By NHI Mgmt Group Editorial TeamBased on C1.ai: “The Identity Stack Was Built for Humans. Agents Don't Care.” (June 4, 2026)

TL;DR: C1.ai argues that identity stacks built for human workflows are failing as AI agents call tools, chain tasks, spawn other agents, and outnumber human identities by more than 80 to 1, while 90% of organisations reported at least one identity-related incident. The governance gap is not login friction but agency control, where lifecycle, scope, attribution, and revocation all need to be rethought for autonomous execution.


At a glance

What this is: This is an analysis of why human-built IAM assumptions break when AI agents act as identities that can call tools, chain tasks, spawn other agents, and outlive human-style review cycles.

Why it matters: It matters because IAM, IGA, and PAM teams now need governance patterns for agentic behaviour, not just human logins or static service accounts.

👉 Read C1.ai's analysis of AI agent identity governance and the human-built stack


Context

The core problem is a governance gap, not a login problem. Existing identity stacks assume a human sits in the loop, while AI agents can initiate actions, chain work, and delegate to other agents without that assumption holding.

For identity teams, this moves the centre of gravity from authentication to agency. The article frames agent identity as a lifecycle, scope, attribution, and revocation problem that current human-first IAM and IGA models do not fully represent.


Key questions

Q: How should security teams govern AI agents that can invoke multiple tools in one session?

A: Security teams should govern AI agents as decision-making identities, not just tool users. That means defining tool access, context scope, and escalation limits together, then monitoring the full execution chain for unexpected combinations of actions. If those controls are split across teams or policies, the agent can move faster than review cycles and create impact before anyone intervenes.

Q: Why do static access reviews fail for AI agent identities?

A: Static access reviews fail because they assume access remains stable long enough to be observed and certified. An AI agent can take actions, shift scope, and complete work inside a very short execution window. By the time a review happens, the risky behaviour may already be over. Identity governance needs runtime signals, not only periodic certification.

Q: What breaks when an AI agent spawns another agent to finish a task?

A: What breaks is attribution and scope containment. Once work is delegated across multiple agents, a single approval no longer maps cleanly to a single actor, and the effective permission boundary becomes the whole chain rather than one account.

Q: How do organisations keep humans accountable when AI agents are doing more of the investigation work?

A: They need a model where agents can investigate and propose actions, but humans still own the judgment calls and the verification standards. The practical guardrail is a system that shows what the agent did, what remains pending approval, and whether the action actually worked. That preserves accountability while reducing manual toil.


Technical breakdown

Why agent identity is not just another service account

Agent identity behaves differently from a human or a conventional workload account because it can decide when to act, what tool to call next, and when to hand work off to another agent. That creates delegation chains rather than single-step access events. In the article's framing, the issue is not merely that agents are automated. It is that they operate with runtime agency, which breaks assumptions embedded in access request, approval, and review workflows. Traditional IAM models answer who authenticated. They do not capture who initiated the chain, who propagated privilege, or when the chain should end.

Practical implication: Treat agent identity as a distinct governance subject, not as a renamed service account.

Why lifecycle controls fail for ephemeral agent identities

Human lifecycle governance assumes an identity persists long enough to be provisioned, reviewed, and later deprovisioned. The article argues that an agent may exist only long enough to complete a task chain, which makes quarterly recertification too slow and offboarding too late. IGA tooling built around durable accounts struggles when identities create themselves, act, and disappear in minutes. The technical problem is not only short duration. It is that lifecycle state can change faster than governance processes can observe it.

Practical implication: Move lifecycle enforcement to issuance and task boundaries instead of relying on later review cycles.

Why revocation and attribution break in chained agent workflows

When one agent spawns another and each step uses different credentials or scopes, revocation becomes a control-plane problem rather than a simple account disablement action. The article's example of a coding agent, deployment agent, and migration agent shows how one human request can fan out into multiple identities and permissions. Attribution also becomes ambiguous because audit trails now have to explain who originated the chain, which agent executed each step, and which credential was active at each hop. Existing logging often records access, but not agency.

Practical implication: Instrument the full delegation chain so revocation and accountability can follow the sequence, not just the final credential.


Threat narrative

Attacker objective: Exploit delegated agent workflows to reach production secrets or other high-value resources without clean human accountability.

  1. Entry occurs when a human asks an AI coding agent to complete a task and the agent begins operating with delegated access. Legitimate access is then expanded as the first agent spawns a deployment agent and a migration agent to continue the work.
  2. Credential and scope use change mid-chain as the migration agent requests production-secret access for a narrowly scoped task. The chain then escapes human-paced review because each step is valid in isolation but not governed as a whole.
  3. Impact appears when the agent chain reaches production resources that were never meant to be reachable through one request path. The article's concern is that a Saturday 2 a.m. production-secret event can happen before anyone can intervene.
  4. The attacker or failure objective is to gain or misuse production access through delegated agent actions that evade normal human review and accountability.
  • Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
  • Poland ArcGIS password leak 2023: An ArcGIS login emailed in 2020 was published from stolen mail in 2023 and still worked, exposing Polish military and infrastructure maps.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI agent governance exposes an assumption collapse in human-first identity design: access review processes were designed for identities that persist long enough to be observed, certified, and removed later. That assumption fails when an agent acquires, uses, and discards access inside a single task chain. The implication is not simply to add more reviews, but to recognise that review-based governance no longer maps cleanly to agentic execution.

Agency, not login, is the new control problem: the article correctly shifts the question from who authenticated to what this identity is allowed to do, on whose behalf, with what scope, and for how long. That is a different governance object from a user account or a static service principal. Practitioners should treat delegation, revocation, and provenance as a single control surface rather than separate IAM tickets.

Ephemeral execution breaks the old lifecycle model: agent identities that self-create and self-destruct undermine the joiner-mover-leaver assumptions behind IGA. Quarterly access reviews and periodic recertification were never built for identities that may exist for seconds or minutes. The practical conclusion is that lifecycle governance for agents has to be bound to task orchestration and issuance events, not calendar time.

Attribution becomes a chain problem, not an account problem: once one agent spawns another, the meaningful unit of accountability is the delegation path, not the final credential label. A log line that says a service account acted is not enough to explain the human request, the intermediate agent decisions, or the scope propagation that followed. Security teams need identity graphs that preserve provenance across the full chain.

AI Access Management is a useful concept, but only if it is grounded in governance reality: the article's proposed category makes sense because agents need legitimate, governed ways to act. The field should not confuse that with another wrapper around existing IAM controls. Practitioners should use it to force a design discussion about agency, not just another policy layer.

What this signals

AI Access Management is becoming a distinct governance requirement: once agents can initiate, delegate, and self-terminate work, classic IAM no longer covers the full control problem. Programme owners should expect pressure to separate human authentication, workload identity, and agent authority into different governance layers.

Existing access review cycles will not surface agent behaviour that exists only inside a task window. Security teams should assume that issuance-time policy, provenance capture, and chain-aware revocation will matter more than periodic certification for agentic workflows.


For practitioners

  • Instrument agent delegation chains Capture which tools each agent calls, which credentials it uses, who originated the chain, and when control passes from one agent to another.
  • Redesign lifecycle governance for ephemeral identities Move from calendar-based recertification to issuance-time controls that can govern identities that create and destroy themselves within a single task.
  • Separate agency scope from human role scope Define task-bounded, time-bounded, and blast-radius-bounded access for agents instead of inheriting coarse human roles.
  • Build revocation that can stop one agent without collapsing the chain Test whether your controls can revoke a single agent's access mid-execution without breaking unrelated automation or leaving orphaned permissions behind.
  • Unify accountability across the identity graph Tie audit evidence to the full delegation path so investigators can see the human request, intermediate agent actions, and final resource access in one timeline.

Key takeaways

  • The article argues that human-built IAM assumptions fail when agents can call tools, chain tasks, and delegate work without a person clicking through each step.
  • The main governance gap is not authentication but control over agency, lifecycle, attribution, and revocation across chained agent actions.
  • Security teams need issuance-time controls and delegation visibility if they want to govern AI agents before they touch production secrets or other high-value resources.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe article centres on agent identity, delegated privilege, and chained actions.
ASI10 — Rogue AgentsThe article warns that agents can spawn other agents and operate beyond human-style review.
Recommendation — Map agent delegation and privilege exposure to ASI03 and constrain each step to task-specific authority. Monitor for uncontrolled agent spawning and block unsanctioned autonomous execution paths.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article highlights that agent identities may self-destruct or persist outside normal offboarding models.
NHI-05 — Overprivileged NHIThe article argues that RBAC is too coarse for task-bounded agent access.
NHI-10 — Human Use of NHIThe article focuses on humans initiating actions that agents execute on their behalf.
Recommendation — Design offboarding controls that can revoke agent authority when tasks end or delegation changes. Reduce agent privilege to the narrowest task scope and avoid inheriting human roles. Record human origin and delegated authority for every agent action that affects production access.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe post is fundamentally about governing AI agent authority and accountability.
Recommendation — Establish governance for who can authorise agent action, delegation, and revocation.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article's core issue is controlling permissions as agents move through delegated workflows.
Recommendation — Apply entitlements management to ensure agent permissions are explicit, scoped, and time-bound.

Key terms

  • AI Access Management: AI Access Management is the governance layer that controls which AI clients, assistants, and agents can reach enterprise tools and data. It combines entitlement requests, policy enforcement, logging, and review so AI use is governed through identity controls rather than ad hoc exceptions.
  • Agency: Agency is what an identity is allowed to do, on whose behalf, with what scope, and for how long. For autonomous or semi-autonomous systems, this is more important than login status because the control problem is about delegated action, not mere authentication.
  • Delegation Chain: A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly.
  • Dynamic Ephemeral Identity: Dynamic Ephemeral Identity is a model in which credentials or authority exist only for a short operational window and are generated at runtime. It reduces the value of exposed secrets, but only if the environment can also limit what the identity is allowed to do while active.

What's in the full article

C1.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The article's four failure modes laid out as a practitioner checklist for identity, scope, attribution, and revocation.
  • The agency model the author proposes for governing agents as identities that act on behalf of humans.
  • The visibility-first approach recommended for instrumenting tool calls, credential use, and chain origin.
  • The author's view of how a unified identity graph should represent humans and agents together.

👉 The full C1.ai post expands on lifecycle failure modes, attribution gaps, and the proposed AI Access Management model.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org