By NHI Mgmt Group Editorial TeamBased on Strata Identity: “How identity management is shifting into the agent era” (June 13, 2025)

TL;DR: Agentic AI systems require cryptographic authentication, task-scoped authorization, and delegation-aware audit trails because traditional IAM was built for long-lived human users, according to Strata Identity. The real shift is that identity governance now has to follow runtime decisions, not static roles, or compliance and accountability will break down.


At a glance

What this is: This is a Strata Identity analysis arguing that agentic AI forces IAM to shift from static user controls to runtime identity, delegation, and audit for autonomous actions.

Why it matters: It matters because IAM, PAM, and governance teams must account for non-human actors that authenticate, delegate, and act at runtime without the review cycles designed for human users.


Context

Agentic AI identity is the security problem here: autonomous agents are taking actions, making decisions, and calling downstream systems without fitting the assumptions behind human-centric IAM. The model breaks because login-centric controls, static roles, and manual review cycles were designed for people, not for runtime decision-makers.

Strata Identity frames the shift as one from identity for users to identity for autonomous actors operating across clouds and APIs. For IAM and governance teams, the core question is no longer whether an agent can authenticate, but whether its identity, delegation, and audit trail remain trustworthy at the moment it acts.


Key questions

Q: What breaks when AI agents inherit human IAM controls?

A: Human IAM controls break because they assume a person makes a request, waits, and can later be reviewed or deprovisioned. AI agents can chain actions, spawn downstream agents, and complete tasks faster than review cycles can observe. The result is weak attribution, stale privilege, and revocation paths that are too blunt to contain one actor cleanly.

Q: Why does agentic AI increase access risk in enterprise identity programs?

A: Agentic AI increases risk because one agent may move across multiple services to complete a single task. Each new connection creates another access relationship to govern, and unmanaged connections quickly fragment policy, logging, and approval. Without centralized enforcement, teams lose visibility into who or what acted, which policy applied, and whether access stayed within intended scope.

Q: How do security teams know whether managed identities are working for agents?

A: Managed identities are working when there are no embedded secrets in code or config, each agent has a distinct identity, and privileges map cleanly to a small number of functions. If roles are broad, reused, or hard to revoke, the model is failing. The signal to watch is whether identity ownership and expiry are visible in operations.

Q: What is the difference between delegation for agents and session access for users?

A: Session access assumes the person who logged in is the person who acts until logout. Delegation for agents must preserve a machine-readable chain from user to agent to downstream service, because the actor executing the task may not be the original requester. That makes signed claims and on-behalf-of records essential.


Technical breakdown

How agent authentication differs from human login flows

Agentic systems do not authenticate like people. Instead of passwords, MFA, or a browser session, they rely on cryptographic proofs such as SPIFFE/SVID, PKCE, mTLS, and signed JWTs so the runtime can verify both identity and session binding. The important distinction is that these credentials are short-lived and task-scoped, which makes the identity context part of the execution path rather than a pre-login event. This is why the control surface moves from the endpoint to the workload, API gateway, or proxy layer.

Practical implication: treat agent authentication as workload identity, not user login, and verify where the proof is enforced at runtime.

Why RBAC and static ABAC struggle with agentic AI

RBAC assumes stable roles and ABAC often assumes relatively stable attributes. Agentic AI breaks both assumptions because the actor can change task, context, and downstream action sequence within the same runtime window. That is why the article emphasises scoped tokens, dynamic policies, and policy-as-code engines such as OPA or Cedar. The control is not just who the agent is, but what task it is doing, what user intent it is executing, and what risk state applies at that instant.

Practical implication: move authorisation checks to the point of action and make scope, intent, and risk part of every policy decision.

Delegation chains and on-behalf-of authorisation

When an agent acts on behalf of a user or service, the identity chain extends beyond a single subject. OAuth on-behalf-of flows, signed role assertions, and downstream delegation tracking preserve the link from user to agent to service, which is critical for trust and accountability. Without that chain, the system may know that an API call happened, but not whose intent it served or which scope justified it. For autonomous workflows, this makes delegation metadata a core control rather than audit decoration.

Practical implication: require delegation-aware tokens and traceable claims wherever an agent can act for another identity.


NHI Mgmt Group analysis

Runtime identity is replacing static identity for autonomous actors: Agentic AI does not fit a model built around logins, long-lived roles, and periodic review. The decisive change is not that identity matters more, but that identity has to be verified at the moment of action, with scope and intent attached. IAM programmes that keep treating agent behaviour as a human workflow will miss the control point entirely.

Assumptions about stable access windows are collapsing: Access review processes were designed for conditions where entitlement persists long enough to be certified. That assumption fails when an autonomous actor can request, use, and discard credentials inside a single execution path. The implication is that governance has to move from retrospective review to runtime issuance and runtime evidence.

Delegation becomes the governance centre of gravity: The article’s most important architectural shift is not authentication alone, but the chain from user to agent to downstream service. Once agents can act on behalf of people, organisations need to know which action was delegated, which policy authorised it, and which outcome was produced. That changes accountability from an after-the-fact reporting problem into a design requirement.

Identity fabrics and agent registries will become the control plane for AI operations: As autonomous agents proliferate, manual provisioning and ad hoc account tracking will not scale. The article points toward registry-based governance, lifecycle events, and runtime orchestration because identity sprawl is the predictable failure mode. Practitioners should interpret this as a signal that agent identity management is becoming infrastructure, not administration.

Runtime audit evidence matters more than raw API logs: A log line that records only an API call cannot explain intent, policy, or delegated authority. For autonomous actors, that is insufficient for compliance validation, incident response, or post-incident reconstruction. The field needs execution graphs and decision context, because traceability without context does not establish accountability.

From our research library:

What this signals

Runtime controls will become the default design pressure: Agentic identity collapses the usefulness of periodic reviews because the actor can obtain and release access before a human process ever sees it. Teams should assume that identity evidence must be produced at task time, not at certification time.

Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey. That gap suggests most programmes are still mapping agent behaviour onto human IAM models that cannot preserve context, delegation, or accountability.

Agent registries will matter as much as credential stores: Once agents proliferate, the operational question becomes which agents exist, what scopes they hold, and when they were last revoked. Identity governance for autonomous actors will be judged by its ability to explain active authority in real time.


For practitioners

  • Redesign agent authentication around cryptographic proof Replace login-based assumptions with workload-bound identity proofs, short-lived credentials, and session binding for any autonomous system that can call production services.
  • Move authorisation to runtime policy enforcement Enforce task-scoped access at the proxy or API layer so scope, intent, and risk are evaluated when the agent acts, not when it is provisioned.
  • Track delegation chains end to end Require traceable claims for user, agent, and downstream service relationships so every on-behalf-of action can be reconstructed from the authorization record.
  • Treat agent lifecycle as runtime governance Issue credentials just in time, attach expiries, record revocation events, and retire dormant agents automatically instead of relying on manual provisioning.

Key takeaways

  • Agentic AI forces IAM to move from static user-centric control to runtime identity, because autonomous actors can authenticate and act within the same execution path.
  • Delegation chains are now the core accountability problem, since audit trails must show who initiated the task, what policy authorised it, and what outcome followed.
  • Governance will have to treat agent identity as infrastructure, with just-in-time issuance, revocation, and runtime evidence replacing manual provisioning and retrospective review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article is centered on autonomous agents receiving and using delegated privilege at runtime.
ASI02 — Tool MisuseRuntime controls are needed because agents can call downstream tools and APIs in changing contexts.
Recommendation — Limit agent privileges to task scope and validate every delegated action at execution time. Constrain which tools an agent may invoke and enforce policy before each tool call.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article emphasises cryptographic proofs, short-lived credentials, and workload-bound authentication.
NHI-05 — Overprivileged NHIThe article warns against agents accumulating broad access beyond the task they are executing.
Recommendation — Replace human login assumptions with short-lived, verifiable machine authentication for agents. Scope agent permissions to the minimum task required and remove standing access.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governance, accountability, and lifecycle control for autonomous AI actors.
Recommendation — Establish governance rules for agent identity, delegated authority, and runtime accountability.

Key terms

  • Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
  • Delegation Chain: A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
  • Identity Fabric: An identity fabric is a connected control model that shares context across governance, privileged access, and access management. It is not a product category. The aim is to make identity decisions coherent across the full lifecycle so ownership, privilege, and enforcement reinforce each other.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org