TL;DR: Agentic application security has been named a 2025 Top InfoSec Innovator, with the company framing agent protection as full-lifecycle coverage across SaaS, cloud and endpoint environments, according to Zenity and Cyber Defense Magazine. For IAM teams, the key shift is that agent behaviour, tool use, and data access now need governance and runtime controls, not just static policy.
At a glance
What this is: This is a Zenity announcement about AI agent security governance extending across SaaS, cloud and endpoint environments, with the key finding that agent risk needs full-lifecycle visibility and control.
Why it matters: IAM and security teams need a governance model that treats AI agents as runtime identities with behaviour, tool use and data access to control across multiple environments.
Context
AI agent security is no longer a single-surface problem. The article frames the issue as governance across SaaS, cloud and endpoint environments, where an agent may discover resources, invoke tools and move data in ways that do not fit static application controls.
For identity teams, the key gap is not just policy coverage but lifecycle coverage. If an AI agent can act across business systems, the programme has to account for discovery, authorisation, runtime monitoring and response as one chain rather than separate tools.
Zenity presents this as a market signal that autonomous systems are becoming a distinct identity and governance surface, not just another application layer.
Key questions
Q: What breaks when AI agent activity is not monitored across cloud, SaaS, and endpoint environments?
A: Without consistent monitoring, agencies lose sight of which agents exist, what they touch, and when their behaviour changes. That gap makes it harder to detect anomalies, prevent unauthorized access, and prove compliance after an incident. In practice, blind spots lead to delayed response, weak accountability, and higher exposure to data leakage.
Q: Why do autonomous agents need runtime governance instead of simple access controls?
A: Autonomous agents can turn a request into a sequence of actions without a human pausing the workflow for review. Access control alone does not show what the agent inferred, returned, or invoked next. Runtime governance is needed because the risk is created during execution, not just at login or authorization time.
Q: What are the signs that an AI security agent is failing governance review?
A: Common warning signs include unclear retry behaviour, no fixed scope boundaries, mixed operator intervention, and logs that cannot reconstruct each action. If the team cannot explain what the agent was allowed to do and prove what it actually did, governance is not working.
Q: How should security teams govern AI agents that move across multiple trust boundaries?
A: They need runtime controls that follow the agent rather than staying attached to one platform. The practical test is whether enforcement, telemetry, and inventory remain consistent as the agent moves from IDEs to MCP servers to downstream SaaS actions. If the control breaks at the boundary, governance is incomplete.
Technical breakdown
Why agent governance breaks across SaaS, cloud and endpoint
AI agents do not stay inside one control plane. They may act in SaaS workflows, trigger cloud actions and touch endpoint data or local tooling, which means security policy has to follow the agent’s execution path rather than a single app boundary. Traditional controls often assume a stable application or user session, but agentic systems can chain actions across platforms, making discrete point controls blind to the overall workflow. The technical problem is identity, authorisation and observability across heterogeneous runtimes, not just model safety or prompt filtering.
Practical implication: Map every environment where agents can act, then verify that identity, access and logging controls travel with the workflow.
What full-lifecycle agent security actually covers
Full-lifecycle protection for AI agents starts with discovery and posture management, then extends into runtime detection, inline prevention and response. Discovery finds agents that already exist, including unmanaged or shadow deployments. Posture management evaluates what they can reach, which tools they can invoke and how much privilege they carry. Runtime controls are needed because agent decisions happen during execution, not only at provisioning time. That combination matters because AI agents are not static workloads. They are behaviour-producing systems whose effective access can change with context, task and tool selection.
Practical implication: Treat discovery, privilege review and runtime enforcement as one programme, not three separate projects.
Why agent intent and impact need observability
The article emphasises observing how agents process information, make decisions and take action. That is important because agent risk is often produced by the sequence of steps, not a single malicious call. If a system can inspect only inputs or outputs, it misses the path between them, including tool invocation, data movement and delegation. In agentic security, observability is not just telemetry for after-the-fact investigation. It is how the security function understands whether the agent is operating within its intended authority and whether its behaviour is drifting into unsafe actions.
Practical implication: Instrument agent decisions and tool calls so security teams can detect scope drift before it becomes impact.
Threat narrative
Attacker objective: Exploit agent authority and cross-environment access to create uncontrolled actions, data exposure or workflow abuse under legitimate automation.
- Entry occurs when an AI agent is granted access to SaaS, cloud or endpoint resources as part of normal business automation.
- Escalation happens when the agent invokes additional tools or reaches data and systems beyond the original human assumption behind the workflow.
- Impact follows when the agent’s runtime actions create compliance, safety or trust failures across multiple environments without a single control seeing the whole chain.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI agent governance now behaves like an identity programme, not a point product problem. The article’s real signal is that agents can act across SaaS, cloud and endpoint environments with a single behavioural context. That breaks the old assumption that application security can be handled per platform. Practitioners should read this as a governance boundary shift, where authorisation, observability and response must follow the agent rather than the system it happens to touch.
Runtime control is the decisive layer because agent risk is produced during execution. Static policy can describe what an agent should be allowed to do, but it cannot by itself stop unsafe tool invocation or unexpected sequence changes once the task begins. That is why this category increasingly resembles NHI governance with behavioural enforcement attached. The practical conclusion is that the control surface has moved from provisioning alone to runtime decision-making.
Cross-environment coverage exposes the identity blast radius of autonomous behaviour. A platform that spans SaaS, cloud and endpoint is not just broader coverage, it is recognition that one agent can accumulate privilege and impact across multiple trust zones. Identity blast radius: the amount of organisational reach a single agent can accumulate before any one control plane detects the full pattern. Security teams need to understand that blast radius before they can contain it.
Agent discovery and posture management are becoming the governance prerequisite for AI transformation. If an organisation cannot inventory where agents exist, what they can access and which tools they can invoke, it cannot credibly claim to govern them. That is true whether the agent is vendor-managed or home-grown. The implication is straightforward: AI adoption without agent inventory is governance by assumption, not by control.
AI agent security is moving toward standards-based accountability across the market. The article’s references to MITRE ATLAS and OWASP show that the category is maturing from vendor language into shared threat and control vocabulary. That matters because practitioners need consistent language to compare risk, audit controls and define internal policy. The field is heading toward formalised agent governance, and teams should align to that direction now.
From our research library:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
- Read next: AI Agent Observability, Audit and Incident Response Guide
What this signals
Identity blast radius: AI agents that can invoke tools across SaaS, cloud and endpoint environments expand the reachable impact of a single identity decision. Security teams should treat cross-environment behaviour as a governance boundary, not just a deployment architecture choice.
Where agent authority crosses multiple platforms, review cadences and alerting models need to be tied to execution paths rather than system silos. That is the practical shift from application security to agent governance, and it is why discovery and runtime control now belong in the same operating model.
For practitioners
- Inventory every deployed agent Build a live register of AI agents across SaaS, cloud and endpoint environments, including home-grown and shadow deployments, with owner, purpose and reachable systems.
- Map agent tool authority Document which tools, connectors and APIs each agent can invoke, then flag any path that exceeds the task it was originally meant to perform.
- Add runtime blocking for unsafe actions Use runtime policy to stop agent actions that cross approved data, tool or environment boundaries after the task has already started.
- Tie agent alerts to incident response Route anomalous agent behaviour into your response process so detection, triage and containment can happen while the agent is still active.
Key takeaways
- AI agent governance is moving beyond a single platform view because the same agent can now touch SaaS, cloud and endpoint systems.
- The hardest problem is not model output but runtime authority, tool use and cross-environment behaviour that static controls do not fully see.
- Security teams need inventory, posture management and runtime enforcement to govern agent impact before it becomes an operational or compliance issue.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 provides the primary governance reference for this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article is about governing agent identity, access and behaviour across environments. |
| Recommendation — Apply ASI03 to bound agent privileges and verify tool use against task intent. | ||
Key terms
- AI Agent Governance: AI Agent Governance is the set of policies, controls, and oversight practices used to direct how autonomous software agents behave. It defines allowed actions, approval paths, identity boundaries, logging, monitoring, and accountability so agent decisions remain traceable, constrained, and aligned with business, security, legal, and ethical requirements.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Runtime Enforcement: Runtime enforcement is the practice of blocking malicious behaviour while software is running, rather than only detecting it after the fact. It monitors process activity, network actions, and privilege changes so a live attack can be interrupted at the point of execution.
- Agent Discovery: Agent discovery is the process of finding every AI agent across cloud platforms, low-code tools, repositories, and deployment pipelines. It matters because governance cannot start until the organisation can see where the agent exists, who owns it, and what it can reach.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org