By NHI Mgmt Group Editorial TeamBased on Oasis Security: “Oasis x Cursor: Governing Agentic Execution in the IDE” (May 1, 2026)

TL;DR: Cursor and Oasis are framing agentic IDE security around just-in-time, policy-based control, because agent actions now execute commands, call MCP tools, and touch internal systems in ways that create audit and approval gaps, according to Oasis Security. The security problem is no longer autocomplete, it is governing runtime execution before developer velocity turns into untracked access drift.


At a glance

What this is: This analysis argues that AI agents inside the IDE have turned code-assist tools into governed execution paths, where commands, MCP tools, and internal system access need policy and auditability.

Why it matters: IAM, NHI, and PAM teams should treat agent actions as identity-governed runtime events because approval gaps, untracked scope, and shadow tool use now emerge inside developer workflows.


Context

An agentic IDE changes the governance problem because the software is no longer just suggesting code. It is executing commands, calling MCP tools, and interacting with internal systems, which means access decisions happen during runtime rather than only at provisioning time.

That shifts the identity question from who can use the IDE to what an agent is allowed to do inside a live developer session. For IAM and NHI programmes, the control point moves closer to execution, where policy, approval, and audit evidence have to line up with the task in progress.

The article frames that shift as AI zero trust: intent is evaluated, policy is applied, access is granted just in time, and the action is logged. The result is a governance model for agentic execution, not a product feature for autocomplete.


Key questions

Q: What breaks when agentic IDE tools are allowed to act with standing access?

A: Standing access breaks the assumption that a human reviewer can evaluate privilege before use. In an agentic IDE, commands and tool calls happen at runtime, so broad access creates approval gaps, unclear tool provenance, and untracked scope drift. The control failure is not speed, it is the loss of a meaningful decision point before action completes.

Q: When does just-in-time access help most for AI agents?

A: JIT access helps most when agent tasks are episodic, high-risk, or difficult to predict in advance. It reduces standing exposure, but it works only if the agent's permissions are also tightly scoped and actively revoked after use. Otherwise, the temporary token masks a persistent privilege problem.

Q: What are the signs that agentic execution is getting out of control in the IDE?

A: Common warning signs are unapproved tools appearing in workflows, weak visibility into which MCP servers were used, copied tokens or workarounds, and missing approval records for high-risk actions. If security cannot answer who authorised the action, what was accessed, and whether the permissions were approved, governance is already behind the agent.

Q: What should security teams do when AI agents need access to tools and data?

A: Security teams should treat AI agents as runtime access actors and separate them from static machine identities. Limit tool scope, define approval gates, and require explicit revocation triggers for sessions and delegated access. The goal is to prevent broad runtime behaviour from inheriting static privileges.


Technical breakdown

How Cursor hooks turn agent execution into a policy decision

Cursor hooks create an enforcement point before or after an agent action, such as MCP execution or shell command execution. That matters because the system can inspect the request while context is still intact: who initiated it, which tool is being called, what input is being sent, and whether the action should proceed. In identity terms, the hook becomes a runtime control point, not a post-event detection layer. It can return allow, warn, step-up, or deny, which lets policy attach to execution rather than to the broader IDE session.

Practical implication: place policy checks at the action boundary so high-risk agent behaviour is evaluated before it reaches internal tools.

Why MCP access changes the identity surface in the IDE

Model Context Protocol makes external tools available to the agent, which expands the identity problem beyond the editor itself. Once an agent can call MCP endpoints, the security question is no longer limited to code generation. It becomes whether each tool is approved, what data the agent may pass, and whether the current permissions are appropriate for the task. That creates a classic governance problem for non-human identities: the toolchain is dynamic, the access path is runtime-driven, and the blast radius depends on which MCP servers and internal systems are reachable in the moment.

Practical implication: inventory MCP endpoints as governed access paths and tie each one to explicit approval and scope controls.

Why audit trails must capture intent, tool use, and approval state

A decision trail is not the same as a log line. For agentic IDE governance, the useful evidence is the chain from intent to policy decision to action outcome, because that is what answers whether access was justified. The article’s model also shows why post-hoc review alone is weak: if the agent can complete a task in seconds, security may never see a stable privilege state to recertify after the fact. This is where AI zero trust becomes operational, because governance must preserve who approved the action, what tool was invoked, and whether the permission was ephemeral or standing.

Practical implication: capture approval context and tool provenance in the audit trail, not just command output or event metadata.


NHI Mgmt Group analysis

Agentic IDEs collapse the assumption that access can be governed after execution begins. The article shows that agent actions happen inside the workstream, not after it. That means approval, scope, and audit all have to be decided while the action is still live. For identity governance, this is a structural change, because the control point moves from session review to runtime decisioning.

Just-in-time access becomes the only defensible way to handle AI-driven development tasks. Standing permissions do not fit a model where the agent can run a command, call a tool, and complete a task before a human would ever review the request. The article’s AI zero trust framing is really a statement about governable execution, not convenience. The practitioner implication is that access duration must match task duration, not user convenience.

Shadow IT is no longer a user behaviour problem alone, it is an agent governance problem. When developers can route around guardrails with different tools, copied tokens, or untracked workflows, the issue is not simply policy noncompliance. It is that the execution environment itself can fragment control. That raises the value of allowlists, step-up approval, and centralised decision logs across the agent ecosystem.

Intent-based access for agents is becoming a distinct governance pattern, not a variant of human PAM. The article’s emphasis on onboarding, scoped permissions, expiration, and auditable activity shows that non-human identities inside developer tools need lifecycle management. The named concept here is agentic execution governance: controlling what an agent is authorised to do at the moment it acts. Practitioners should treat that as a separate control surface from human developer access.

From our research library:

What this signals

Agentic IDE governance is moving from theoretical to operational because execution now happens inside the development workflow itself. Programmes that still rely on post-hoc review will miss the decision point where agent scope is actually created.

Agentic execution governance: this is the control pattern emerging when organisations treat AI agents as governed identities with scoped, expiring permissions and auditable action trails. The practical implication is that identity teams must design for runtime authorisation, not just access review after the fact.


For practitioners

  • Define runtime policy for agent actions Map allow, warn, step-up, and deny decisions to the specific agent actions that can execute commands, call MCP tools, or touch internal systems.
  • Inventory approved MCP tools and endpoints Treat each MCP server as a governed access path and require explicit onboarding for unknown tools before they are reachable by an IDE agent.
  • Move developer access to task-scoped issuance Replace broad standing access with ephemeral permissions that expire at task completion so agent privileges do not persist beyond the work being performed.
  • Log the full decision chain for audit Capture the initiating intent, the policy decision, the tool invoked, and the resulting action so reviewers can reconstruct what the agent actually did.

Key takeaways

  • Agentic IDEs change the problem from code assistance to governed execution, which means access decisions must happen at the moment of action.
  • Auditability depends on linking intent, policy, tool use, and result, because that is the only reliable way to explain what an agent did.
  • Just-in-time, task-scoped permissions are the clearest fit for agentic development because standing access leaves too much room for approval gaps and scope drift.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseThe article centers on agent actions calling tools and needing policy control.
ASI03 — Identity & Privilege AbuseThe risk is agent privilege expanding inside the IDE beyond intended scope.
Recommendation — Apply ASI02 to govern which tools an IDE agent may call and under what approval state. Use ASI03 to constrain agent privileges to task-scoped, approved access only.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article warns against broad standing access for non-human identities in agentic workflows.
NHI-01 — Improper OffboardingThe article stresses expiring permissions and lifecycle management for agents.
Recommendation — Apply NHI-05 to replace standing agent privileges with least-privilege, task-bound access. Use NHI-01 to ensure agent permissions expire and are revoked when tasks end.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is about governing AI execution paths and accountability in development workflows.
Recommendation — Implement GOVERN to assign ownership, approval, and accountability for agentic execution.

Key terms

  • Agentic Tool Execution: Agentic tool execution is the pattern where an AI system does more than generate text and instead calls APIs, reads data, runs functions, or changes state. This creates security risk because legitimate operations can be manipulated into unintended actions, making intent harder to distinguish from normal behavior.
  • Intent-Based Access Control: An access control model that evaluates not just what an agent is requesting, but the inferred intent and context behind the request, granting or denying access based on whether the action aligns with the agent's declared purpose.
  • MCP Endpoint: An MCP Endpoint is the network location where an AI agent or application connects to use the Model Context Protocol. Technically, it exposes a protocol interface that lets clients discover tools, resources, and prompts, while enforcing authentication, authorization, transport security, and logging for controlled machine-to-machine access.
  • Decision trail: A decision trail is the record of inputs, choices, and outputs that led an AI agent to take an action. It goes beyond access logs by showing why the agent behaved a certain way, which is essential for auditability, incident reconstruction, and policy enforcement.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org