TL;DR: C1.ai argues that AI agents are shifting knowledge work from human-paced execution to machine-paced delegation, making identity core infrastructure with controlled inputs, observable outputs, and accountable actions. Access review models built for stable human access windows no longer fit continuously acting agents.
At a glance
What this is: This is a blog post arguing that the agentic enterprise makes identity the control plane because humans are increasingly managing fleets of AI agents rather than doing the work directly.
Why it matters: It matters because IAM, PAM, and governance programmes built around periodic human access reviews will not keep up with continuously acting agents that need real-time authorisation and traceability.
👉 Read C1.ai's analysis of how agentic enterprise identity becomes the control plane
Context
The governance gap is that identity programmes were designed for a world where humans initiated most work and exceptions could be handled later. Agentic enterprises invert that model: AI agents can act continuously at machine speed, so the old assumption that access remains stable long enough for periodic review no longer holds.
In practical terms, this is an identity governance problem, not just an automation story. The article frames the shift around controlled inputs, observable outputs, and accountable actions, which puts lifecycle governance, authorisation, and auditability at the centre of AI-agent operations.
Key questions
Q: How should security teams govern AI agents that can take runtime response actions?
A: Treat them as privileged NHI workloads with explicit scope, short-lived authority, and full action logging. Separate read-only investigation from enforcement, require approval for high-impact containment, and review the agent’s effective permissions on a schedule. If the agent can change runtime policy, it needs the same governance discipline as any other elevated identity.
Q: Why do traditional access reviews fail for agentic enterprise identity?
A: Access reviews assume permissions remain stable long enough to be sampled and certified later. Agentic systems can create, use, and retire access in a much shorter window, so the control misses the decision point and leaves no durable state to review.
Q: What breaks when an AI agent can use allowed actions incorrectly?
A: The break is in the assumption that permission equals safety. If an agent can chain valid actions into the wrong outcome, traditional access control no longer captures risk. Security teams need runtime checks for task alignment, confidence, and reversibility before high-impact actions execute, especially where the actor can improvise under uncertainty.
Q: How can organisations align human IAM and NHI governance for agentic systems?
A: Organisations should use one governance model for approval, scope, review, and revocation across humans, service accounts, and AI agents. Agentic systems should not sit outside existing identity lifecycle processes. If they do, access decisions, recertification, and offboarding will drift into separate exception handling.
Technical breakdown
Why periodic access review breaks for agentic systems
Periodic access review assumes access persists long enough to be observed, certified, and removed on a human cadence. AI agents can be created dynamically, act continuously, and interact with many systems in parallel, which compresses the governance window to runtime. That changes identity from a retrospective control into a live control point. In this model, the issue is not whether a permission was once approved, but whether the permission was valid for the exact action the agent is about to take. Real-time policy enforcement becomes the architecture, not the exception.
Practical implication: Shift governance from after-the-fact certification to runtime authorisation and continuous traceability.
How identity becomes the control plane for AI agents
A control plane is the layer that decides who can do what, when, and under which constraints. For AI agents, that means identity must bind the agent, its delegated scope, the systems it may touch, and the actions it may trigger. The article’s framing is important because it treats identity as core infrastructure rather than a bolt-on checkpoint. The technical requirement is not just authentication. It is the combination of identity, policy, and observability needed to constrain agent actions and reconstruct them later. Without that linkage, trust becomes unauditable.
Practical implication: Map every agent action to a governed identity and an explicit policy decision.
What controlled inputs, observable outputs, and accountable actions mean in practice
The article names three operating conditions that distinguish safe agent use from unmanaged automation. Controlled inputs limit what data and prompts an agent can consume. Observable outputs make agent decisions and side effects visible to operators and audit systems. Accountable actions ensure each step is attributable to a governed identity rather than an opaque workflow. Together, these reduce the chance that an agent drifts into unintended behaviour across systems. This is especially relevant where agents can chain decisions across multiple tools and services without a human approving every step.
Practical implication: Design agent governance around input boundaries, output logging, and action attribution from the start.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity is no longer a support function when agents become the execution layer. The article correctly reframes the enterprise around managed non-human action rather than human productivity. That changes identity from a directory concern into an operational control plane for machine-paced work. Practitioners should treat agent identity as a first-class governance domain, not a side effect of automation.
Periodic review was designed for access that stays stable long enough to be certified. That assumption fails when agents are created dynamically, act continuously, and expire or re-scope within the same operating window. The implication is not simply that reviews need to be faster; it is that review itself stops being the primary control for many agent actions.
Controlled inputs, observable outputs, and accountable actions define the minimum viable governance model for agentic work. This is the named concept that should anchor the category. If any one of those three is missing, the organisation is trusting behaviour it cannot bound, see, or attribute. Practitioners should evaluate agent programmes against this triad before expanding scope.
The governance problem spans human IAM, NHI, and agentic AI at once. Humans are increasingly supervising fleets of non-human actors, which means delegation chains now cross traditional identity boundaries. That creates a shared lifecycle problem for approval, monitoring, and offboarding. Practitioners should align IAM, PAM, and NHI governance around the same operating model rather than managing them as separate silos.
Identity governance for agents will be judged by runtime containment, not quarterly cleanup. The article’s argument points to a market shift in which control quality is measured by how well policy follows execution. That makes traceability, policy enforcement, and action-level attribution the practical differentiators. Practitioners should expect agent governance to become a board-level resilience issue, not just an IAM design choice.
From our research library:
- 28% of secrets incidents now originate outside code repositories, in Slack, Jira, and Confluence, and are 13% more likely to be categorised as critical than code-based leaks, according to the State of Secrets Sprawl 2026.
- Read next: Ultimate Guide to NHIs — Why NHI Security Matters Now
What this signals
Agentic enterprise governance is a lifecycle problem, not a point solution problem. Organisations that treat agents as just another automation layer will miss the fact that their permissioning, review, and offboarding assumptions all change at once. The operating model has to move from periodic cleanup to continuous lifecycle control across people and machines.
Identity blast radius becomes the practical metric for agent programmes. Once an agent can chain actions across multiple systems, the question is no longer whether the model is accurate but how far a bad decision can travel before governance interrupts it. That is why runtime containment and action attribution matter more than post-hoc certification.
Controlled inputs, observable outputs, and accountable actions should become the organising concept for agent governance. The same principle should guide IAM, PAM, and NHI teams that are now sharing the same operational surface. Use the identity plane to limit what an agent can consume, what it can do, and how far its decisions can propagate.
For practitioners
- Define agent identity before deployment Assign each agent a governed identity, explicit owner, and bounded delegated scope before it is allowed to touch production systems.
- Replace periodic reviews with runtime policy checks Move authorisation decisions to the point of action so continuously acting agents are evaluated against current policy, not stale certification cycles.
- Constrain inputs, outputs, and action paths Limit what each agent can read, what it can emit, and which downstream actions it can trigger across systems.
- Make agent actions fully attributable Log prompts, tool calls, approvals, and resulting actions so every decision can be traced back to a controlled identity and policy decision.
Key takeaways
- The article argues that agentic work collapses the old assumption that identity can be governed on a human review cadence.
- The practical risk is not only scale, but that agents can operate continuously across many systems without a stable access window.
- The control that matters most is runtime authorisation paired with clear attribution, so every agent action is constrained and explainable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centers on governing agent identities and delegated privilege. |
| ASI01 — Agent Goal Hijack | The post warns that agents can drift from intended objectives once they operate continuously. | |
| Recommendation — Bind each agent to explicit identity, scope, and runtime authorisation before allowing production access. Constrain agent objectives with policy and supervision so task drift cannot expand authority. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Agent identity depends on strong authentication and trustworthy delegation boundaries. |
| NHI-05 — Overprivileged NHI | The article highlights the need to limit agent permissions to narrow, accountable scopes. | |
| Recommendation — Use strong authentication and delegated identity controls for every agent before it can act. Review agent entitlements for least privilege and remove access that is not tied to a current task. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Runtime authorisation is the core control the article argues for. |
| Recommendation — Apply entitlement governance at the moment of action instead of relying on periodic certification. | ||
Key terms
- Agentic enterprise: An operating model where humans and autonomous AI systems work together inside the same business workflows. The security challenge is that decisions, data movement, and access all happen at machine speed, so governance must track both the actor and the workflow context.
- Controlled Inputs: The data, prompts, and context an agent is allowed to consume before it acts. Controlled inputs limit what an agent can infer or use, which reduces the chance that it will make decisions based on out-of-scope information or unsafe context.
- Observable Outputs: The ability to inspect, log, and review what an agent produces or triggers after it acts. Observable outputs create an audit trail for decisions, side effects, and downstream changes, which is essential when agents operate faster than human review cycles.
- Accountable Action: Accountable action is a response that has a clear owner, a specific purpose, and a way to measure whether it worked. In human risk management, it turns insight into work that can be assigned, tracked, and reviewed. Without accountability, risk signals may be visible but still fail to change outcomes.
What's in the full article
C1.ai's full blog post covers the operating model details this post intentionally leaves for the source:
- The essay's full argument for why identity becomes the control plane in an agentic enterprise
- The human-to-agent delegation model that compares managers, approval points, and monitoring responsibilities
- The operational framing around controlled inputs, observable outputs, and accountable actions
- The broader business case for scaling work without linear headcount growth
👉 The full C1.ai post expands on the shift from human throughput to governed agent execution.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org