By NHI Mgmt Group Editorial TeamBased on Strata Identity: “A New Identity Playbook for AI Agents: Securing the Agentic User Flow” (June 20, 2025)

TL;DR: AI agents are dynamic, ephemeral and autonomous, so the source article argues they need identity controls at every step from OIDC authentication to JIT provisioning, policy evaluation and human approval for sensitive actions, according to Strata Identity. The core issue is that legacy IAM assumes fixed, long-lived identities, while agentic work creates delegation chains and runtime decisions that existing NHI models do not cover.


At a glance

What this is: This article describes an agentic identity flow for AI agents and argues that legacy NHI controls do not adequately govern dynamic, autonomous delegation across tools, domains and trust zones.

Why it matters: IAM, IGA and PAM teams need to distinguish agentic identity from ordinary NHI so they can design controls around runtime delegation, step-up approvals and auditable policy decisions rather than static account lifecycle only.

By the numbers:

  • Gartner highlights that by 2026, 30% of enterprises will rely on AI agents that act independently and complete tasks on behalf of humans or systems.

Context

Agentic identity is the control problem that appears when a software entity can make runtime decisions, delegate tasks and act across multiple systems without behaving like a fixed service account. The article argues that legacy NHI governance assumes identities are pre-provisioned, narrowly scoped and mostly static, which does not fit this operating model.

For identity programmes, the issue is not whether AI agents use credentials, but whether the governing model can bind subject, actor, purpose and approval into a single lifecycle. That requires treating authentication, authorization, delegation and observability as one flow rather than disconnected controls.

The source frames AI agents as a separate identity class with autonomous behaviour, not just a new workload pattern. That distinction matters because the controls that work for long-lived NHI often fail when access is created, evaluated and retired within one task.


Key questions

Q: How should security teams govern agentic identities in client environments?

A: Security teams should govern agentic identities like a distinct non-human identity class with named ownership, scoped permissions, and continuous logging. The key is to separate the agent’s identity from the human who requested it and to tie access to a specific use case, not a broad entitlement. That reduces overreach and makes accountability possible.

Q: Why do legacy NHI controls fall short for autonomous AI agents?

A: Legacy NHI controls assume identity is fixed, scope is known in advance and authorization happens once. Autonomous agents can discover resources, choose tools and change action timing during execution, so the original provisioning decision no longer captures the real access pattern. That makes runtime governance the decisive control point.

Q: What breaks when human approval is not tied to a specific agent action?

A: When approval is generic, it becomes impossible to prove what the human actually authorized. That creates weak accountability, reusable consent, and poor audit evidence. A secure model binds the approval to one action, one scope, and one validity window so the human decision is cryptographically traceable and cannot drift into standing access.

Q: What should teams log to make agentic decisions auditable?

A: Log the subject, actor, delegation chain, resource, purpose and policy outcome for every agent action. That gives security, compliance and SIEM teams a complete reconstruction of why the agent acted and who authorised the path. Without that trail, incident review becomes guesswork.


Technical breakdown

OIDC, subject-actor binding and delegated identity

The article’s flow starts with a human or delegating agent authenticating to an actor agent through OIDC, then binding subject and actor through OAuth scopes. That distinction matters because the subject is the accountable principal, while the actor is the executing entity. In agentic systems, the trust question is not just who signed in, but who is authorised to act, under what purpose, and with what delegation context. Without that binding, the system cannot distinguish delegated intent from independent action, especially when the agent later uses multiple downstream tools and services.

Practical implication: model subject and actor as separate governance objects and require explicit delegation context before the agent can act.

JIT provisioning and ephemeral agent identities

The article describes on-demand provisioning of agent identities with TTL, purpose, risk and delegation attributes attached. This is more than short-lived access, because the identity itself is created for the task and then retired when the task ends. That pattern reduces orphaned credentials and permission sprawl, but only if provisioning, policy and retirement are tied to the same task boundary. For agentic systems, the governance unit is not the account record; it is the execution episode.

Practical implication: build provisioning and retirement around task completion, not around static account administration.

Layered policy evaluation across APIs, MCP and sensitive actions

The flow uses discovery through MCP, then layered policy evaluation through coarse-grained API controls and fine-grained ABAC decisions. That architecture is important because agentic behaviour creates a chain of decisions: which resource to find, which API to call, which action to attempt and whether the task stays inside policy. The article also adds human-in-the-loop approval for sensitive actions, which shows that policy cannot stop at initial authentication. The security boundary moves to each runtime decision point.

Practical implication: enforce authorization at discovery, invocation and high-risk execution points, not only at initial login.


Threat narrative

Attacker objective: The objective is to make an agent carry out authorized-looking actions that exceed the intended human or policy boundary while preserving the appearance of legitimate delegation.

  1. Entry occurs when the human or delegating agent authenticates to the actor agent through OIDC and establishes delegated authority.
  2. Escalation occurs when the agent discovers APIs and resources, then combines scope, purpose and delegation context to select actions at runtime.
  3. Impact occurs when the agent executes approved calls or sensitive transactions under policy, with the risk concentrated in mistaken delegation or excessive scope.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic identity breaks the assumption that an identity is stable long enough to govern it as a fixed account. Static NHI models were designed for service accounts, API keys and other identities whose scope can be set at provisioning time. That assumption fails when the actor reasons, delegates and changes tool use at runtime. The implication is that identity governance has to treat execution episodes, not just accounts, as the unit of control.

Subject, actor and purpose have to be governed together or the delegation chain becomes the attack surface. In agentic systems, the user, the agent and the downstream resource consumer are not the same thing. If policy only sees the authenticated subject or only sees the calling actor, accountability fractures. Practitioner teams need governance that preserves the link between intent and execution across every hop.

Just-in-time access is no longer only a privilege-reduction pattern, it becomes the only defensible way to scope autonomous execution. A long-lived entitlement model assumes the future task is known today. Agentic workflows invalidate that assumption because tool choice and timing emerge during execution. The result is a runtime governance problem, not a provisioning hygiene problem.

Human approval remains a control boundary for high-risk agent actions because the final authorization must still map to accountable intent. The article’s step-up authentication and liveness checks show where machine speed stops and governance begins. That does not make the agent less capable; it makes the control plane more auditable. Teams should treat human-in-the-loop approval as a boundary for irreversible action, not as a UX add-on.

Agentic identity is a named governance category, not an NHI subcase. NHI controls still matter, but they are insufficient when the identity can self-direct, query for resources and request new access mid-flow. The field needs a clearer separation between static machine identity governance and autonomous identity governance so programmes stop overextending service-account models into agentic behaviour.

From our research library:

What this signals

Agentic identity flow: the control problem is no longer only credential issuance, but whether a programme can preserve intent and accountability as an AI agent discovers resources and acts across domains. IAM teams should expect existing service-account governance to cover only part of that flow, not the whole execution path.

Runtime governance becomes the new boundary: if the policy decision is made only once at provisioning, the system has already lost visibility into tool choice, delegation and sensitive action approval. Programmes should shift review and enforcement toward the runtime path, where the decision to act is actually made.


For practitioners

  • Define agentic identity as a separate governance class Create policy and review paths that distinguish autonomous agent behaviour from static service accounts, API clients and machine users. Use different lifecycle, authorization and approval rules for the two classes.
  • Bind subject, actor and delegation context Require the identity layer to record who initiated the task, which agent executed it and what delegation scope was granted. Preserve that binding through downstream API calls and policy decisions.
  • Provision agent identities just in time Issue agent credentials only for the task at hand, attach TTL, purpose, risk and delegation attributes, and retire the identity automatically when the task ends.
  • Insert human approval for irreversible actions Use step-up authentication, liveness validation and explicit human approval before high-risk agent actions such as financial transactions, data movement or privilege changes.
  • Centralize agentic flow telemetry Log subject, actor, resource, delegation chain and policy outcome into a single OTEL-compatible trail so SIEM and audit teams can reconstruct the decision path.

Key takeaways

  • AI agents behave differently from static NHI because they can reason, delegate and act across domains during a live task.
  • The article’s control model ties authentication, JIT provisioning, layered policy evaluation and human approval into one governance flow.
  • Identity teams should separate agentic governance from traditional NHI management so they can control runtime delegation and auditability more precisely.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on agentic delegation and runtime privilege use.
ASI02 — Tool MisuseAgentic resource discovery and action selection create tool-misuse risk.
Recommendation — Map agent delegation paths to ASI03 and constrain runtime privilege scope to each task. Review agent tool access against ASI02 and remove unnecessary callable tools.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article warns against excess privilege in dynamically provisioned agent identities.
NHI-07 — Long-Lived SecretsThe flow replaces durable credentials with TTL-bound identities.
Recommendation — Apply NHI-05 to keep agent credentials narrowly scoped to the active task. Use NHI-07 to eliminate long-lived credentials from agent execution paths.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governing accountable AI action, not only access.
Recommendation — Establish governance ownership for agentic action paths under GOVERN and define approval thresholds.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article’s layered authorization model aligns to permissions and entitlements control.
Recommendation — Apply PR.AA-05 to validate every agent entitlement against current task context.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementDelegated agent activity and token movement map to credential use and movement across systems.
Recommendation — Use TA0006 and TA0008 to hunt for agent-driven credential use and cross-domain movement.

Key terms

  • Agentic Identity: An agentic identity is a non-human identity used by an autonomous system that can act, call tools, and access data with execution authority. It needs the same governance discipline as other privileged identities, plus runtime context, ownership mapping, and revocation paths.
  • Subject-Actor Binding: Subject-actor binding links the human or upstream delegator to the AI agent that actually performs the work. It is the control relationship that makes delegation explicit, so auditors can see who authorised the action, what the agent executed and under which scope.
  • Just-in-Time Provisioning: Just-in-time provisioning creates an account or entitlement at the moment it is needed, then removes it later. It reduces standing access duration, but it still relies on a static identity or role existing during the access window, which leaves room for misuse if revocation lags.
  • Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org