TL;DR: GitGuardian frames AI agent governance, secrets security, and workflow integration as the central topics for CISOs and senior leaders at the October 5 to 7 Scottsdale summit. The practical question is no longer whether agentic systems create risk, but how identity, secrets, and access governance keep pace with operational deployment.
At a glance
What this is: This is an event page for Innovate Scottsdale 2026 that positions AI agent governance, secrets security, and developer workflow integration as the main discussion themes.
Why it matters: It matters because identity teams need to align governance, secrets handling, and access boundaries before agentic systems spread deeper into cloud-native and hybrid operations.
👉 Register for GitGuardian's Innovate Scottsdale event page on AI agent governance
Context
AI agent governance is the discipline of deciding who or what can act, what it can access, and how those decisions are reviewed across runtime systems. In this event context, the governance gap is that agentic systems do not fit neatly into human-centric IAM or static NHI controls, especially when they span development and production environments.
GitGuardian’s event page positions that gap as a CISO-level concern rather than a developer tooling topic. The practical question is how to manage secrets, non-human identities, and workflow access when decision-making becomes more dynamic and operationally distributed.
Key questions
Q: How should security teams govern agentic AI as it moves into production?
A: Security teams should govern agentic AI as a class of non-human identity, not as a generic application feature. That means assigning ownership, scoping permissions tightly, logging every tool action, and revoking access on a defined lifecycle. Production rollout should require clear approval points for high-risk actions and continuous monitoring for drift.
Q: When do secrets become a higher risk in agentic AI environments?
A: Risk rises when autonomous systems can copy, reuse, or trigger credentials across multiple tools and workflows. At that point, one exposed secret can support repeated machine execution rather than a single human action. Teams should assume faster exploitation and stronger amplification when AI agents are involved.
Q: What breaks when agent permissions are designed like traditional IAM roles?
A: Traditional roles assume access patterns stay stable long enough to be reviewed and certified. Agentic systems can change tasks, tools, and timing inside one work session, so static role design often fails to reflect the real decision path.
Q: Should teams integrate agent governance into developer workflows or keep it separate?
A: Integrate it into the workflow. If controls sit outside the path where code, secrets, and agents interact, teams will lose either adoption or assurance. Governance works best when policy checks are visible at the point of execution.
Background and context
Why AI agent governance is different from standard NHI control
AI agent governance differs from standard NHI control because the subject is not just a credential or service account, but a runtime actor that may select actions, touch multiple tools, and cross environment boundaries during one task. That changes the governance problem from static permissioning to decision-scoped authorisation, where access context matters as much as identity binding. In practice, the control question becomes whether the environment can constrain what the agent may do, when it may do it, and how those decisions are audited.
Practical implication: define governance boundaries at runtime, not only at provisioning time.
Secrets management across development and production systems
Secrets management remains central because AI agents often sit close to code, pipelines, and production access paths. The operational risk is not only secret leakage, but also secret reuse across environments that makes attribution and offboarding difficult. When a machine or agent can invoke tools across the software lifecycle, the estate needs clearer ownership, tighter scoping, and faster revocation than many legacy vault practices assume.
Practical implication: separate development and production secrets handling so agent access cannot drift across both.
Integrating security into developer workflows without losing control
Embedding security into developer workflows only works when governance stays visible at the point of action. If identity checks, secret controls, and approvals live far from where code and agents operate, teams get speed without assurance. The useful architecture is one where developer tooling, agent permissions, and secrets policy reinforce each other rather than create parallel control planes that no one can reconcile later.
Practical implication: place identity checks where developers and agents already work, not in a detached review layer.
NHI Mgmt Group analysis
AI agent governance is now a CISO agenda item, not a specialist side topic. The event framing shows that agentic systems are being discussed alongside senior security priorities such as secrets security and operational control. That matters because governance will fail if it is left inside isolated platform teams instead of being folded into enterprise identity decision-making. The practitioner conclusion is that CISO ownership is now part of the control model.
Secrets and non-human identity controls are converging around the same runtime problem. The event page links secrets management, NHI governance, and developer workflow integration in one conversation. That is the right shape for the market because agents do not respect the old separation between app runtime, pipeline, and production access. The practitioner conclusion is that access, secret, and workflow controls need a shared governance view.
Operationalising agentic AI will expose the limits of static permission thinking. Access decisions for autonomous or semi-autonomous systems cannot rely on one-time provisioning assumptions when the work itself is dynamic. This is where the identity blast radius becomes the decisive concept: the question is not only who can authenticate, but how far that authentication can travel across tools and environments. The practitioner conclusion is to govern reach, not just login.
Developer workflow integration is where agent governance either becomes usable or breaks down. If controls are bolted on after the fact, teams will route around them in the name of delivery speed. If controls are too rigid, the business will ignore them. The challenge is to make policy enforceable inside the workflow path without turning every agent action into an exception process. The practitioner conclusion is to design for governed velocity, not abstract assurance.
From our research library:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Maturity Model
What this signals
Identity blast radius: when agentic systems can touch code, credentials, and production services in one workflow, governance has to measure how far one authenticated action can propagate. That is a stronger programme metric than counting logins or reviewing static roles after the fact.
Agentic AI pushes identity teams toward runtime authorisation and away from purely periodic review. Access decisions need to be visible where agents act, because post hoc certification cannot explain a sequence that already completed inside a single task.
Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey. That gap suggests governance is still lagging operational rollout.
For practitioners
- Map agent touchpoints across workflows Identify where agentic systems touch code, tickets, CI/CD, cloud consoles, and production data so you can see where identity decisions are actually being made.
- Separate secrets by environment and task Review whether development, staging, and production credentials are still reused by the same automated paths, then scope them so one agent task cannot traverse all three.
- Define approval boundaries for runtime actions Document which agent actions require human approval, which are pre-authorised, and which must be blocked entirely before deployment reaches production use.
- Add auditability to agent access paths Make sure logs capture the agent identity, the credential source, the tool invoked, and the downstream system touched so governance can be reviewed after execution.
Key takeaways
- AI agent governance is moving into the CISO remit because agentic systems sit at the intersection of identity, secrets, and workflow control.
- The central risk is not just exposure of a credential, but the expansion of that credential’s reach across environments and tools.
- Practitioners need runtime boundaries, separate secret scopes, and auditable agent actions before agentic deployment outpaces governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The event centers on agent governance and runtime access boundaries for AI agents. |
| Recommendation — Apply ASI03 to bound agent privileges and review every tool path an agent can invoke. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The page explicitly raises secrets security as a core discussion topic. |
| NHI-05 — Overprivileged NHI | Agentic systems can accumulate access across cloud-native and hybrid environments. | |
| Recommendation — Use NHI-02 to reduce secret exposure across agent workflows and production systems. Use NHI-05 to scope non-human access to the minimum set of actions required by the workflow. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article frames AI agent governance as a CISO-level accountability issue. |
| Recommendation — Establish governance ownership for AI agents before deployment expands across teams and environments. | ||
Key terms
- AI Agent Governance: AI Agent Governance is the set of policies, controls, and oversight practices used to direct how autonomous software agents behave. It defines allowed actions, approval paths, identity boundaries, logging, monitoring, and accountability so agent decisions remain traceable, constrained, and aligned with business, security, legal, and ethical requirements.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Runtime Authorisation: Runtime authorisation is the practice of deciding access while a task is in progress, rather than only at provisioning time. It matters for NHIs because credentials and entitlements can change risk mid-session, especially when automation or AI agents interact with sensitive systems.
- Secret Scope: Secret scope is the boundary that defines where a credential can be used and what it can change. Narrow scope reduces blast radius, but only if the credential cannot be copied into other jobs, logs, or repositories. In pipelines, scope should match a single purpose and a single release path.
What to expect at the briefing
GitGuardian's full event page covers the practical event details this post intentionally leaves out:
- Booth and meeting context for CISO and senior security conversations at Innovate Scottsdale
- The summit’s networking and session format, including how the event is structured for focused discussions
- The event’s location and dates for teams deciding whether to attend in person
- The registration path and event logistics for readers planning to join the summit
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on May 14, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org