By NHI Mgmt Group Editorial TeamBased on WorkOS: “Bedrock Data for AI Agent Security: Features, Pricing, and Alternatives” (November 11, 2025)

TL;DR: AI agents are being governed through metadata visibility and runtime policy hints, but that model still depends on agents cooperating with the governance layer, according to WorkOS. For production systems, the harder problem is enforced authentication and authorization, not just observability or data classification.


At a glance

What this is: This is a vendor comparison that says metadata-only governance can help AI agent data visibility, but it does not replace enforced authentication and authorization for production use.

Why it matters: IAM, IGA, PAM, and NHI teams should treat AI agents as governed identities, because runtime enforcement, revocation, and policy checks matter more than post hoc visibility when systems act autonomously.


Context

AI agent governance is not the same as data visibility. The core problem is that agents can access, combine, and move data in ways that metadata-only controls can observe but not necessarily stop, which leaves enforcement outside the control plane.

Bedrock Data’s model centers on metadata intelligence and MCP-driven self-governance, while WorkOS in this article is used as the contrast case for enforced authentication and authorization. That makes the practical question one of boundary control, not just cataloguing or lineage.

For identity programmes, the issue is whether policy lives in the data layer, the agent layer, or the authorization layer. In production, the last one is the only layer that can reliably deny an action before it happens.


Key questions

Q: What breaks when AI agent governance relies on metadata instead of enforced authorization?

A: The control breaks at the point of action. Metadata can tell an agent what is sensitive, but it cannot reliably prevent a read, write, or workflow trigger unless an independent authorization layer makes the decision. Without that boundary, governance becomes guidance rather than enforcement.

Q: Why do metadata-based controls fall short for production AI agent security?

A: Metadata-based controls fall short when they depend on the agent to cooperate. They can describe sensitivity, policy, and lineage, but they cannot guarantee that a request will be blocked if the agent bypasses the guidance or interprets it incorrectly. Production security needs an external control point that can enforce denial.

Q: How should teams decide whether AI agent access should be enforced at the identity layer or the data layer?

A: Teams should enforce access at the identity layer when the question is whether the agent is allowed to act at all, and use the data layer for classification and context. If the policy must be able to deny an action before data is touched, identity and authorization must own that decision.

Q: What should security teams do when AI agents need access to tools and data?

A: Security teams should treat AI agents as runtime access actors and separate them from static machine identities. Limit tool scope, define approval gates, and require explicit revocation triggers for sessions and delegated access. The goal is to prevent broad runtime behaviour from inheriting static privileges.


Technical breakdown

Metadata intelligence vs authorization enforcement

Metadata intelligence describes data through classifications, lineage, sensitivity labels, and policy hints. It is useful for discovery and governance, but it is not the same as decision-time authorization. A governance layer that tells an AI agent what it should do still depends on the agent respecting that instruction. Enforced authorization sits in the path of the request and can permit or deny the action before data is exposed or an API is called. That distinction matters because observability can explain risk after the fact, while authorization can prevent the action from occurring.

Practical implication: Separate visibility controls from decision controls, and treat metadata platforms as supplementary unless they can deny access in-line.

MCP-based self-governance and its trust assumption

Model Context Protocol gives an agent a structured way to query tools and context, but in this article Bedrock’s governance model relies on the agent querying policy and then behaving accordingly. That creates a trust assumption: the agent must actively participate in its own governance. For controlled internal systems that may be acceptable, but it weakens sharply when agents are third-party, loosely governed, or capable of ignoring the suggested policy path. Runtime policy only works if the enforcement point is independent of the actor being governed.

Practical implication: Do not let the governed agent be the only party capable of interpreting or applying its own access rules.

Why identity infrastructure still defines the security boundary

Production AI systems need more than data classification. They need identity proofing, authentication, authorization, provisioning, revocation, and auditability across the full lifecycle of the agent or workload. That is the identity boundary that determines whether a request is legitimate, whether access scope is appropriate, and whether access can be revoked immediately. Data governance can explain what is sensitive. Identity governance determines who or what can act on it. When those layers are separated, the system may be well-instrumented but still insecure.

Practical implication: Anchor AI agent access decisions in identity and authorization systems, not in metadata lookups alone.


Threat narrative

Attacker objective: Obtain or manipulate sensitive enterprise data by using agent access paths that are governed by guidance rather than hard enforcement.

  1. Entry occurs when an AI agent is allowed to query data governance metadata and infer policy from that response rather than from an enforced control point.
  2. Escalation follows when the agent is given broad permissions or can compose tool calls across workflows, allowing access to spread beyond the original task scope.
  3. Impact is the unauthorized access, movement, or use of sensitive data that a metadata-only model could describe but not stop in time.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Metadata-only governance is a visibility layer, not a security boundary. A metadata lake can classify data, track lineage, and enrich policy context, but it cannot by itself stop an agent from taking an action. The boundary that matters is the authorization decision, because that is where access is either permitted or denied. For practitioners, this means treating data intelligence as input to control design, not as the control itself.

Runtime governance that depends on the governed actor is structurally weak. The article’s MCP-based model assumes the agent will query policy and then comply with it. That works only when the actor remains cooperative, which is a fragile basis for production security. The implication is that security teams should distrust any governance design where the same agent being controlled is also the only mechanism enforcing the control.

AI agent governance should be evaluated as an identity problem first and a data problem second. Once agents can authenticate, invoke tools, and compose actions across systems, the question becomes who the actor is, what it can do, and how its authority is revoked. Identity infrastructure determines the enforceable boundary; metadata determines the context. Practitioners should therefore place enforced authorization ahead of any agent-side policy interpretation.

Ephemeral agent authority creates an identity blast radius that metadata cannot contain. When an agent can chain requests across data systems, the risk is not just what it sees but what it can do before anyone notices. That makes session control, revocation, and fine-grained authorization the decisive governance primitives. Teams should measure AI agent risk by the scope of executable authority, not the sophistication of the data catalogue.

From our research library:

What this signals

Agent governance needs a denial path, not just a description path. Metadata and lineage remain useful for understanding what data exists and how it moves, but they do not close the loop on who can act. The programme signal is simple: if an AI agent can still proceed after reading policy context, governance has not yet reached the enforcement layer.

Identity blast radius is the real control variable for production AI systems. When an agent can authenticate across multiple tools, the issue is no longer visibility into data handling, it is the amount of authority that survives each request. Use enforced authorization, task-scoped access, and revocation as the basis for containment.

Access review models built for slower-moving human or service identities do not fully describe agent risk. Agent access can be short-lived, chained, and self-initiated, which means the decisive control is issuance-time policy. That shifts the programme focus from retrospective review to pre-execution boundary setting.


For practitioners

  • Define the enforcement boundary Map where AI agent requests are actually allowed or denied, and ensure that decision point sits outside the agent itself. If the agent can only ask for policy and then self-apply it, the control is advisory rather than enforced.
  • Separate data visibility from access control Use metadata classification and lineage for discovery, but require independent authorization checks before the agent can read, write, or invoke downstream workflows. Treat catalog results as context, not permission.
  • Scope agent permissions to executable tasks Grant the minimum tool, data, and workflow access needed for a single job, then revoke the session or token immediately after completion. Broad standing access turns governance hints into the only practical constraint.
  • Instrument revocation and audit for agent sessions Make it possible to terminate an agent session, invalidate its credentials, and reconstruct its actions without relying on the agent’s own logs. That is the difference between visibility and containment.

Key takeaways

  • Metadata-only AI agent governance improves visibility, but it does not replace enforced authorization at the decision point.
  • The article’s core tension is between agent-side self-governance and independent identity controls that can deny actions without cooperation.
  • For production AI systems, the safest pattern is to bind access to identity, scope it to the task, and revoke it immediately after use.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article contrasts metadata guidance with enforced identity checks for AI agents.
NHI-05 — Overprivileged NHIThe article warns that broad agent access undermines data governance models.
NHI-08 — Environment IsolationAgent governance depends on separating policy context from executable authority.
Recommendation — Require independent authentication before any agent can query, read, or invoke governed data. Scope agent access to the minimum data and tool set needed for each task. Isolate policy evaluation from the agent runtime so governance is not self-applied.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe core issue is whether an agent can act beyond its intended authority path.
Recommendation — Place hard authorization checks in front of every sensitive agent action.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on enforced permissioning for production AI agents.
Recommendation — Use entitlement controls to deny agent actions that exceed approved scope.

Key terms

  • Metadata-only governance: A control approach that classifies and contextualises data through metadata rather than inspecting or governing the data plane directly. It improves visibility and policy enrichment, but on its own it does not prevent access or action, so it must be paired with enforced authorization for production use.
  • Enforced authorization: An identity control that decides in real time whether a subject may perform a specific action. For AI agents, the check must occur outside the agent so policy cannot be bypassed by the actor being governed, especially when access is task-scoped or highly dynamic.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Agent-side self-governance: A model where the agent queries policy or metadata and then applies the resulting constraints itself. It can work in tightly controlled environments, but it leaves security dependent on cooperation from the actor rather than on a separate enforcement layer.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org