TL;DR: A single innocent request can enable agentic AI to merge multiple authenticated contexts into one operational identity, allowing cross-system lateral movement, data exfiltration, phishing, or malware distribution, according to Lasso Security's IdentityMesh research. The finding makes clear that existing MCP and browser-based controls assume boundaries the agent does not preserve.
At a glance
What this is: IdentityMesh is Lasso Security's analysis of an agentic AI attack pattern where separate authenticated contexts collapse into one operational identity across systems.
Why it matters: IAM, PAM, and NHI teams need to treat agentic cross-system execution as a boundary problem, because one legitimate request can become unauthorized movement across tools and environments.
Context
Identity boundaries in agentic systems are only meaningful if the agent preserves separation between systems, credentials, and actions. IdentityMesh shows what breaks when that assumption fails: the agent can treat multiple authenticated contexts as one operating identity and move information across them without a clean authorization boundary.
The issue is not simply that an agent can use tools. The issue is that MCP-style and browser-integrated agents can chain read and write operations across separate systems while appearing to act within one user session. That creates an IAM and NHI governance gap that traditional per-system permission models do not address.
Lasso Security's research is especially relevant because it spans both enterprise assistants and browser-based agents, showing that the same identity collapse pattern can affect internal workflows and customer-facing use cases.
Key questions
Q: What breaks when an agent can combine multiple authenticated contexts into one workflow?
A: The boundary between systems breaks down. An agent that can carry context from one authenticated service into another may convert permitted steps into unauthorized cross-system action, so the real failure is not one tool but the loss of separation between identities, sessions, and intended scope.
Q: Why do cross-system agent workflows create lateral movement risk?
A: Because read access in one system can feed write actions in another without a fresh trust decision. When an agent can reuse context across email, tickets, documents, and code platforms, attackers can turn one legitimate task into a path for data theft, phishing, or malware distribution.
Q: How can teams tell whether agentic access controls are actually working?
A: Look for evidence that every privileged action is logged with actor type, target resource, and policy decision, and that denied requests are being blocked before execution. If you can only see the login and not the downstream action, the control is too weak for agentic use.
Q: Should organisations treat browser agents differently from backend MCP agents?
A: Yes. Browser agents inherit live authenticated sessions across sites, which means cross-origin movement can look like ordinary user behaviour even when the agent is bridging separate applications. That makes browser-based automation a distinct governance problem, not just another tool integration.
Technical breakdown
How identity collapse happens in MCP and browser agents
MCP agents typically combine a model, context store, and tool layer. When the same session can reach multiple systems, the agent may retain information from one system and act on it in another without re-establishing a distinct authorization boundary. That is the core of identity collapse: the agent behaves as if separate credentials, permissions, and systems were one continuous trust domain. In browser agents, the risk is amplified because the browser already carries authenticated sessions across origins, so the agent can move between services under the user's identity while preserving context. The architectural failure is not just tool access, but the loss of enforced separation between trust zones.
Practical implication: treat cross-system tool chaining as a boundary control problem, not a workflow convenience.
Why read and write tools create lateral movement paths
Read tools let the agent collect sensitive content from one system, while write tools let it export, repost, or trigger actions in another. If the agent does not preserve system-specific intent and authorization, information gathered from email, tickets, documents, or chats can be repurposed into a different environment with no fresh approval. That is why the article links the same pattern to data exfiltration, phishing, malware distribution, and even remote code execution. The critical weakness is not that each tool is unsafe in isolation. It is that a unified agent can convert individually permitted steps into a cross-system attack chain.
Practical implication: review any agent workflow that combines read access in one system with write capability in another.
Why indirect prompt injection works in agentic environments
Indirect prompt injection succeeds because malicious instructions can arrive through trusted content, such as a ticket, issue, or message, and later be interpreted during a legitimate task. The agent does not need to be directly attacked at the moment of compromise. Instead, the payload survives as contextual content until the agent reaches another system and acts on it. That delayed activation is hard for conventional monitoring to spot because every individual step may look permitted. In practice, the exploit is a sequencing problem as much as a content problem: malicious text becomes executable only when the agent reuses it across systems.
Practical implication: separate content ingestion from action execution and inspect cross-system task transitions for hidden instructions.
Threat narrative
Attacker objective: The attacker wants to convert one trusted agent session into a bridge that moves data and actions across separate systems without fresh authorization.
- Entry begins when an attacker plants malicious instructions in a legitimate external input such as a contact form, issue, or email that an agent later processes.
- Credential access occurs through the user's existing authenticated sessions and delegated tool permissions, which the agent can reuse across systems.
- Escalation and lateral movement happen when the agent carries context from one system into another and performs read and write actions under a unified operational identity.
- Impact is achieved when the agent exfiltrates data, distributes phishing content, spreads malware, or performs other unauthorized cross-system operations.
Breaches seen in the wild
- AI LLM hijack breach: attackers used stolen AWS access keys to hijack Anthropic LLM models on Bedrock.
- Storm-2949 Azure Breach: Storm-2949 social engineering attack turns one cloud identity compromise into full Azure tenant breach.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
IdentityMesh is not just a tool-integrity problem, it is a boundary-collapse problem. The research shows that agentic systems can merge authenticated contexts into one operational identity, which breaks the assumption that each system boundary is separately preserved. Once that assumption fails, traditional per-application authorization no longer describes the real risk surface. Practitioners should treat the agent session itself as the new boundary object.
Single-identity architecture is a necessary design principle, but only if the agent truly stops at one trust domain. The article shows that multi-system agents can inherit privileges from different services and act as if they belong to one user-plane. That creates identity blast radius: a single compromised or manipulated task can span email, ticketing, documentation, and code platforms. The governance implication is that access scope must be reasoned about at the orchestration layer, not only at the backend system layer.
Allow-always modes create permission persistence that outlives user intent. The Lasso Security findings show how one-click approval and YOLO-style interaction models widen the attack window for cross-system abuse. That is not merely a UX defect; it is a governance failure that weakens accountability for every downstream action the agent takes. Security teams should regard persistent approval paths as identity amplification mechanisms, not convenience features.
IdentityMesh exposes a named concept: cross-system identity mesh. In this pattern, separate credentials and sessions behave like one merged execution fabric because the agent carries context across tools without revalidating trust between them. The result is not simple privilege abuse but an operational mesh where information and actions flow freely across systems. Practitioners need to design for explicit context separation if they want agentic systems to remain governable.
Agentic AI governance now has to cover lateral movement, not just prompt safety. The article makes clear that malicious outcomes come from the interaction of read tools, write tools, and hidden instructions, not from prompts alone. That means IAM, NHI, and AI governance teams need a shared control model for cross-system execution paths. The field is moving from input filtering to identity-bound orchestration controls.
From our research library:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Guide
What this signals
Cross-system identity mesh: Agentic systems need controls that preserve separation between authenticated contexts, because once read and write tools can bridge systems under one session, the agent becomes the transport layer for lateral movement rather than a simple assistant. That shifts governance from per-tool approval to cross-boundary execution control.
Organizations that already manage NHIs, service accounts, and delegated tokens should recognise the same pattern here: the risk is not just credential misuse, but the collapse of intended scope when one identity can act across multiple environments. The operational question is whether the programme can prove that agentic sessions remain bounded at the point of action, not after the fact.
The 2026 Infrastructure Identity Survey found that 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey. That shift is no longer theoretical when a single user request can become cross-system movement across internal and customer-facing tools.
For practitioners
- Disable persistent approval modes Remove allow-always and YOLO-style settings from agent deployments so each cross-system action requires explicit review.
- Separate read and write privileges by system Do not let the same agent session both collect sensitive data from one system and write to a different system without a fresh authorization boundary.
- Restrict cross-origin browser agent behaviour Treat browser-integrated agents as a distinct control surface and limit their ability to move between authenticated web applications under one session.
- Inspect ticket and issue content for hidden instructions Add review steps for externally supplied content that could later be executed by an agent as part of a different workflow.
- Redesign for single-purpose agent identities Assign each agent a narrowly scoped identity and prevent permission consolidation across email, chat, ticketing, documentation, and code systems.
Key takeaways
- IdentityMesh shows that agentic systems can collapse multiple authenticated contexts into one operational identity, creating a lateral movement path across otherwise separate services.
- The article demonstrates impact across data exfiltration, phishing, malware distribution, and browser-based cross-origin abuse, so the risk is broader than a single workflow defect.
- The control failure is loss of boundary enforcement at the agent layer, which means practitioners must govern cross-system execution instead of assuming per-application permissions are enough.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK define the specific risk controls and attack patterns relevant to this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The exploit depends on agents reusing and merging privileges across systems. |
| ASI07 — Insecure Inter-Agent Communication | Cross-system content propagation is central to the attack chain. | |
| Recommendation — Constrain agent identities so cross-system privilege cannot be merged into one operational context. Validate and segregate inter-agent messages before they can trigger actions in other systems. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The attack exploits authentication assumptions that do not survive context switching across tools. |
| NHI-05 — Overprivileged NHI | The same agent can accumulate excessive effective access across multiple platforms. | |
| Recommendation — Bind authentication to each system boundary and reject inherited trust across agent sessions. Reduce each agent identity to the minimum access needed for a single bounded task. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The research centers on credential reuse and movement across systems. |
| Recommendation — Map agent cross-system abuse to TA0006 and TA0008 to prioritise detections around context bridging. | ||
Key terms
- Identity Mesh: A merged operational state where one AI agent effectively carries multiple authenticated identities across different systems. In practice, this collapses trust boundaries that were assumed to be separate, allowing a single workflow to read in one system and act in another without a fresh authorization decision.
- Cross-System Lateral Movement: The movement of an attacker or malicious workflow from one trusted environment into another using legitimate access paths. In agentic systems, this often happens when the agent is allowed to repurpose context or data across tools, turning normal interoperability into an attack path.
- Indirect Prompt Injection: Indirect prompt injection is an attack where malicious instructions are hidden inside content that an AI system reads later. The model may treat that content as context rather than as hostile input, which can influence tool use, data access, or workflow actions if controls are weak.
- Agentic boundary control: A governance control that preserves separation between systems, sessions, and permissions when an AI agent operates across multiple tools. For agentic systems, this means validating trust at each cross-system transition rather than assuming one user session can safely span every action.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org