By NHI Mgmt Group Editorial TeamBased on Aembit: “The Future of Secrets Management in the Era of Agentic AI” (July 7, 2025)

TL;DR: Agentic AI systems that independently act across APIs, databases, and SaaS tools are exposing the limits of static secrets, because predictable provisioning and human-paced access reviews no longer match runtime behaviour, according to Aembit. The governance shift is toward dynamic, context-bound credentials and identity-first access decisions, not broader vault usage.


At a glance

What this is: This is an analysis of why agentic AI exposes the limits of static secrets, with the key finding that predictable vault-based models do not fit autonomous runtime behaviour.

Why it matters: It matters because IAM, PAM, and NHI programmes must govern access at issuance time for agents that change context and act faster than human-paced review cycles.


Context

Agentic AI changes the access problem because the actor does not just execute a fixed workflow. It can decide what to do next, call different systems, and change context while the task is still running, which makes static secret assumptions unreliable for identity governance.

In practice, that means secrets management is no longer just about where credentials are stored. For NHI, agentic AI, and hybrid delegation cases, the control point shifts toward real-time authentication, task-scoped authorisation, and short-lived access that matches the runtime state of the actor.


Key questions

Q: What breaks when organisations keep using static secrets for autonomous AI workflows?

A: Static secrets break the control model because they persist longer than the task that needs them, are easier to leak, and are harder to contain once exposed. In autonomous workflows, a compromised secret can be reused by attackers or by other systems, creating broad and persistent access. That makes rotation, scoping, and revocation far more urgent.

Q: Why do agentic AI systems increase initial access and privilege abuse risk?

A: Because they can chain valid access into multiple tool calls without needing a human to approve each step. If a secret is exposed or a role is overbroad, the agent can turn that access into data movement, service interaction or recursive task execution. The risk rises when access outlives the task that created it.

Q: How do teams know when a secrets management model is failing for agents?

A: A model is failing when access has to be preloaded, manually maintained, or reused across unrelated tasks to keep the agent functioning. That is a sign the programme is compensating for a mismatch between static credentials and dynamic runtime behaviour. Frequent exceptions, broad tokens, and hardcoded values are practical warning signals.

Q: What is the difference between delegated user access and agent-owned NHI access?

A: Delegated user access is permission the agent inherits to act on behalf of a person, usually within a defined user scope. Agent-owned NHI access is the identity the agent uses when it acts independently or reaches systems outside that delegated boundary. The two should not be collapsed into one governance rule because the accountability and scope are different.


Technical breakdown

Why static secrets fail for agentic AI

Static secrets management assumes the caller, context, and access pattern are known in advance. That works for stable workloads, but not for an agent that can decide which tool to use, when to act, and which system to reach next. A secret injected into memory or a container does not express purpose, intent, or changing context, so the credential becomes broader than the task. Once the agent can branch across APIs, databases, and SaaS tools, the trust model stops being about storage location and becomes about whether access can be issued at the moment of use.

Practical implication: treat static secret injection as a fallback pattern, not the primary access model, for agentic systems.

Dynamic credentials and context-bound access

Dynamic access management replaces prepositioned secrets with credentials issued at request time and constrained by task context. That context can include the agent identity, intended action, runtime environment, and scope of the work being performed. This is the operational difference between a vault that stores a reusable secret and a policy decision that decides whether the agent should receive a short-lived credential at all. For agentic AI, the useful control is not merely rotation. It is whether access can be minted, bounded, and invalidated at the pace of runtime decisions.

Practical implication: move high-value agent access to ephemeral, context-aware issuance with explicit task scoping.

Hybrid identity in delegated and autonomous agent flows

Many agentic systems operate with mixed authority. An agent may use delegated human permission for one action, then need its own non-human identity for another system that sits outside that delegation boundary. That split matters because one identity model cannot safely cover both behaviours. OAuth delegation helps with user-authorised access, but it does not solve the broader NHI problem when the agent initiates actions on its own. The access model therefore has to distinguish between acting on behalf of a person and acting as an independent runtime identity.

Practical implication: separate delegated user scope from agent-owned NHI scope and govern each one explicitly.


  • Hugging Face Spaces breach 2024: Unauthorised access to Hugging Face Spaces may have exposed secrets users stored for AI apps; tokens were revoked and org tokens removed.
  • Toyota T-Connect key exposure 2022: A subcontractor left a T-Connect server key on public GitHub from 2017 to 2022; 296,019 customers' emails were exposed, misuse unknown.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Static secrets management is built on a stable-workload assumption that agentic AI invalidates. The model presumes access can be provisioned centrally, then reused while the workload behaves predictably. Agentic systems break that premise because the runtime path is not fixed, the tool sequence is not predetermined, and the access need can change mid-task. The implication is that secrets lifecycle thinking is no longer sufficient on its own for autonomous behaviour.

Agentic AI creates identity blast radius, not just credential sprawl. The real issue is not the number of secrets in circulation but the range of actions a single runtime identity can reach when it can choose tools dynamically. That changes the governance question from where secrets live to how far one decision can propagate across cloud, SaaS, and data systems. Practitioners should treat scope control as the primary containment variable.

Identity-first access decisions are now the control plane for autonomous systems. In a static model, vaults are the gate. In an agentic model, the decision to issue, scope, and expire access becomes the security boundary. This aligns with OWASP-AGENTIC and OWASP-NHI thinking because the actor is both non-human and runtime-variable. Security teams need to govern the decision moment, not just the credential store.

Hybrid delegation is the named concept teams are underestimating. Agentic systems increasingly switch between delegated human authority and their own non-human identity inside the same workflow. That creates a governance gap if teams assume one authorisation model covers both cases. The implication is that IAM and NHI programmes must analyse when the agent is acting for the user and when it is acting as itself.

Vaults are becoming a backstop, not the primary access mechanism. That does not eliminate them, but it does change their role in modern identity architecture. Where the article is strongest is in showing that secrets storage alone cannot satisfy runtime authorisation for autonomous systems. Practitioners should re-centre governance on issuance, context, and revocation rather than repository-centric control.

From our research library:

What this signals

Hybrid delegation is the governance gap most teams will underestimate first. Once an agent can move between delegated user permissions and its own non-human identity, the control problem is no longer just secret storage. It becomes identity selection, scope separation, and revocation across two different authority models.

Identity-first access decisioning is the real operating model shift. Agentic behaviour compresses the time between intent and action, which means human-paced review cycles are no longer the right place to enforce policy. Access has to be decided at issuance time, with context attached to the request rather than inferred after the fact.


For practitioners

  • Define agent-owned access boundaries Separate accesses the agent takes as itself from accesses it inherits through delegated human authority, and document which systems allow each mode.
  • Issue short-lived credentials at request time Replace preloaded or long-lived credentials for agent workflows with task-scoped credentials that expire within the runtime window of the action.
  • Bind access to runtime context Use policy decisions that consider agent identity, purpose, and environment before granting access to APIs, databases, and SaaS tools.
  • Review where vaults remain necessary Keep vaults for legacy systems and human-operated paths, but remove them as the default pattern where runtime identity can be authenticated directly.

Key takeaways

  • Agentic AI exposes a mismatch between static secret models and runtime identity behaviour, especially when access decisions change inside a task.
  • The main governance issue is not only secret storage, but the size and persistence of the access blast radius created by reusable credentials.
  • Practitioners should shift toward short-lived, context-bound access decisions and treat vaults as a backstop for legacy and human-operated paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgentic systems can outgrow static privilege assumptions as they switch tools at runtime.
Recommendation — Treat agent access as runtime privilege and constrain identity selection to the task context.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on replacing static secret-based access with dynamic agent authentication.
NHI-05 — Overprivileged NHIBroad long-lived credentials create excessive access when an agent can reach multiple systems.
Recommendation — Move agent authentication away from reusable secrets and toward short-lived, context-bound credentials. Review agent permissions for overbreadth and narrow scope to the minimum task boundary.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governing autonomous AI access decisions across systems.
Recommendation — Assign ownership for AI access decisions and document who approves and revokes agent authority.
NIST Zero Trust (SP 800-207)5.6 — Access is Granted on a Need-to-Know BasisThe piece argues for context-aware, task-scoped access instead of standing credentials.
Recommendation — Enforce need-to-know access for agents at issuance time rather than relying on standing secrets.

Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Dynamic Access Control: Dynamic Access Control is an access decision model that changes permissions in real time based on current context. It evaluates signals such as user risk, device posture, location, time, resource sensitivity, and behavior, then grants, limits, or revokes access continuously. It is commonly implemented with policy engines and identity telemetry.
  • Static Secret: A secret, such as an API key or password, that does not change automatically over time. Static secrets require manual or scheduled rotation and represent a higher security risk than dynamic secrets or managed identities.
  • Hybrid Delegation: A pattern where one agent alternates between acting on behalf of a human and acting under its own non-human identity. The distinction matters because delegated authority and agent-owned authority carry different scope, accountability, and revocation requirements.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org