By NHI Mgmt Group Editorial TeamBased on WorkOS: “Nightfall AI vs WorkOS: Data Protection vs Access Control for Agentic Security” (November 10, 2025)

TL;DR: As organizations deploy AI agents, the core security choice is whether to start with data loss prevention or access control, according to WorkOS. Data protection can detect exfiltration, but secure agentic systems still depend on authentication, authorization, and auditable identity boundaries before data ever moves.


At a glance

What this is: This article argues that secure AI agents depend first on authentication, authorization, and auditable access boundaries, while DLP only addresses data leaving the environment.

Why it matters: IAM, PAM, and NHI teams should treat agentic security as an access-governance problem first, because controlling identity and privilege determines what an agent can reach before any data-control layer can intervene.


Context

Agentic security is the problem of governing software that can act, choose tools, and touch systems on behalf of a user or workflow. In this article, the central question is not whether data can be detected after it moves, but whether the agent was ever authorised to reach the resource in the first place.

For AI agents, identity control is the control plane. Authentication, authorization, session handling, and tenant boundaries determine what an agent can do, while DLP only observes some of the consequences when data leaves approved boundaries. That makes access control the earlier and more durable governance layer for agentic systems.


Key questions

Q: What breaks when AI agents are given broad standing access?

A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check. That creates a control gap between intended scope and actual runtime behaviour. The result is weak accountability, limited containment, and audit trails that show activity without explaining why the activity was allowed.

Q: Why does DLP not replace access control for agentic systems?

A: DLP inspects content movement, but access control decides whether the agent should have been able to reach the data, tool, or workflow at all. For agentic systems, the earlier control is decisive because the risk starts when identity is authorised too broadly, not only when data leaves the environment.

Q: How should security teams reduce the blast radius of AI agents without assuming authorization alone is enough?

A: Security teams should treat agent permissions as necessary but insufficient. Limit the agent to the smallest practical identity, tool set, and data scope, then add controls that observe what the agent actually does across a session. The key is to separate legitimate actions from coerced sequences, because every individual call may be allowed while the overall chain still causes data loss or policy abuse.

Q: How can IAM teams tell whether agent access is actually safe?

A: Look for proof that identity is tied to the execution moment, not just the provisioning record. Safe agent access requires a control that can validate who is accountable, what action is being attempted, and whether it is approved right now. If those checks do not happen at runtime, the access model is still static.


Technical breakdown

Why access control is the first boundary for AI agents

Agentic systems are different from passive applications because they can initiate actions, call tools, and traverse resources in ways that depend on identity context. Authentication proves who or what the agent is, authorization limits what it can access, and session management constrains the duration and scope of those rights. In enterprise settings, that means the agent’s identity must be bound to a user, service, or tenant context before it can touch customer records, internal APIs, or administrative workflows. DLP can inspect outbound content, but it cannot decide whether the agent should have reached the data source at all.

Practical implication: define the agent’s allowed resources and privileges before deployment, not after data inspection catches a leak.

How authorization differs from data loss prevention

Authorization answers whether access should exist. DLP answers whether sensitive content is leaving the boundary. That distinction matters because an agent can be fully compliant with DLP and still be dangerously over-privileged, able to query records, update systems, or trigger actions it should never have had in scope. Fine-grained authorization and role-based access control work upstream of the data path, so they reduce blast radius before a request becomes a data event. For AI agents, this is especially important because their value comes from action, not just observation.

Practical implication: treat DLP as a monitoring layer and authorization as the control that prevents excess access in the first place.

Why auditable identity boundaries matter in agentic workflows

Once an AI agent acts on behalf of a user or tenant, the enterprise needs to know which identity was bound to the action, which resources were exposed, and which policy approved it. That is an access-governance problem, not a content-inspection problem. Auditable identity boundaries make it possible to reconstruct responsibility, enforce least privilege, and segment tenants in multi-application environments. Without those boundaries, security teams may detect data movement but still lack the identity evidence needed to prove whether the action was legitimate or excessive.

Practical implication: log the acting identity, entitlement set, and tenant context for every meaningful agent action.


Threat narrative

Attacker objective: The objective is to exploit over-broad agent access to reach and act on systems or data beyond the intended identity boundary.

  1. Entry occurs when an AI agent is granted access to internal systems, external tools, or sensitive data sources through enterprise authentication flows and delegated credentials.
  2. Escalation follows when authorization is too broad, allowing the agent to read, modify, or invoke more resources than its job requires.
  3. Impact emerges when the agent can perform sensitive actions or expose data within a tenant or system boundary that was never properly constrained.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Access control is the real control plane for agentic security: DLP cannot compensate for an agent that was authorised too broadly at the start. If the agent can already reach internal systems, DLP only observes a subset of the damage path. The practitioner conclusion is straightforward: identity and privilege boundaries must precede content monitoring.

Agentic security exposes an identity governance gap, not just a data protection gap: The problem is not only that AI tools may leak data outward, but that they may be granted excessive inbound authority in the first place. That makes agent identity, entitlement scoping, and tenant isolation the decisive governance issues for the category. Practitioners should treat over-privileged agents as a core access-risk class.

Runtime authorization beats retrospective inspection when the actor can take action: A system that can read, write, or call tools needs policy enforced before the action, not after the content has already moved. This is where access review cadence alone is insufficient, because agent behaviour is defined by live permissions at execution time. The practitioner conclusion is to govern the action path, not just the payload.

Tenant boundaries must be explicit in agent design, or blast radius becomes undefined: Multi-tenant SaaS and internal platforms cannot rely on generic user permissions when the actor is an agent operating across workflows. The right question is not whether the data was sensitive, but whether the identity was constrained to one organisational context. Practitioners should make tenant isolation a first-class agent control.

Agentic access creates a new named risk: identity-led blast radius: When an agent’s entitlement set is too broad, the damage is driven less by what data exists than by what the identity can touch. That shifts security thinking from detection of exfiltration to prevention of excessive reach. Practitioners should map agent permissions to the smallest possible blast radius.

From our research library:

What this signals

Identity-led blast radius: Agentic security needs to be designed around what an agent can reach, not only what it can leak. When authorization is too broad, the meaningful control point moves upstream to identity issuance and entitlement scope, and DLP becomes a secondary detection layer rather than the primary safeguard.

Access reviews alone are a weak fit for agents that act continuously or across many tools. IAM and NHI teams should expect more pressure to prove real-time authorization, tenant isolation, and auditable acting identity rather than rely on after-the-fact inspection of data movement.


For practitioners

  • Define agent identity before tool access Bind every AI agent to a clear enterprise identity, then scope the tools, APIs, and datasets it can reach under that identity. Do not allow a general-purpose agent account to inherit broad user permissions by default.
  • Scope authorization at the resource level Use fine-grained authorization to constrain which records, actions, and tenants an agent can touch. Apply resource-level permissions so the agent can only perform the specific workflow it was created to execute.
  • Log the acting identity and entitlement set Record the user, agent, tenant, and policy context for every meaningful action so investigators can prove whether access was appropriate. Keep these logs tied to the access decision, not only the data event.
  • Treat DLP as a secondary control Use DLP to detect or block sensitive content leaving approved boundaries, but do not rely on it to compensate for excessive agent privilege. The upstream control is authorization, because that is where blast radius is set.

Key takeaways

  • Agentic security fails early when AI agents are granted broad access, because the blast radius is created at authorization time.
  • The article’s core distinction is that DLP observes exfiltration while access control prevents unsafe access in the first place.
  • For practitioners, the priority is to scope agent identity, entitlements, and tenant boundaries before layering on detection controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on over-privileged AI agents and unsafe access scope.
Recommendation — Scope agent identities narrowly and prevent privilege abuse across agent workflows.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governance decisions for agent access and responsibility.
Recommendation — Define accountability for agent access decisions and align them to governance processes.
NIST SP 800-53 Rev 5IA-9 — Service Identification and AuthenticationAI agents and back-end services authenticate to systems through machine identity patterns.
Recommendation — Use service authentication controls to verify non-human actors before granting access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article argues access permissions must be controlled before DLP can help.
Recommendation — Apply entitlement controls to limit what agents and users can access by default.

Key terms

  • Agent Identity: An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities.
  • Authorization Boundary: The authorization boundary is the defined scope of systems, identities, and dependencies that must satisfy a compliance programme. In FedRAMP, it determines what the assessor evaluates and what must be documented as external, so boundary accuracy is a control decision, not a paperwork exercise.
  • Tenant Isolation: Tenant isolation is the practice of separating identities, tokens, sessions, logs, and data so one tenant cannot access another tenant's resources. It can range from full physical or logical separation to carefully controlled shared services with strict tenant-aware policy enforcement.
  • Data Loss Prevention: Data loss prevention is the set of controls used to detect, block, and report sensitive data moving in ways the organisation does not allow. In practice, DLP must account for endpoints, email, cloud apps, APIs, and user behaviour, or it will miss the paths where real exposure happens.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org