By NHI Mgmt Group Editorial TeamBased on WorkOS: “Concentric AI vs WorkOS: Data Governance vs Identity for Agentic Security” (November 10, 2025)

TL;DR: As organisations deploy AI agents that act on behalf of users, the core security problem shifts to authenticated identity, delegated authority, and revocation, according to WorkOS. Data governance still matters, but agentic systems fail fastest when identity controls cannot define who the agent represents, what it may do, and when that authority ends.


At a glance

What this is: This is a comparative analysis of agentic security that says identity and authorization are the foundation, while data governance is only one layer of control.

Why it matters: IAM, PAM, and NHI teams need this split because agent permissions, delegation, and revocation now determine whether data controls can actually enforce policy.


Context

Agentic security is the problem of governing software that can act on behalf of users, choose actions at runtime, and access multiple systems with delegated authority. The governance gap is that many controls still assume the subject is either a human user or a static workload identity, not an agent that can inherit and exercise privileges dynamically.

This article argues that the first question is identity, not data alone: who the agent represents, what permissions it inherits, and how authority ends. For IAM and NHI programmes, that shifts the centre of gravity from isolated data protection to identity-bound authorisation, revocation, and audit.


Key questions

Q: What breaks when AI agents are given broad inherited permissions?

A: Broad inherited permissions break the assumption that access is tied to a narrow business need. The result is larger blast radius, weaker accountability, and faster propagation of mistakes or abuse across connected systems. A single compromised or misconfigured agent can then touch far more data and workflows than the original task required.

Q: Why do AI agents require stronger identity controls than standard applications?

A: AI agents can choose actions, call tools, and chain operations, so their identity is not just a login mechanism. If they are overprivileged, one prompt injection or workflow abuse can turn into broad enterprise misuse. Teams should therefore constrain agent permissions, use short-lived credentials, and treat agent access as privileged by default.

Q: How do security teams know if agent authorization is actually working?

A: Authorization is working only if the agent can complete the intended task without gaining unnecessary reach. Good signals include short-lived credentials, task-scoped permissions, approval for sensitive changes, and clear logs linking each action to a user and an agent. If credentials are reused, privileges persist, or the agent can move between systems without reauthorization, the control is failing.

Q: Should organisations prioritise identity governance before expanding agentic AI?

A: Yes. Organisations should establish ownership, least privilege, monitoring, and revocation for machine identities before broadening agentic AI use. Without those controls, each new agent can multiply blast radius and create shadow access that is hard to unwind after an incident.


Technical breakdown

Why delegated authority becomes the control plane for AI agents

Agentic systems do not just retrieve data; they act under some form of delegated authority. That means the security question is not only what the agent can see, but what it can do in the name of a user, team, or service account. In practice, the control plane becomes identity first: authentication establishes the actor, authorization scopes the permitted actions, and session management defines how long that authority lasts. Without those controls, data protections become downstream safeguards that can be bypassed by legitimate but overbroad access.

Practical implication: model agent access as delegated authority, not as a generic application session.

Why data controls alone cannot stop agentic misuse

Data security posture management can classify and monitor sensitive information, but it does not answer whether an agent should have reached the data in the first place. That distinction matters because AI agents often combine systems, context, and permissions in ways that static data rules cannot fully anticipate. If identity is weak, the agent can still query, transform, or route sensitive content within permitted channels. Data controls reduce exposure, but authorization determines whether exposure was legitimate at all.

Practical implication: pair data controls with explicit authorization boundaries for every agent action path.

How revocation and auditability change for agentic identity

Traditional access governance assumes a stable account or service identity that can be reviewed after the fact. Agentic workflows challenge that assumption because permissions may be inherited, time-scoped, or triggered by context rather than by a durable human operator. That means revocation has to be immediate and auditable at the point where delegation exists, not only at the data layer. If the identity record does not capture who the agent acted for and under which authority, compliance evidence becomes incomplete even when data protection controls are present.

Practical implication: make delegation, revocation, and action logs first-class identity records for AI agents.


NHI Mgmt Group analysis

Identity is the control boundary for agentic systems: AI agents inherit risk from the authority they are granted, not just from the data they touch. Data-centric controls can reduce leakage, but they cannot answer the foundational governance question of who the agent is acting for and whether that authority is still valid. The implication is that agentic security programmes must start with identity governance, not treat it as an afterthought.

Delegated authority is the named risk concept: The article exposes a delegation gap where permission inheritance matters more than raw access to repositories. Once an agent can act on behalf of a user, the security model must govern representation, scope, and termination together. Practitioners should recognise delegated authority as the place where identity and autonomy meet, because that is where most policy assumptions break.

Data governance and identity governance are complementary, not interchangeable: The article is right to separate data protection from identity infrastructure, because one cannot substitute for the other. DSPM-style controls can classify sensitive content, but they do not create trustworthy authorization decisions for non-human actors. The field needs to stop treating data visibility as a proxy for safe agent access.

Revocation windows become the decisive governance test: Agentic systems fail when access persists longer than the task that justified it. That exposes a lifecycle problem as much as an authorization problem, because the moment authority outlives intent, the control model is already late. The practitioner takeaway is to govern the end of authority as tightly as the start of access.

Identity-first agent security aligns with existing IAM discipline: This is not a new security category so much as a stricter application of IAM, PAM, and lifecycle control to non-human actors. The article reinforces that enterprises do not need to invent a parallel model for every AI use case; they need to extend identity governance to delegated, time-scoped, and auditable machine action. That is where the programme will stand or fall.

From our research library:

What this signals

Agentic security programmes should expect identity to become the primary policy boundary for non-human action. Once an agent can act on behalf of a person or service, data controls become necessary but insufficient, because the decisive question is whether the delegation itself was valid.

Delegated authority drift: the most important failure mode is not leakage after access, but permission inheritance that outlives the task. Identity teams need to watch for roles, sessions, and approvals that were built for human-paced workflows and do not fit agent-timed execution.


For practitioners

  • Define agent identity before data access Map every AI agent to a named human, service, or business context before it can inherit permissions. Record who it represents, what authority it receives, and which systems that authority covers.
  • Scope delegated permissions by task and context Replace broad inherited access with explicit permission boundaries tied to business function, session context, and trigger conditions. Review whether the agent can read, write, or act only within that bounded scope.
  • Treat revocation as an operational control Ensure permissions can be withdrawn immediately when the user changes role, leaves the organisation, or the task completes. Revocation should reach the agent identity, not only the underlying source system.
  • Log delegated actions as identity events Capture who authorised the agent, what it accessed, what it changed, and under which delegation chain it operated. Use those records for audit, compliance, and incident review.

Key takeaways

  • The article’s central point is that AI agents change the security model by making identity, delegation, and revocation the first governance questions.
  • Data protection still matters, but it cannot compensate for weak authorization boundaries or unclear agent representation.
  • Identity teams should treat agent permissions as time-scoped and auditable machine authority, not as ordinary application access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgent identity and delegated authority are the article's central risk theme.
Recommendation — Constrain agent authority to explicit identities and audit every privilege grant.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on authentication and authorization for non-human agents.
NHI-05 — Overprivileged NHIThe piece warns against broad inherited permissions for AI agents.
NHI-01 — Improper OffboardingRevocation and end-of-authority are a major part of the argument.
Recommendation — Require strong authentication for every agent before any delegated access is issued. Reduce inherited permissions and scope each agent to the minimum necessary access. Treat revocation as part of the agent lifecycle and remove access when the task ends.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about how permissions are granted and bounded.
Recommendation — Enforce explicit authorization boundaries for every agent action and delegated role.

Key terms

  • Agentic security: The practice of governing software actors that can choose actions, tools, and timing in production workflows. It extends identity, authorization, logging, and lifecycle control to agents so their behaviour is tied to a verifiable principal and a revocable permission set.
  • Delegated Authority Model: A delegated authority model defines who is allowed to approve, review, or execute control-related decisions across the enterprise. It helps ensure requests reach the correct responsible party, especially when control owners, managers, and process owners sit in different teams, regions, or systems.
  • Identity-first security: Identity-first security is an approach that treats identity as the primary control plane for managing risk. Instead of relying mainly on network or endpoint boundaries, it uses identity context to decide what can happen, when it can happen, and under what conditions. That model is especially relevant where privileges move across human, non-human, and agentic actors.
  • Agent Revocation: Agent revocation is the process of withdrawing an AI agent's authority so it can no longer act on behalf of a user, service, or workflow. The control is only effective when it reaches the delegated identity itself, not just the backend system or dataset the agent was using.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org