TL;DR: AI agents, MCP servers, model endpoints, and orchestration layers expand enterprise identity into a multi-entity control problem, and Saviynt argues that posture, lifecycle, access, audit, and provenance must work together to keep AI governable. The real issue is that identity review assumes stable access and human-paced accountability, while agentic systems can create, use, and discard privileges far faster than current governance cycles can observe.
At a glance
What this is: This is a Saviynt analysis arguing that identity has to become the operating system for AI security because AI agents and related components create multiple governable identity classes.
Why it matters: It matters because IAM, IGA, PAM and NHI teams will need to govern AI agents as identities with lifecycle, access, audit and provenance controls, not as a sidecar to application security.
Context
AI agents are increasingly acting as enterprise identities rather than just application features, which changes how security teams have to think about control, accountability and trust. Once an agent can request context, consume data and initiate actions across systems, the governance problem is no longer only about the model itself but about the identity relationships around it.
This article argues that the current failure is structural: identity programmes were built around human users and service accounts, while AI ecosystems add agents, MCP servers, model endpoints and orchestration layers that behave differently at runtime. Saviynt's framing is that AI security becomes governable only when those entities are brought into a single identity model with posture, lifecycle, access and audit tied together.
The practical implication for IAM and NHI teams is that AI governance cannot be delegated to a single control point. Discovery, registration, entitlements, runtime enforcement and evidence generation have to operate as one system, or the organisation will lose line of sight the moment agents start interacting autonomously.
Key questions
Q: How should security teams govern AI agents that inherit authority from other identities?
A: Security teams should govern AI agents by tracking identity lineage, not just credentials. That means recording the originating identity, the delegated authority path, and the runtime context for each action. If an agent can inherit permissions from humans, services, or other agents, policy has to evaluate the full chain before access is granted or continued.
Q: Why do existing access review processes fall short for autonomous AI?
A: Access reviews assume privileges persist long enough to be observed, recertified, and removed later. Autonomous systems can acquire, use, and discard access within the same session or workflow, so the review cycle may never see the meaningful event. Governance needs runtime controls, not just periodic certification.
Q: What breaks when AI posture, lifecycle and access controls are managed separately?
A: The organisation loses state continuity. One team may discover an agent, another may certify it, and a third may control runtime actions, but none of them has the full picture unless the controls share a common identity model. The result is stale entitlements, incomplete evidence and weak accountability.
Q: How should teams implement AI agent governance without losing auditability?
A: Start with a centralized control plane that all agent-to-tool traffic must pass through. Then enforce tool-level authorization, session tracking, and immutable logging so each action can be traced to an identity, a context, and a policy decision. If those controls are not in place, governance becomes descriptive rather than enforceable.
Technical breakdown
Why AI ecosystems create multiple identity classes
AI environments are not one identity problem. They combine AI agents, MCP servers, model endpoints and agent frameworks, each with different authentication patterns, permission scopes and operational lifecycles. An agent may consume data and take actions, while an orchestration layer routes context and a model endpoint exposes inference through an API. That means identity boundaries shift from a single login event to a chain of registered entities and delegated permissions. The technical challenge is not just authenticating each component, but keeping those identities inventoryable, scoped and attributable across interactions.
Practical implication: model each AI component as a separate governed identity, not as one umbrella application.
Posture, lifecycle and runtime access are separate controls
The article's control model splits AI governance into posture management, lifecycle management, access management and audit and provenance. Posture answers what exists, lifecycle answers whether it is still valid, runtime access answers what it can do now, and provenance answers why it did it. Those controls are often treated as separate programmes in mature IAM stacks, but AI systems expose the weakness in that separation because an agent can be discovered, provisioned, used and retired inside the same operational window. If those controls do not share state, visibility collapses into fragments that are hard to reconcile.
Practical implication: connect discovery, certification, policy enforcement and logging so AI governance is stateful rather than episodic.
Why provenance matters in agentic workflows
Provenance is the evidence chain that ties an AI output to the policy, input data and sequence of delegated actions that produced it. In agentic workflows, especially where one agent delegates to another, simple action logs are not enough because accountability depends on showing how authority moved through the system. The article treats provenance as a governance control, not just an audit feature, because regulators and security teams need to reconstruct decisions after the fact. Without that lineage, a security event may be observable but still not explainable.
Practical implication: retain decision lineage for agent actions, delegated tokens and policy checks so each AI outcome remains auditable.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity is becoming the governing fabric of AI security, not a supporting control. Saviynt's central point is that AI security fails when organisations treat agents, orchestration layers and model endpoints as isolated technical components instead of governed identities. That is the right framing because each component can authenticate, consume data or initiate action in its own right. The practitioner conclusion is that AI security architecture now starts with identity inventory and control ownership, not with model behaviour alone.
AI governance exposes the limits of control silos that were acceptable in older IAM programmes. Posture, lifecycle, runtime access and provenance are distinct disciplines, but AI systems force them to work together in one operational chain. If discovery does not feed certification, and certification does not inform runtime policy, the organisation will not know which AI identities are active or what they can reach. The practitioner conclusion is that AI governance has to be engineered as a connected control plane.
Agentic workflows create an identity blast radius that standard human review cycles cannot contain. AI agents can act, delegate and consume context far faster than periodic access reviews are designed to observe. That does not mean access review is obsolete, but it does mean review alone cannot be the primary control for dynamic machine behaviour. The practitioner conclusion is that issuance-time controls and runtime policy must absorb risk that recertification can no longer catch in time.
Traceable provenance is the missing trust layer for AI decisions. The article correctly ties accountability to evidence, not to intent. In AI operations, organisations need to show what data was used, what policy applied and which delegated action produced the outcome. The practitioner conclusion is that without decision lineage, AI governance may look complete on paper while remaining unprovable in practice.
AI identity governance is converging with NHI governance, but it is not merely a rebrand of service-account control. AI agents inherit many NHI concerns such as registration, privilege scope and offboarding, yet they add runtime decisioning and delegated action paths that make the governance problem more dynamic. That means NHI teams can transfer discipline, but not copy controls unchanged. The practitioner conclusion is that AI identity needs its own operating model built on NHI foundations.
From our research library:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- Read next: Top 10 Agentic AI Identity Issues
What this signals
Identity-first AI governance will increasingly look like a control plane problem, not a model risk problem. The organisations that make progress will be the ones that tie discovery, entitlement control and evidence into a single operating model instead of scattering them across separate teams. That shift matters because AI identity sprawl behaves more like infrastructure sprawl than like a traditional application rollout.
AI agent blast radius is now a governance metric, not just a security concern. Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems, according to the 2026 Infrastructure Identity Survey. That gap shows that privilege scope is one of the few levers that still changes outcomes materially when AI behaviour becomes dynamic.
Provenance is becoming the differentiator between visible and governable AI. If an organisation can show what an agent did but not why it was allowed to do it, the control stack is incomplete. The next programme milestone is not more logging by volume, but better evidence that connects policy, identity and delegated action.
For practitioners
- Define AI identities explicitly Create a governed inventory for AI agents, MCP servers, model endpoints and orchestration layers so each entity has ownership, purpose and lifecycle state.
- Tie certification to active entitlements Map every AI entitlement to a named lifecycle owner and require recertification to confirm the entitlement still matches the agent's current role and use case.
- Enforce runtime policy at request time Gate each AI action through current policy rather than trusting original provisioning, especially where agents can chain tools or delegate tasks to other agents.
- Preserve provenance for every decision path Log prompts, policies, delegated actions and outputs in a way that allows investigators to reconstruct how an AI decision was made end to end.
- Separate shadow AI discovery from approval workflows Use discovery to find unmanaged agents first, then route confirmed entities into registration, policy assignment and review workflows instead of trying to govern them ad hoc.
Key takeaways
- AI security becomes governable only when agents, orchestration layers and model endpoints are treated as identities with lifecycle and access controls.
- Breaking posture, lifecycle and runtime enforcement into separate tracks leaves AI governance without a reliable state model or accountability chain.
- Provenance closes the loop by tying each AI outcome back to policy, data use and delegated action, which is essential for audit and trust.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centers on governing AI agents as identities with scoped privilege. |
| ASI10 — Rogue Agents | Shadow AI and unmanaged agents are a major governance concern in the article. | |
| Recommendation — Map AI agents to ASI03 and constrain delegated privileges to the minimum runtime scope. Detect rogue agents early and route them into registration and policy enforcement before use. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | AI agents and orchestration layers need governed authentication as identities. |
| NHI-05 — Overprivileged NHI | The article warns against broad AI access and stresses least privilege. | |
| Recommendation — Apply NHI-04 to ensure each AI identity authenticates through controlled, traceable methods. Review AI entitlements against NHI-05 and remove access that is broader than the task requires. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article's runtime access and entitlement controls align directly to CSF access governance. |
| Recommendation — Apply PR.AA-05 to keep AI permissions current, scoped and approved for the active use case. | ||
Key terms
- AI Identity Scope: The set of resources, tools, and credentials an AI system can access in order to complete a task. Proper scope is narrower than generic user access because autonomous systems can chain actions quickly, making overbroad permissions far more damaging than in human-only workflows.
- Provenance: Provenance is the traceable history of where a software artifact came from, who approved it, and what controls were applied along the way. In container security, provenance supports trust decisions because it links delivery steps to accountable identities and review points.
- Identity-Centric Security Fabric: An identity-centric security fabric is a connected control model where identity data and risk signals flow across security tools. It lets IGA, monitoring, and access decisions share context so organisations can respond consistently to changing risk instead of treating identity governance as a stand-alone process.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org