By NHI Mgmt Group Editorial TeamBased on Opnova: “Joiner for AI Agents: The Workforce Nobody Hired” (May 19, 2026)

TL;DR: AI agents are entering enterprises with no owner, approval record, or access review, according to Opnova, while one survey found 74% of organisations already run credentialed AI agents or automations and 5% of security leaders cannot confirm whether agentic AI is present. Joiner governance breaks when identity is issued before ownership and classification exist, so access control must start at provisioning.


At a glance

What this is: This blog says AI agent joiner workflows fail because agents are being provisioned as ad hoc credentials rather than governed identity objects with ownership, classification, and review.

Why it matters: IAM, IGA, and PAM teams need to treat AI agents as first-class identities or they will miss orphaned access, over-privilege, and segregation-of-duties gaps at the point of issuance.

By the numbers:

  • 74% of organisations are already running AI agents or automations that require credentials.
  • 5% of security leaders cannot confirm whether agentic AI is running in their environment at all.
  • AI agents and other non-human identities grew 44% year-over-year between H1 2024 and H1 2025.
  • Non-human identities now outnumber human identities 144 to 1 in the average enterprise.

Context

AI agent joiner governance breaks when an organisation treats an agent like a credential instead of an identity subject. The article argues that provisioning often happens at engineering speed, before ownership, classification, or approval are recorded, which leaves IGA, PAM, and access review processes unable to see the actor they are meant to govern.

That gap matters most in regulated industries where the joiner problem meets SoD, auditability, and lifecycle control. The article’s central claim is not that agents are unusual, but that current identity workflows assume a human hiring model and fail when applied to non-human identities that can be created, modified, and deployed outside standard HR-driven controls.

The article positions joiner governance as the first point of failure in the broader identity lifecycle for AI agents. Once the front door is open without inventory, ownership, and scope definition, the rest of the governance model has to compensate after the fact, which is exactly the wrong sequence for high-velocity machine identities.


Key questions

Q: What breaks when AI agents are added to joiner workflows without ownership and approval?

A: The joiner model loses its core governance anchors. Without a named owner, a record of approval, and a system entry for the identity, access is granted to an actor that no one can later certify, review, or offboard cleanly. That makes inventory gaps and orphaned access inevitable.

Q: Why do service accounts and AI agents create different identity risk than employees?

A: Service accounts and AI agents create different risk because they are not managed through HR lifecycle events, yet they often hold broad technical permissions and can act at machine speed. That makes ownership, monitoring, and revocation harder to sustain with human-centric controls. Risk rises when their access is persistent, poorly documented, or spread across multiple platforms.

Q: How do security teams know if an AI agent has too much access?

A: Look for agents that can reach multiple systems without task-specific limits, use persistent tokens, or touch high-value services such as email, chat, cloud consoles, and file stores. A healthy deployment leaves a clear audit trail of what the agent can do, what it actually did, and which credentials it used.

Q: What should teams check before putting an AI agent into production?

A: Teams should verify three things before production: the agent has a unique identity, its permissions are minimal and explicitly approved, and its actions are fully auditable. They should also confirm that any privacy control used for analytics is layered on top of, not instead of, the access model.


Technical breakdown

Why AI agent joiner workflows fail in enterprise IAM

Human joiner processes depend on a stable sequence: request, approval, record creation, entitlement assignment, and review. AI agents often bypass that sequence because the credential is issued by an engineer, a pipeline, or a platform integration before any authoritative system records the identity. That creates an identity object without a reliable owner, purpose, or lifecycle state. In practice, the agent may be authenticated to code repositories, SaaS apps, or downstream systems while remaining invisible to the systems that would normally enforce joiner governance. The failure is structural, not procedural: legacy IAM assumes the joiner event is initiated by business onboarding, not by software deployment.

Practical implication: treat agent provisioning as an identity-creation event, not a config change.

How standing privilege and scope creep appear at birth

Joiner failures for AI agents are often present on day one, not after a later compromise. The article describes credentials being pasted into CI/CD configs, OAuth scopes inherited through directories, and agents inheriting access from the user who approved them. That means the initial entitlement set can be far broader than the task requires, especially when the approving human has more access than the agent should ever need. In NHI terms, this is over-privilege at creation time, compounded by long-lived secrets and unclear ownership. Once the agent is live, the governance issue is not just access size but the absence of a defensible baseline against which later review can operate.

Practical implication: define birthright access by use case and classification before any credential is minted.

Why segregation of duties breaks when agents join outside HR

Segregation of duties depends on the governance system knowing who is allowed to request, approve, and execute sensitive actions. The article shows how an agent can be given both read and action capability, such as viewing financial data and initiating transfers or writing code and approving deployment. That collapses a core control because the entitlement model never sees the agent as a separate subject with its own conflict rules. The result is not just excess privilege but a broken approval chain. For IGA, the deeper issue is that SoD is being applied to workflows designed for human roles, while the real actor is a machine identity with no HR anchor.

Practical implication: enforce SoD at provisioning for every AI agent that can both observe and act.


Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI agent joiner governance is now an identity problem, not a tooling problem. The article shows that agents are appearing without the basic governance artefacts that make joiner controls work for humans: owner, purpose, approval, and record of hire. That means the enterprise is creating machine identities faster than it can classify them. The practitioner conclusion is simple: if the identity cannot be named, owned, and scoped before issuance, it should not enter production.

Joiner controls built for HR-fed identities collapse when provisioning is driven by engineering workflows. Human onboarding assumes an authoritative source, a stable manager, and a predictable review cycle. Agents arrive through pipelines, app settings, and delegated OAuth consent, which makes the joiner event invisible to traditional IGA. The practical takeaway is that governance has to move upstream to the moment of credential creation, because post-provisioning review is already too late for many agent use cases.

Ephemeral AI agent trust debt: the article describes a pattern where access is granted first and ownership is documented never. That is not a policy gap in the abstract; it is a broken assumption that identity state will exist long enough to be audited. When the actor is an AI agent, the problem is compounded because scope can change faster than an access review cycle. The implication is that identity governance must be designed around issuance-time control, not retrospective certification.

Regulated industries will feel the joiner failure first because auditability is the first control to disappear. Banks, insurers, healthcare systems, and critical infrastructure operators cannot rely on informal visibility when agents are created by engineers and inherited through cloud permissions. The article correctly places inventory, ownership, and SoD at the centre of compliance readiness. Practitioners should expect regulators to ask for the same evidence they already expect for human access, only with far weaker current answers for agents.

AI agent lifecycle governance will become the next separating line between mature and immature identity programmes. The article frames joiner as the first part of a larger lifecycle problem, and that is the right signal. Once agents exist, mover and leaver controls determine whether scope drift, model updates, and vendor changes are governed or simply accumulate risk. The implication for identity teams is to build lifecycle handling for AI agents as a distinct subject, not as a variation of human onboarding.

From our research library:

What this signals

AI agent joiner governance is moving from edge case to baseline control. The article’s core warning is that identity teams can no longer assume onboarding is a human process with an HR anchor. When agents are created through engineering and platform workflows, the governance boundary shifts to issuance time, where ownership, approval, and scope must already exist.

Identity blast radius starts at provisioning, not at compromise. A joiner process that issues credentials before classifying the agent creates immediate exposure, because every downstream entitlement inherits that mistake. The practical response is to make creation, inventory, and entitlement aggregation part of the same control plane rather than separate operational steps.

Agent lifecycle discipline will separate governed enterprises from visible-but-uncontrolled ones. Agentic AI Identity Guide is relevant here because the same lifecycle logic applies from joiner through mover and leaver. If an organisation cannot answer who owns each agent and why it exists, it does not yet have a governable agent estate.


For practitioners

  • Define AI agents as first-class identity subjects Create a distinct identity record for every agent with owner, purpose, deploying platform, classification tier, and lifecycle state before any credential is issued.
  • Gate provisioning on named human approval Require a named human owner to approve the agent before the service account, API key, or OAuth grant is created. If no accountable owner exists, do not provision the agent.
  • Set birthright access by classification tier Use risk tiers to limit initial access for customer-facing or production-touching agents, and keep internal agents on a narrower default scope until their task is confirmed.
  • Aggregate entitlements from day one Continuously pull agent entitlements from connected systems so the IGA tool sees actual access, not self-reported intent or stale onboarding data.
  • Enforce segregation of duties before go-live Block any agent that can both read sensitive data and execute high-impact actions unless the SoD conflict is resolved at provisioning time.

Key takeaways

  • AI agent joiner failures happen when identity is issued before ownership, approval, and classification exist.
  • The article shows that human IAM patterns do not reliably handle machine identities created through engineering and platform workflows.
  • Governance has to move to provisioning time, with inventory and SoD checks in place before any agent credential goes live.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article frames AI agents as identities that lack a governed lifecycle from the start.
NHI-05 — Overprivileged NHIThe article repeatedly describes broad birthright access and inherited scopes for agents.
NHI-07 — Long-Lived SecretsThe joiner pattern relies on issued credentials that often persist without lifecycle control.
Recommendation — Register every AI agent before issuance and tie it to a named owner and lifecycle state. Limit initial AI agent access to the minimum scope needed for the declared task. Reduce standing agent credentials by issuing short-lived secrets and tracking their renewal.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe article describes agents gaining broad access that can be reused across connected systems.
Recommendation — Map agent credential exposure to credential access and limit reach across downstream systems.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsJoiner governance hinges on who can authorise and receive agent access.
Recommendation — Apply PR.AA-05 to verify agent entitlements before production access is granted.

Key terms

  • AI Agent Governance: AI Agent Governance is the set of policies, controls, and oversight practices used to direct how autonomous software agents behave. It defines allowed actions, approval paths, identity boundaries, logging, monitoring, and accountability so agent decisions remain traceable, constrained, and aligned with business, security, legal, and ethical requirements.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org