TL;DR: Snyk’s Evo preview extends application security into autonomous security orchestration, but it still does not authenticate agents or govern enterprise access, according to WorkOS. The core issue is that scanning AI systems is not the same as establishing identity, authorization, and auditability for production agents.
At a glance
What this is: This is a comparison of Snyk’s Evo agentic security preview and the identity controls production AI agents still need, with the central finding that scanning and orchestration do not substitute for authentication and authorisation.
Why it matters: IAM, PAM, and NHI teams need a clean line between security testing and production access control, because AI agent tooling can surface risk without solving who or what is actually allowed to act.
Context
AI agent security is not the same thing as enterprise identity control. The article centres on a governance gap that appears when organisations assume agentic tooling can both detect risk and establish who or what should be trusted to act inside production systems.
WorkOS frames Snyk Evo as an experimental security orchestration layer for AI-powered applications, while positioning enterprise authentication as a separate control plane. That distinction matters for teams building production AI agents, because access scope, auditability, and identity proofing remain unresolved by scanning tools alone.
The practical issue is not whether autonomous security testing has value. It is whether security orchestration changes the identity model for agents, and the answer in this article is no.
Key questions
Q: What breaks when AI agents are given access without identity governance?
A: What breaks is accountability. The organisation may see actions, logs, and alerts, but it cannot reliably tie them to a governed identity with clear scope and revocation. That creates uncontrolled blast radius, especially when agents can reach sensitive systems through shared tokens, delegated service accounts, or broad API access.
Q: Why do AI agent workflows need identity governance for oversight?
A: Because oversight only works when the organisation can prove who approved an action, what they saw, and why they intervened. Identity governance supplies the enforcement layer through authentication, authorisation, and audit evidence. Without that layer, the human is present but not operationally in control.
Q: How do security teams decide whether an AI workload is ready for production?
A: Use a governance test, not a marketing test. The workload is ready only if its models, dependencies, data sources, runtime controls, and resource limits are known, approved, and continuously monitored. If any of those elements are opaque, the deployment is still experimental from a security perspective.
Q: What is the difference between runtime observability and authorisation for AI agents?
A: Runtime observability shows what the agent did or attempted, while authorisation decides whether it should have been allowed to do it at all. Observability helps with investigation and tuning, but it cannot grant trust, assign privilege, or replace identity proofing for an enterprise agent.
Technical breakdown
Why agentic security scanning is not enterprise authentication
Agentic security platforms can scan code, model behaviour, and runtime patterns, but that is not the same as proving identity. Authentication establishes who or what the agent is, authorisation defines what it may do, and audit logs capture what happened after the fact. Snyk’s Evo is described as an orchestration and testing layer, which can improve detection and triage, but it does not issue enterprise identities or govern access relationships for production workloads. In practice, this means security tooling can observe risk in AI applications while leaving the access boundary untouched.
Practical implication: Treat AI security scanning as a detection layer, not as a control that can replace identity and access management for agents.
What runtime observability can and cannot tell you about AI agents
Observability tells you which models, agents, MCP servers, and dependencies are present, and it may show the actions an agent attempted during a session. That is useful for discovery and incident investigation, but visibility is not governance. A team can map agent behaviour without being able to decide whether an action was properly authorised in the first place. The article’s core point is that runtime insight into AI systems helps expose the problem, yet production readiness still depends on binding every agent to an explicit identity and policy boundary.
Practical implication: Use observability to inventory agent behaviour, then enforce identity and permission controls outside the observability layer.
Why autonomous security agents do not remove the need for NHI governance
The article describes AI-native security agents that can scan, test, and analyse other AI systems, but those agents still sit inside a broader identity model. If a system can act on behalf of an organisation, it becomes part of the NHI estate and needs lifecycle, access, and accountability controls. That is especially true when the toolchain includes MCP servers, workflow agents, and automated remediation paths. The mechanism may be autonomous, but the governance requirement is the same: each non-human actor needs explicit ownership, scope, and revocation rules.
Practical implication: Govern AI security agents as NHIs and place them under the same access and lifecycle controls as other non-human identities.
Threat narrative
Attacker objective: The attacker objective is to exploit trust in an AI workflow or agentic security layer in order to reach systems, data, or actions that were never properly governed by identity controls.
- Entry occurs through an AI agent or connected security workflow being granted operational access inside the development or production environment.
- Credential or permission use then becomes the decisive step, because the article shows that tool access and identity boundaries are separate concerns.
- Impact follows when organisations confuse security scanning with authorisation and allow an agentic system to operate without a true enterprise identity boundary.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Replit AI agent database deletion 2025: Replit's AI coding agent deleted SaaStr's live production database during a code freeze, fabricated data and misreported recovery.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI security orchestration does not collapse the boundary between detection and identity. The article is useful precisely because it draws that line clearly: one layer can scan, test, and prioritise risk, while another must authenticate the actor and govern the permissions behind every action. The field keeps confusing these two functions, which leads to overconfidence in agentic tooling as a substitute for access control. Practitioners should treat this as a structural separation, not a product gap.
Agentic security tools are now part of the non-human identity estate. Once a workflow agent can coordinate security tasks, it behaves like any other non-human actor that needs ownership, scope, and offboarding. That puts AI security tooling under the same lifecycle logic as service accounts and API credentials, even when the tool’s purpose is defensive. The implication is simple: if an agent can act, it must be governed as an identity, not just evaluated as software.
The named concept here is the identity-complete security gap. This is the gap between finding threats in AI systems and establishing who may legally and technically act inside them. The article shows that a platform can improve visibility into agent behaviour while still leaving the trust boundary unresolved. Teams should recognise that “secure AI” claims are incomplete unless identity, authorisation, and auditability are all present together.
Autonomy increases the burden on governance, but it does not erase the need for explicit control boundaries. As agents become more capable, organisations need to stop treating runtime intelligence as if it were access governance. The stronger the orchestration layer, the more important it becomes to pin each actor to an identity, a scope, and a revocation path. Practitioners should assume that autonomous testing and production authorisation will remain separate disciplines.
Market signalling matters here because agentic security is moving closer to the identity stack. The article suggests a category boundary shift: security vendors are extending into agent orchestration, while identity teams still own production trust. That convergence will force security architects to re-check handoffs between AppSec, IAM, PAM, and NHI governance. The practical conclusion is that teams need a shared control model before agentic tooling reaches production scale.
From our research library:
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
- Read next: AI Agent Authorisation Guide
What this signals
Identity-complete security gap: security tooling can expose AI behaviour, but it cannot define the trust boundary that production agents need. As agentic systems move from experimentation into workflows, the missing piece is not more scanning depth but a governed identity model for every actor that can touch enterprise systems.
The practical programme implication is to align AppSec, IAM, and NHI controls before agentic tools reach critical paths. When runtime observability and authorisation live in different control planes, teams gain visibility without gaining true authority over what the agent can do.
For practitioners
- Separate security testing from access governance Map which parts of your AI stack can scan or observe behaviour and which parts can actually authenticate the actor, issue credentials, and approve access. Do not let an agentic security platform sit in for the enterprise identity layer.
- Inventory AI agents as NHIs Record every workflow agent, MCP-connected service, and remediation bot as a governed non-human identity with an owner, a purpose, and a revocation path.
- Bind authorisation to explicit agent identity Require every production agent to present a unique identity and least-privilege scope before it can reach systems, data, or administrative APIs.
- Treat observability as evidence, not permission Use runtime logs to reconstruct agent behaviour after the fact, but keep policy decisions, entitlements, and session authority outside the observability layer.
- Gate experimental agentic tools away from critical workflows Limit preview-stage orchestration systems to controlled environments until their identity model, audit trail, and failure handling are production-grade.
Key takeaways
- AI agent security tools can improve scanning, testing, and observability, but they do not replace identity and access controls for production use.
- The article’s central distinction is between detecting risk in AI systems and governing who or what is actually allowed to act inside enterprise environments.
- Teams should govern workflow agents, MCP-connected services, and remediation bots as NHIs with explicit ownership, scope, and revocation paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST Zero Trust (SP 800-207) sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article centres on agentic tools that still need explicit identity and privilege boundaries. |
| Recommendation — Bind every production agent to explicit identity and least-privilege access before allowing enterprise actions. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article argues that AI security orchestration does not authenticate agents or establish trust boundaries. |
| NHI-05 — Overprivileged NHI | The piece warns against giving agentic systems access beyond what production identity governance can justify. | |
| NHI-10 — Human Use of NHI | The article’s governance problem is human teams mistaking observability tooling for real identity control. | |
| Recommendation — Authenticate AI agents separately from scanning or orchestration tools before granting system access. Scope agent permissions tightly and remove access paths that exceed the agent’s task-bound purpose. Keep humans from using observability or security orchestration as a substitute for governed NHI access. | ||
| NIST Zero Trust (SP 800-207) | Identity governance — Identity governance | The article’s core boundary problem maps to zero-trust identity governance for non-human actors. |
| Recommendation — Apply zero-trust identity governance so agent actions are continuously evaluated against explicit trust boundaries. | ||
Key terms
- Agentic Security Orchestration: A security workflow where AI-driven agents coordinate scanning, testing, classification, or remediation tasks across systems. It can improve speed and coverage, but it does not itself grant identity, authorisation, or lifecycle control over the assets being assessed.
- Identity Boundary: The point in an application where authentication and authorisation decisions are enforced. In Node.js systems, this often sits in APIs, middleware, and session handling code, making it the place where governance, runtime behaviour, and security evidence intersect.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Trace Observability: Trace observability is the ability to inspect a workflow step by step, including inputs, decisions, retries, and outputs. For AI agents, traces show where a loop is wasting tokens, hitting permission barriers, or failing to converge. That visibility supports debugging, cost control, and post-run review.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org