By NHI Mgmt Group Editorial TeamBased on Cyera: “96% of Enterprise Permissions Go Unused. AI Agents Won't Leave Them That Way.” (March 27, 2026)

TL;DR: 96% of enterprise permissions go unused, while static profiles, broad admin assignments, and dormant entitlements leave a large hidden access surface that AI agents can inherit and actively exercise at machine speed, according to Cyera research. Access governance now has to assume unused rights are still operationally real.


At a glance

What this is: This research argues that enterprise permissions are far more dormant than most organisations assume, and that AI agents turn that unused access into an immediate governance problem.

Why it matters: IAM, NHI, and PAM teams need to treat unused privilege as latent exposure, because agentic systems can operationalise permissions that human users rarely touch.

By the numbers:

  • 96% of enterprise permissions go unused in the environments Cyera Research analysed.
  • Only 4 in 100 workers take any action at all in most enterprise applications over a 90-day period.
  • More than 80% of access is managed through static permission profiles across enterprise SaaS environments.
  • Some environments assigned admin privileges to nearly 30% of users, far above the 2% to 5% governance benchmark.

Context

Enterprise permissions management is the discipline of deciding who or what can do what inside business systems, and this article shows that most organisations are carrying far more access than they actually use. The core issue is not theoretical over-provisioning but dormant privilege that remains live, functional, and ready to be exercised.

That matters because AI agents do not behave like human users. When an agent inherits a permission set, it can call APIs continuously and consume the full technical scope of access, not just the small slice a person typically uses. The result is a governance problem that sits squarely at the intersection of human IAM, PAM, and non-human identity control.


Key questions

Q: What should teams do when most permissions go unused but still remain active?

A: Treat unused access as live exposure, not harmless clutter. Measure exercised permissions separately from granted permissions, then remove dormant rights before they can be inherited by an agent, automation, or compromised account. This is especially important where static profiles and broad overrides make the maximum technical scope much larger than normal human behaviour suggests.

Q: Why do AI agents and copilots create more risk when they inherit broad enterprise permissions?

A: AI agents and copilots create more risk when they inherit broad enterprise permissions because their access can extend beyond their business purpose. If an AI system can read files, call APIs, or modify records, excessive privilege turns a useful automation into a high-impact exposure path. The danger is not only what the AI says, but what it can retrieve, decide, and do.

Q: Where do enterprise permissions fail when they are mapped to agents?

A: They fail at the point where a permission model assumes human restraint. Access profiles, administrative overrides, and long-lived entitlements are often designed around a person who uses only a fraction of what they hold. An agent inherits everything technically available, so the failure is not just over-provisioning but a mismatch between governance assumptions and execution behaviour.

Q: What should security teams do first if Salesforce access has never been formally reviewed?

A: Start with the highest-risk permissions. Verify that only administrators have the System Administrator profile, then map who can view and edit sensitive data across roles and permission sets. From there, tighten access to the least privilege needed for each job function. That sequence gives the fastest reduction in exposure without waiting for a full redesign.


Technical breakdown

Why dormant enterprise permissions stay live

Enterprise systems often accumulate access through static permission profiles, role expansion, and integration sprawl. A profile is a bundled set of permissions assigned once, then left in place long after the original job need changed. That creates a structural gap between designed access and exercised access. In the article's data, the majority of permissions are never touched, yet they remain technically usable. From an identity standpoint, that means access recertification is often reviewing theoretical rights rather than actual behaviour.

Practical implication: audit exercised access separately from assigned access so dormant entitlements can be removed without waiting for an annual review.

How AI agents change permission risk

AI agents are not human users with slower habits. They can execute continuously, invoke APIs directly, and apply the full permission scope of the identity they inherit. That turns dormant access into active exposure because the agent does not preserve human restraint or routine. In NHI terms, the inherited identity becomes the control plane, and overbroad entitlements become immediately operational. The important distinction is not that the agent is smart, but that it is capable of using access at machine speed without natural pause points.

Practical implication: give agents dedicated identities with narrowly scoped permissions instead of reusing human accounts or broad profiles.

Why broad platform permissions become the real blast radius

The article's Salesforce example illustrates a broader pattern in enterprise platforms: a few permissions can override the normal sharing model and expose far more data than teams expect. View All Data and Modify All Data are effectively blast-radius multipliers because they collapse row-level and role-based boundaries into platform-wide access. When those permissions persist beyond their original justification, the issue is not just excess privilege but a governance model that no longer matches business reality. That is especially dangerous when autonomous tooling can act on the account without the friction humans normally introduce.

Practical implication: identify permissions that override normal access boundaries and review them before enabling any non-human workload on the platform.


Threat narrative

Attacker objective: The objective is to weaponise inherited enterprise permissions so an AI agent can reach, alter, or export sensitive data at scale.

  1. Entry occurs when an attacker places malicious instructions inside content or integrations that an agent processes, rather than needing stolen credentials.
  2. Credential and permission abuse follows when the agent inherits a user's broad access scope and can execute actions the human never normally performs.
  3. Impact lands when the agent is induced to use dormant permissions at machine speed, turning unused access into data exposure, modification, or deletion.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Dormant privilege is now active risk, not idle inventory. The article shows that most enterprise access goes unused, but unused does not mean harmless when the same permissions can be inherited by an AI agent. This is where traditional access governance fails as a planning model, because dormant entitlements are still technically live and immediately usable. The practitioner conclusion is that access depth matters less than the ability to execute it.

Static permission profiles create an identity blast radius that humans used to mask. Human behaviour has historically limited the effect of over-broad access because people do not consume every permission they receive. AI agents remove that behavioural brake. The result is a permission model whose effective risk is defined by maximum technical scope, not typical human use. That means entitlement design has to be judged by worst-case machine execution, not average human habit.

Human review cadences do not protect machine-consumable access. Access review processes were built around the assumption that privilege persists long enough for a person to inspect it. An AI agent can inherit, use, and exhaust those permissions inside operational windows that review cycles never see. The implication is not simply tighter review, but a rethinking of whether review remains the right control point for agent-bound access at all.

Permission governance is becoming a data governance control. The Salesforce case in the article makes clear that overly broad permissions are no longer just IAM hygiene issues. They determine whether regulated data, customer records, and modification rights are available to systems that operate continuously. That shifts the control conversation from who was granted access to what an agent can do with inherited authority. Practitioners should treat entitlement scope as a direct determinant of data exposure.

Identity blast radius is the right named concept for this problem. The article is really about the blast radius created when static access, administrative overreach, and agentic execution combine. Once that blast radius exists, the question is not whether a human would have used the access, but whether any actor can. The practitioner conclusion is to design for minimum effective scope before agent deployment makes dormant privilege operational.

From our research library:

What this signals

The next governance step is to stop treating identity review as a human-only control. Once a non-human identity can inherit a static permission profile, the programme has to evaluate whether entitlement scope is safe for continuous execution, not just acceptable for occasional human use.

Identity blast radius: the real risk is no longer the permission that a person intentionally uses, but the permission an agent can activate at scale once it inherits a broad account. That changes access governance from a review problem into a scope-design problem.

Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey. That gap suggests the market understands the risk faster than most programmes can operationalise it.


For practitioners

  • Audit actual permission use before agent rollout Compare exercised access over the last 90 days with assigned permissions so dormant rights can be removed before any agent inherits them.
  • Create dedicated non-human identities for agents Do not let agents inherit employee accounts, profile bundles, or standing human entitlements; scope each identity to one task or workflow.
  • Reduce platform-wide override permissions first Prioritise permissions such as broad read, write, and delete overrides because they determine the largest possible blast radius in enterprise platforms.
  • Start new agent access in read-only mode Limit early agent deployments to read-only actions, then expand only after logging, exception handling, and business need are proven.

Key takeaways

  • Most enterprise permissions sit unused, but they still represent real access that can be activated by non-human actors.
  • Static profiles and broad overrides create a blast radius that human behaviour used to mask and AI agents can expose instantly.
  • The control priority is to narrow agent scope before deployment, not after a non-human identity has already inherited excess privilege.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article centres on excess permissions being inherited by agents and non-human access paths.
NHI-10 — Human Use of NHIThe article warns against letting agents inherit human accounts and static profiles.
Recommendation — Reduce inherited access scope and remove overprivileged non-human identities before agent deployment. Separate human and non-human identities so agents never operate through employee credentials.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAI agents inheriting broad permissions directly creates privilege-abuse risk in agentic workflows.
Recommendation — Constrain agent privileges to task-specific scopes and block inherited excess rights.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe core issue is entitlement scope, dormant access, and authorization governance across enterprise systems.
Recommendation — Review entitlement assignments against actual business need and revoke dormant permissions promptly.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article shows why least privilege must be applied to inherited access before agents execute.
Recommendation — Apply least privilege to reduce agent-executable authority to the minimum required.

Key terms

  • Static Permission Profile: A bundled access model that assigns a predefined set of rights to a user or role. Static profiles are efficient to administer, but they often accumulate excess privilege over time and become risky when inherited by agents or other non-human identities.
  • Dormant access: Dormant access is an entitlement that remains technically valid even though the subject no longer uses it for its intended purpose. In identity governance, dormant access is dangerous because it preserves privilege, complicates review, and often survives well past the business need that created it.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Inherited Access: Inherited access is permission a tool receives from a connected user, service account, or integration rather than from a purpose-built identity. It often hides privilege expansion because the tool appears lightweight while actually operating under broad, durable entitlements.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on May 26, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org