By NHI Mgmt Group Editorial TeamBased on WorkOS: “Identity for AI: Who Are Your Agents and What Can They Do?” (June 13, 2025)

TL;DR: AI agents need broad, persistent, delegated access across multiple tools, but traditional machine-to-machine authentication, RBAC, and human-centric login patterns do not match their unpredictable runtime behaviour, according to WorkOS. The core problem is assumption collapse: identity models built for stable, reviewable access cannot govern actors that act, escalate, and chain delegation in-flight.


At a glance

What this is: This is an analysis of why AI agent identity breaks existing IAM assumptions, especially around login flows, least privilege, delegation, and auditability.

Why it matters: It matters because IAM teams must govern agent access without pretending agents behave like humans or static service accounts, especially when they span multiple tools and approval paths.


Context

AI agent identity is the problem of giving software that acts on behalf of people a verifiable identity, scoped access, and an audit trail that matches how it actually behaves. Traditional IAM models assume the actor is either a human user with a login flow or a service with narrow, predictable machine-to-machine access.

WorkOS argues that AI agents sit between those models and break both. They need to operate across production databases, SaaS tools, and delegated workflows, but their actions are non-deterministic and can extend across multiple invocations, sub-agents, and systems.

That is why this topic belongs squarely in identity governance, not only application architecture. The issue is not just how to authenticate an agent, but how to govern delegation, scope, accountability, and revocation when the actor is neither purely human nor purely static infrastructure.


Key questions

Q: What breaks when AI agent access is managed like standard IAM access?

A: What breaks is the assumption that access is stable, reviewable, and tied to a single human owner. AI agents can call tools, change scope, and execute within runtime workflows, so standard IAM review cycles may miss the real moment of risk. Governance needs to move closer to execution and delegated authority.

Q: Why do capability tokens reduce risk for AI agent access?

A: Capability tokens narrow an agent’s authority to a specific task, time window, and delegated context. That reduces blast radius compared with role-based access that can persist well beyond the job. They also make it easier to revoke rights cleanly when the task ends or the delegation changes.

Q: How do you know if agent delegation is becoming ungoverned?

A: The warning signs are missing hop-by-hop attribution, shared service accounts across multiple agents and logs that show actions without the initiating user or top-level agent. If you cannot reconstruct who authorised each step, the delegation chain is already too opaque.

Q: How should security teams govern AI agents that use multiple identity layers?

A: Security teams should inventory every identity layer an agent can use, including static credentials, session identities, embedded tool identities, and any delegated relationships between agents. Governance fails when one layer is controlled while another remains open, because the agent can still act through the weaker path. Treat the layered identity surface as the actual access boundary.


Technical breakdown

Why traditional authentication fails for AI agents

Traditional authentication assumes a user can complete a login flow or a service can present a fixed machine credential to a known endpoint. AI agents often cannot do either cleanly. They may run headless, operate across multiple systems, and need credentials that survive across invocations without turning into standing access. That makes the old split between human SSO and machine-to-machine auth too narrow. In identity terms, the agent is an executable actor with shifting tool needs, not a static client with a fixed trust boundary. The governance problem starts when authentication is treated as the whole answer, because the hard part is authorising and tracing what the agent may do after it is authenticated.

Practical implication: design agent authentication as only the entry point, then govern issued rights, session scope, and revocation separately.

Capability tokens and persona shadowing

Capability-based tokens narrow access to a task-specific right, such as reading a calendar for 60 minutes, instead of giving an agent broad standing permissions. Persona shadowing goes one step further by giving the agent its own identity that is linked to, but distinct from, the human delegator. That matters because it preserves attribution while reducing the temptation to let agents impersonate users directly. The model is closer to delegated authority than shared credentials. For IAM and IGA teams, this is a structural change: the control point moves from who owns the account to what the token allows, for how long, and under which delegated context.

Practical implication: issue task-scoped capabilities rather than copying user access into an agent account or shared service identity.

Delegation chains create audit and accountability gaps

Once an agent calls another agent or service, the trust model becomes a delegation chain rather than a single session. Each hop must preserve the original authority, or the chain becomes opaque and hard to investigate. This is where audit logging, SIEM correlation, and entitlement review start to fail if they still assume a one-identity, one-action model. The article’s core insight is that agents do not just consume access. They propagate it. That means identity evidence must survive across sub-agents, tool calls, and intermediate services if organisations want meaningful accountability and post-event reconstruction.

Practical implication: preserve end-to-end delegation context in logs and access records so agent-driven actions remain attributable across hops.


NHI Mgmt Group analysis

AI agent identity is an assumption-collapse problem, not a simple authentication problem. Traditional IAM assumes access can be predefined, reviewed, and bounded before execution begins. That assumption fails when an actor can decide at runtime which tools to call, which privileges to request, and whether to spawn additional delegated work. The implication is that identity governance must stop treating the login event as the primary control boundary.

Persona shadowing is more defensible than user impersonation for agent governance. When an agent acts under its own identity, tied to a delegating user, accountability survives even when the agent spans multiple systems. This aligns with delegated authority patterns and avoids collapsing human and machine identities into one ambiguous actor. Practitioners should treat the agent as a governed identity in its own right, not as a disguised employee account.

Capability tokens define the right control plane for agent access. Agents often need rights that are narrower than a user role but broader than a single API call, which makes role-based models too coarse. Time-bound, self-contained capability tokens are a better fit because they express task authority directly. The practitioner conclusion is that entitlement should be expressed as temporary capability, not durable role membership.

Delegation chains are now an identity governance surface. Once an agent can spawn sub-agents or call other services, the organisation is no longer governing one session but a chain of inherited authority. That chain must remain visible for audit, investigation, and policy enforcement. The practical conclusion is to govern delegation as a first-class identity object, not as a side effect of application architecture.

AI agent growth will force IAM, IGA, and PAM teams to converge on a single governance model. The article points to a future where agents exist for minutes or months, interact with dozens of systems, and generate far more events than human users. That means access review, approval, and revocation cannot remain human-centric process variants. Practitioners should rework lifecycle governance so agent identities are created, scoped, observed, and retired with explicit machine and delegation semantics.

From our research library:

What this signals

Identity review must move closer to issuance time. Access reviews assume the privilege being reviewed still exists long enough to be observed, certified, and removed. AI agents can acquire and release access inside a single task, which means governance has to shift from periodic review to pre-issuance control and live delegation visibility.

Agent identity creates a new governance boundary between workload identity and human IAM. The same lifecycle discipline still applies, but the actor is not a person and not a static service account. Programmes that keep agent rights inside ordinary RBAC without distinct attribution will lose both audit clarity and revocation precision.

Capability tokens become the practical expression of least privilege for agents. Task-specific rights are easier to audit than broad role grants, especially when delegation spans multiple tools and sub-agents. That is the control pattern most likely to hold up when agent activity becomes a normal operating state.


For practitioners

  • Define agent identities separately from human users Create distinct identities for agents so every action is attributable without relying on user impersonation or shared credentials. Link the agent to a delegating user or workflow context, but keep the agent’s own subject, policies, and logs separable.
  • Use task-scoped capability tokens Issue time-bound rights that describe a specific job, such as read-only access to a calendar or a single workflow step, instead of broad roles that outlive the task. Revoke or expire the capability as soon as the action is complete.
  • Track delegation chains end to end Record the original delegator, every intermediate agent or service, and the final action target so audit teams can reconstruct how authority moved across the chain. Preserve this context in logs, SIEM correlation, and investigation workflows.
  • Separate authentication from authorisation Treat successful agent authentication as the start of governance, not the end. Define what the agent may do, where it may act, and what conditions trigger human approval before execution crosses a sensitive threshold.
  • Design lifecycle controls for ephemeral and persistent agents Apply joiner-mover-leaver logic to AI agents with explicit creation, change, review, and retirement states. Some agents may exist for minutes and others for months, so governance must cover both short-lived and long-running identities.

Key takeaways

  • AI agents expose a governance gap because they do not fit cleanly into either human login models or static machine credentials.
  • The article argues for separate agent identities, task-scoped capabilities, and preserved delegation context so actions remain attributable.
  • For IAM and IGA teams, the most important shift is moving control from periodic review of standing access to issuance-time governance of delegated authority.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAgent access scope, delegation, and privilege are the central governance issues in the article.
Recommendation — Model agent delegation and privilege boundaries under ASI03 so runtime authority stays visible and bounded.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on agents needing broader access than traditional machine identities were designed to hold.
Recommendation — Scope agent credentials to the minimum task authority and avoid persistent over-privileged access.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governance for AI actors that make runtime decisions and affect accountability.
Recommendation — Establish governance ownership for agent identity, delegation, and accountability under GOVERN.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on how permissions and authorisations should be shaped for agent identities.
Recommendation — Align agent entitlements with PR.AA-05 by enforcing explicit authorisation and scoped permissions.
NIST Zero Trust (SP 800-207)Principle 3 — Verify explicitlyAgent actions across tools require continuous verification of who or what is acting and with what authority.
Recommendation — Apply explicit verification at each delegated step instead of trusting inherited access by default.

Key terms

  • AI Agent Identity: The digital identity used by an autonomous AI agent to authenticate to external systems, APIs, and services. Managing AI agent identities is an emerging and rapidly evolving area of NHI security.
  • Capability Token: A short-lived credential that grants a narrow, explicit right for a single task or action. Unlike a broad role, it encodes what the agent may do, for how long, and often where. This makes it better suited to unpredictable agent work and easier to revoke when the task ends.
  • Persona Shadowing: A pattern where an AI agent acts under its own identity while remaining linked to a human delegator. This preserves attribution, revocation, and auditability. It is more defensible than direct impersonation because the agent is governed as a separate subject with scoped authority.
  • Delegation Chain: A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org