TL;DR: AI agents now operate directly in enterprise systems, but broad OAuth reuse, standing grants, and weak audit trails leave teams unable to explain or constrain agent actions, according to Oasis Security. Its agentic access model turns requests into short-lived, policy-evaluated sessions with end-to-end accountability. The governing assumption that access can be reviewed after the fact breaks when agents act within a single session.
At a glance
What this is: This is a product announcement about agentic access management, with the key finding that AI agent access becomes governable only when each action is evaluated as a short-lived, policy-scoped session.
Why it matters: It matters because IAM, PAM, and NHI teams now have to govern agent actions at request time, not after broad delegated access has already been granted and used.
Context
AI agent governance fails when teams assume access can be granted broadly and reviewed later. In practice, these systems act inside enterprise tools through delegated OAuth, reused human access, or inherited permissions, which makes post-hoc auditing too late to explain intent or constrain scope.
The governance problem is not that agents are new, but that they sit on top of existing NHI and human access patterns without a clean control boundary. That turns agent activity into an identity governance problem across service identities, permissions, and approval evidence, especially when the same systems already support cloud, SaaS, and production workflows.
Key questions
A: Teams should treat delegated OAuth and reused human access as transitional, not final, controls. The practical step is to enumerate every agent connection, identify which permissions are broader than the task, and move high-risk workflows toward request-scoped authorization with ephemeral identities and explicit policy evaluation.
Q: Why do standing grants create more risk for AI agents than for ordinary application workflows?
A: Standing grants create more risk because agent behaviour is task-driven and variable, while the permissions remain persistent and broad. That mismatch expands blast radius, makes intent harder to prove, and leaves access in place after the workflow ends, which is exactly what identity governance is supposed to avoid.
Q: What are the signs that an agent governance programme is failing?
A: Common signals include unknown agents in staging or production, unvetted MCP connections, broad or long-lived credentials, and logs that show service-account activity without clear ownership. If the security team cannot map the agent to a tool chain and accountable owner, governance is already behind the deployment.
Q: What is the difference between ephemeral agent identities and traditional access reviews?
A: Ephemeral identities govern access before and during execution, while access reviews verify access after it has already existed. For AI agents, that difference matters because the access may be created and destroyed within a single session, leaving little or nothing meaningful to recertify after the fact.
How it works in practice
How intent becomes a governed agent session
Oasis describes an intent-aware flow in which a prompt, tool call, or action plan is translated into structured intent before any access is granted. That intent is then evaluated against policy, including resource, operation, scope, and purpose, rather than letting the model act directly on inherited credentials. If approved, the system issues an ephemeral identity that exists only for the task and is torn down when the task ends. The mechanism matters because it replaces static delegation with per-action authorization.
Practical implication: authorisation decisions for AI agents need to move from account provisioning to request evaluation.
Why delegated OAuth and reused human access fail for agents
Delegated access works tolerably when the acting subject is a person following a predictable workflow, but agent behaviour breaks that assumption. Reused human permissions, broad OAuth grants, and standing access paths all outlive the specific task the agent is performing. That creates a widened blast radius because the agent can touch more systems and more data than the original request required. The article’s core technical point is that broad grants are not just over-permissioned, they are structurally non-specific to the agent’s actual intent.
Practical implication: inventory which agent connections still depend on borrowed human or application grants, then narrow them to task scope.
Prompt-level audit trails and chain of custody
The access model is also about evidence, not only authorization. Oasis describes a chain of custody from human to agent to prompt to intent to policy to identity to actions and results. That is materially different from a normal log trail because it preserves the reason an action was allowed, not just the action itself. For compliance and security operations, the useful signal is whether a specific prompt can be linked to a specific permission decision and a bounded identity session.
Practical implication: require traceability from prompt to permission decision so agent activity can be investigated and explained.
NHI Mgmt Group analysis
Agentic access management exposes the collapse of post-hoc access review. Access review processes were built on the assumption that privilege persists long enough to be observed, recertified, and revoked. That assumption fails when an AI agent can receive, use, and discard access inside a single task. The implication is not simply more logging, but a shift in where control must sit: at issuance time, not review time.
Standing grants are becoming identity blast-radius multipliers for agentic systems. When agents inherit OAuth tokens or human permissions, the resulting access path is larger than the business task that triggered it. The access scope is no longer tied to the purpose of a single action, so one prompt can produce broad downstream reach across SaaS, cloud, and internal platforms. Practitioners should treat scope mismatch as the core governance defect, not a secondary configuration issue.
Prompt-level accountability is now part of identity governance. The article is pointing to a control model where policy decisions must be reconstructable from intent, not just from logs. That changes the evidence standard for AI governance, because auditors and security teams need to know why access existed, not only that it was used. For teams running mixed human, NHI, and agentic estates, the governance boundary has to cover the decision chain end to end.
Agentic access management and NHI governance are converging into one control plane. The vendor frames AAM as extending NHI governance to agents, which reflects a broader market shift: machine identities, service identities, and AI agents are increasingly governed through the same access lifecycle. That convergence should push IAM leaders to stop separating workload identity, delegated access, and agent governance into disconnected programmes. The practical conclusion is a unified entitlement model with task-scoped issuance and consistent offboarding semantics.
Ephemeral credential trust debt is now a named operating risk. Short-lived credentials reduce standing exposure, but they also reveal how much trust organisations have accumulated in reused grants, inherited permissions, and opaque delegation paths. When those paths are not explicit, the real problem is not the credential lifetime but the hidden dependency chain behind it. Teams should re-evaluate whether current governance can explain every agent access path before the next workflow goes live.
From our research library:
- Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, and that 15% of day-to-day work decisions will be made autonomously.
- Read next: Agentic AI Identity Guide
What this signals
Prompt-level governance is becoming the practical boundary for AI agents. Teams that still govern agents through broad delegated access will struggle to explain action scope, especially when the same request can touch SaaS, cloud, and internal systems in one workflow. The useful control point is now the request itself, not the account that happens to execute it.
Agentic access management is converging with NHI governance rather than replacing it. The governance model for service identities, workload identities, and AI agents is starting to look structurally similar: task-scoped access, explicit purpose, and deterministic policy evaluation. That makes identity architecture, not just AI tooling, the programme boundary that practitioners need to rework.
For practitioners
- Map every agent access path Identify where AI agents still rely on delegated OAuth, reused human access, or inherited application permissions, then trace each path to the underlying enterprise systems and data it can reach.
- Replace standing grants with task-scoped issuance Require short-lived identities that are evaluated per request and destroyed after the task completes, so an agent cannot keep broad access between actions.
- Bind approvals to structured intent Capture the resource, operation, scope, and purpose for each agent request before permission is granted, and use that record as the basis for policy decisions and investigations.
- Build prompt-to-action audit chains Preserve a chain of custody from human request through agent prompt, policy decision, identity issuance, and resulting actions so security and compliance teams can explain every access event.
Key takeaways
- AI agents become materially harder to govern when they inherit broad permissions that were never designed for task-specific execution.
- The control problem is not only access volume, but the inability to reconstruct intent, scope, and approval after the action has already happened.
- Practitioners should move agent governance to request time, with ephemeral identities, bounded scope, and evidence that ties each action to policy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on agent permissions, delegated access, and scope control for AI agents. |
| Recommendation — Constrain agent privileges to task scope and verify every permission decision against policy. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Agent access depends on how identities are authenticated and granted access to enterprise systems. |
| NHI-05 — Overprivileged NHI | The article explicitly warns against broad, inherited, and standing permissions for agents. | |
| Recommendation — Replace broad delegated access with task-scoped authentication and bounded session issuance. Reduce agent entitlements to the minimum operation and resource set required for each request. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post is fundamentally about governing permissions, entitlements, and authorization decisions for agents. |
| Recommendation — Apply entitlement governance at request time so access aligns with approved purpose and scope. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | Broad agent grants increase the reach of compromised or misused credentials across enterprise systems. |
| Recommendation — Map broad agent grants to credential access and lateral movement risk in your detection and control model. | ||
Key terms
- Agentic Access: Agentic access is delegated system access granted to an AI agent or autonomous workflow so it can perform defined tasks across tools and data sources. It differs from human access because the actor can execute continuously, combine actions quickly, and amplify mistakes at scale.
- Dynamic Ephemeral Identity: Dynamic Ephemeral Identity is a model in which credentials or authority exist only for a short operational window and are generated at runtime. It reduces the value of exposed secrets, but only if the environment can also limit what the identity is allowed to do while active.
- Interaction-Level Audit Trail: A record that captures the full AI session rather than only network traffic or file events. It ties the prompt, model response, identity, and policy response together so auditors can reconstruct what happened and why the control acted the way it did.
- Standing Grant: A standing grant is access that remains active after the moment it was approved. In SaaS and identity environments, it often comes from OAuth consent, delegated permissions, or service accounts that persist long after the original business need has faded. Standing grants increase blast radius and complicate revocation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org