves the request path. Practical controls must therefore sit where the action is decided, not where it is reported.

Practical implication: treat trace output as evidence, not as a control boundary.

Request-path policy evaluation for agent actions

Request-path enforcement means the system checks policy, context, and authorization state at the moment an agent asks to act. For agentic AI and NHI governance, that usually means evaluating the task, the target resource, the tool scope, and whether the action matches the granted authority. This is closer to access control than telemetry. The important architectural difference is that the enforcement decision can return allow or deny before the action is executed, which is what changes incident outcomes. Latency, policy expressiveness, and fail-closed behaviour become the design constraints that determine whether the control is usable.

Practical implication: place policy decisions inline with tool invocation, not in a downstream analytics pipeline.

Why fail closed matters when policy cannot decide

Fail closed is the safety posture that defaults to deny when the system cannot confidently evaluate a request. That matters because agent environments often face incomplete context, transient tool state, or ambiguous policy rules. If the product responds to uncertainty with an alert instead of a block, it has preserved observability but lost enforcement. In operational terms, the system is still depending on humans to intervene after risk has already crossed the boundary. For agent security, that is a governance failure because the control’s job is to prevent unauthorized execution, not simply narrate it.

Practical implication: require deny-by-default behaviour whenever policy evaluation is incomplete or ambiguous.


Threat narrative

Attacker objective: The objective is to make the agent perform harmful actions through legitimate-looking tool use before any enforcement layer stops it.

  1. Entry begins when an agent receives a valid task and attempts to act through delegated tools or credentials in the request path.
  2. Escalation occurs if the system only records the attempt instead of blocking it, allowing the action to reach protected data or operational APIs.
  3. Impact follows when the agent exfiltrates records or triggers destructive commands, leaving telemetry as evidence rather than prevention.
  • reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
  • CI/CD pipeline exploitation case study: Credentials in an exposed .git/config let a researcher edit a Bitbucket pipeline so it planted their SSH key on the server. No victim was named.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agent security without inline enforcement is operational theatre: if the control only records what happened, the system has already surrendered the decision point. That makes the security story dependent on after-the-fact investigation rather than prevention. For NHI and agentic AI programmes, the real boundary is not the log stream but the authorization decision that occurs before a tool call is executed. Practitioners should treat monitoring as support for control, not as control itself.

Request-path governance is the right model for delegated machine action: agents do not need a broader security vocabulary, they need a tighter decision boundary around what they are allowed to do in real time. That is where identity, context, and policy meet. Once agents can acquire and spend permissions within the same session, the governance problem shifts from review to decisioning. The practitioner implication is clear: control authority must exist at execution time, not after the fact.

Single-digit latency is only meaningful if denial is real: low-latency policy engines matter because agentic systems can move faster than human review. But speed alone is not the point. A fast alert pipeline still leaves the destructive action intact, while a fast deny changes the outcome. That makes outcome-based enforcement the defining criterion for agent security maturity, especially where agents act through delegated NHI-style credentials or scoped tool permissions.

Observability should be the evidence layer, not the safety layer: traces, logs, and audits are necessary for forensics, accountability, and tuning policy, but they do not contain harm by themselves. The named concept here is enforcement gap: the distance between seeing an agent do something and stopping it from doing it. Teams should measure their exposure by whether a bad request is blocked inline, not by how quickly it is detected afterward.

Agent identity controls now sit inside the action path: once software actors can choose actions and invoke tools independently, traditional post-event IAM thinking is too slow. That does not make identity less important, it makes it more operational. The programme question becomes whether the agent’s authority is continuously checked against policy at the moment of use. Practitioners should align agent governance with real-time authorization, not dashboard visibility.

What this signals

Enforcement gap: the central risk in agent security is the distance between observing behaviour and stopping it. As agentic systems gain the ability to choose actions and invoke tools, security programmes need inline decisioning that can deny harmful requests before execution. Teams should measure control maturity by whether policy changes the outcome, not whether telemetry captures the event.

For identity and NHI governance, the practical shift is from post-event review to pre-execution authorization. That changes how privilege, delegation, and tool scope are managed across autonomous workflows. If an agent can still reach a sensitive API after policy uncertainty, the programme has preserved visibility but not control.


For practitioners

  • Implement inline allow/deny controls Put policy evaluation in the request path so an agent call is denied before data access or tool execution can occur.
  • Require fail-closed behaviour Configure the control plane so ambiguous context, missing policy state, or evaluation errors default to denial rather than alert-only handling.
  • Separate observability from enforcement Use traces and logs for audit, but verify that they are not the only mechanism standing between an agent and a sensitive API call.
  • Test the no-verdict path Simulate cases where policy cannot decide and confirm the system blocks the action instead of allowing it to proceed.

Key takeaways

  • Agent security fails when organisations confuse telemetry with control, because traces only describe harmful actions after they happen.
  • The most important control is inline enforcement that can evaluate agent context and deny risky tool use before execution.
  • A system is only governing agent behaviour if a bad request is blocked when policy cannot confidently approve it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on whether agent actions are authorized at the moment of use.
NHI-05 — Overprivileged NHIThe post focuses on delegated agent authority that can become effective privilege abuse.
Recommendation — Enforce NHI-04 by validating agent requests inline before any tool call or data access executes. Apply NHI-05 to limit each agent to the minimum scope needed for the current task.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgent security risk here is the misuse of delegated identity and permissions at execution time.
Recommendation — Use ASI03 to constrain agent privilege checks inside the action path, not after the fact.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsInline enforcement is fundamentally about whether permissions are applied before action execution.
Recommendation — Apply PR.AA-05 to deny agent actions that exceed current entitlements or policy state.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article’s threat pattern aligns with misuse of delegated access to reach data or systems.
Recommendation — Map agent misuse paths to TA0006 and TA0008 so detection and blocking logic covers credential abuse and spread.

Key terms

  • Request-Path Enforcement: Request-path enforcement means the system that understands a security event also makes the blocking or step-up decision at runtime. In practice, this keeps detection context and action together, which is critical when abuse depends on correlation across sessions, identities, or behaviours.
  • Fail closed: Fail closed means a system denies access when a dependency, policy check, or security service cannot make a confident decision. In AI retrieval pipelines, this prevents partial or unauthorised documents from leaking into the model when the authorization layer errors or returns incomplete results.
  • Agent observability: Agent observability is the collection and correlation of traces, logs, metrics, and evaluations across an AI agent’s execution path. It explains what happened during model calls, tool use, handoffs, and downstream effects, but it does not itself authorize, deny, or revoke access.
  • Delegated Authority Model: A delegated authority model defines who is allowed to approve, review, or execute control-related decisions across the enterprise. It helps ensure requests reach the correct responsible party, especially when control owners, managers, and process owners sit in different teams, regions, or systems.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, agentic AI identity, machine identity security, and secrets management. It helps practitioners connect identity controls to the operational decisions that govern real-world access.
NHIMG Editorial Note
Published by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org