TL;DR: Opal Security argues that enterprise AI has moved from LLM assistants to coding agents and digital employees, and that identity now has to govern who or what can act, where, for how long, and under which approvals. Access review models assume privilege persists long enough to review; agentic workflows compress that window into runtime decisions that legacy IAM cannot govern.
At a glance
What this is: This analysis says enterprise AI has moved through LLMs, coding agents, and digital employees, with identity becoming the control plane for task-scoped, time-bound, and approval-aware access.
Why it matters: IAM, IGA, PAM, and NHI programmes now need to govern runtime access decisions for AI actors that change privilege scope faster than traditional review cycles can observe.
👉 Read Opal Security's analysis of identity security as AI moves from prompts to agents
Context
Enterprise AI adoption is shifting from copilots to systems that execute work, which changes the identity problem from user access to actor governance. In practical terms, the article treats identity as the control plane for LLMs, coding agents, and AI agents that may touch enterprise systems, cloud resources, and business workflows.
The governance gap is not about whether AI can perform a task, but about who or what can be allowed to do it, for how long, and under which approvals. That matters because access models built for static human roles do not cleanly map to ephemeral, task-scoped AI activity, especially when the actor can reach code, data, or production systems.
Key questions
Q: What breaks when AI agents are given broad standing access?
A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check. That creates a control gap between intended scope and actual runtime behaviour. The result is weak accountability, limited containment, and audit trails that show activity without explaining why the activity was allowed.
Q: Why do existing access review processes fall short for autonomous AI?
A: Access reviews assume privileges persist long enough to be observed, recertified, and removed later. Autonomous systems can acquire, use, and discard access within the same session or workflow, so the review cycle may never see the meaningful event. Governance needs runtime controls, not just periodic certification.
Q: How do organisations know whether AI identity monitoring is actually working?
A: Monitoring is working when teams can see which agent initiated each action, which tool was used, what data was touched, and whether the sequence matches the approved purpose. If logs show activity but cannot connect it to an owner, workflow, and entitlement set, the programme still has a visibility gap.
Q: When should organisations treat an AI agent as a privileged system?
A: Organisations should treat an AI agent as privileged whenever it can reach production data, administrative tools, or sensitive workflows without direct human approval for each step. At that point, the agent is no longer a passive automation helper. It becomes a governed identity whose permissions, logs, and exceptions need the same scrutiny as other high-risk access.
Technical breakdown
How identity changes as AI moves from prompts to agents
The article describes a three-phase maturity curve: LLMs for knowledge work, coding agents in engineering workflows, and AI agents that operate as digital employees. The technical shift is that each phase expands the action surface, moving from read-oriented assistance to systems that can write code, trigger pipelines, and execute business tasks. Identity therefore stops being a login concern and becomes a runtime authorisation problem. A governing model must know which actor is acting, what systems it can reach, what scope it receives, and when that scope ends.
Practical implication: treat AI actors as governed identities with purpose, scope, and expiry, not as generic software features.
Why JIT access and ephemeral tokens matter for AI workflows
The article repeatedly favours just-in-time access, time-boxed tokens, and scoped privileges over standing credentials. That matters because AI systems often need broad reach for a narrow purpose, such as reading repositories, opening pull requests, or invoking CI/CD jobs. If those grants persist, the blast radius of a mistake or compromise expands far beyond the task itself. Ephemeral access narrows the window in which a token can be abused and ties each grant to a specific approval context and business justification.
Practical implication: replace static access with task-scoped grants that expire automatically once the workflow completes.
How approvals and audit trails need to work for AI agents
The article argues that governance must preserve a clear chain of custody from request to approval to execution. That means the record needs to show which actor requested access, who approved it, what data or systems were touched, and what action was taken. For digital employees, this also extends to risk tier, ownership, and business reason. Without that linkage, teams cannot answer simple accountability questions after a change, a deployment, or a support action. The result is an access model that is visible at action time, not only after the fact.
Practical implication: bind approvals, policy, and execution logs into one audit trail for every AI-mediated action.
Breaches seen in the wild
- Moltbook AI agent keys breach: Moltbook breach exposed 1.5M AI agent keys.
- DeepSeek database exposure 2025: An unauthenticated DeepSeek ClickHouse database exposed over a million log lines with plaintext chat history and API keys in 2025.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity for AI is no longer a provisioning problem, it is a runtime governance problem. The article’s central claim is that AI adoption has crossed the point where static access models are enough, because the actor can now request, combine, and execute work across multiple systems. That changes the governance unit from the account to the action. Practitioners should rethink identity as an execution control plane, not just an authentication layer.
Access review assumptions collapse when privilege is measured in minutes, not months. Traditional recertification assumes there is a stable grant to review, but AI workflows increasingly create short-lived access tied to a single task or session. That is an assumption built for human job roles and persistent entitlements, not for actors whose scope can appear and disappear within a workflow boundary. The implication is that governance must shift from review-after-the-fact to decision-at-issuance.
Ephemeral credential trust debt is the right way to describe the new AI risk surface. The article shows why static secrets, broad repository write access, and unbounded pipeline rights are unsustainable once AI can act directly on code, cloud, and business processes. Each additional minute of standing access increases the trust debt carried by the programme. The practitioner conclusion is to minimise how long any AI actor can hold meaningful authority.
The future identity model must connect ownership, purpose, and separation of duties across human and machine actors. The article’s phased approach makes clear that the same governance pattern has to scale from LLM usage to digital employees. That means ownership, risk tiering, approval thresholds, and auditability cannot remain human-only concepts. Practitioners should design one identity model that covers people, machine identities, and autonomous workflows without duplicating governance logic.
Agent governance will increasingly be judged by whether it can prove why an action was allowed. The article emphasises chain of custody, contextual approvals, and policy-driven execution, which tells us the industry is moving toward explainable access decisions for AI actors. This aligns with broader NHI governance thinking: if a workflow cannot show the reason, scope, and approver, it is not governed. The practical conclusion is that traceability becomes a control objective, not just an audit artifact.
From our research library:
- Enterprise AI use rose from 55% of organisations in 2023 to 88% in 2025, according to McKinsey’s Global Surveys on the State of AI.
- Read next: Agentic AI Identity Maturity Model
What this signals
Ephemeral credential trust debt: The more AI workflows rely on standing permissions, the more hidden trust accumulates in the programme, because access can outlive the task that justified it. That debt is paid down by task-scoped grants, tighter approvals, and faster revocation.
Access reviews will matter less as an after-the-fact control and more as a signal of whether the programme still relies on static authority. For AI-mediated work, the real control point moves to issuance time, where scope, purpose, and expiry are decided before action begins.
For practitioners
- Define AI actors as governed identities Assign each LLM, coding agent, and digital employee an owner, purpose, risk tier, and expiry so the programme can govern the actor, not just the tool.
- Replace standing credentials with ephemeral grants Issue task-scoped access that expires by default for repository, pipeline, data, and cloud actions so AI authority never outlives the workflow that needs it.
- Tie approvals to business context Require approvals to capture who requested access, what systems were touched, what justification applied, and which policy or budget boundary was in force.
- Separate low-, medium-, and high-risk AI actions Use auto-approval in sandboxes, single approvers for routine controlled tasks, and dual control for high-impact actions such as production changes or purchase orders.
- Build one audit trail for request to execution Preserve a single record that links request, approval, privilege scope, execution, and outcome so post-incident review can reconstruct the full chain of custody.
Key takeaways
- AI adoption is changing the identity problem from login control to action control, because agents can now touch code, cloud, and business systems directly.
- The main governance failure is the assumption that privilege will persist long enough to be reviewed, which does not hold for short-lived AI workflows.
- Task-scoped access, ownership, and full request-to-execution audit trails are the controls that make AI identity governable at scale.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centers on AI actors receiving scoped authority across workflows. |
| Recommendation — Apply ASI03 to bound agent privileges by purpose, scope, and approval context. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | AI agents here operate as non-human identities that can easily accumulate excess access. |
| NHI-07 — Long-Lived Secrets | The article explicitly warns against static keys and persistent credentials for AI workflows. | |
| Recommendation — Review AI actors for overprivileged scopes and remove any standing access they do not need. Replace long-lived secrets with expiring tokens for all AI-mediated workflows. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | Ownership, purpose, and approval boundaries are the core governance mechanisms in the article. |
| Recommendation — Define accountable ownership and approval rules for every AI actor and workflow. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about access scope, expiry, and authorization for AI actors. |
| Recommendation — Align AI access grants to PR.AA-05 by enforcing least-privilege entitlements and task-based expiry. | ||
Key terms
- AI Actor: An AI actor is a system that can perform work on behalf of an organisation with some level of delegated authority. In this article’s context, the important distinction is not whether the system uses AI, but whether it can act across tools, systems, or workflows in ways that require identity governance.
- Task-Scoped Access: Task-scoped access is permission granted for one defined purpose and removed once the task is complete or the session expires. For non-human identities, it reduces standing privilege and limits how long an attacker can exploit a stolen credential.
- Ephemeral Credentials: Ephemeral credentials are short-lived access artefacts issued for a limited task or session. They reduce the window for abuse, but they only improve security when paired with strong scope limits, telemetry, and automatic revocation at task completion.
- Chain Of Custody For Identity Actions: Chain of custody for identity actions is the record that links a request, approval, granted scope, execution, and outcome. In AI governance, it is what lets teams explain why an actor was allowed to act and reconstruct the path after an incident or audit.
What's in the full article
Opal Security's full analysis covers the operational detail this post intentionally leaves for the source:
- Phase-by-phase guidance for governing LLMs, coding agents, and digital employees
- Examples of task-scoped approvals across SaaS, data platforms, cloud accounts, and internal tools
- Operational patterns for replacing static secrets with ephemeral, scoped tokens
- Signals to monitor, including recertification completion, approval latency, and standing-access reduction
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org