Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agent IAM readiness: what identity teams need to fix now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Most organisations are still unprepared for agentic AI identity because authentication, authorisation, and compliance controls were designed for human-paced or static machine access, according to Ory. The governance problem is not just access scale but the assumption that identity behaviour can be reviewed and approved before execution.

NHIMG editorial — based on content published by Ory: Agent IAM Agentic AI Identities – Is Your Organization Prepared?

Questions worth separating out

Q: How should security teams govern agent IAM when agents make runtime decisions?

A: They should treat the agent as a distinct identity class with its own delegated scope, session boundaries, and approval rules.

Q: Why do traditional IAM controls struggle with agentic identity?

A: Traditional IAM assumes access can be reviewed and governed as a stable entitlement.

Q: What breaks when authorisation is based only on the agent's starting permissions?

A: You lose sight of authorisation drift.

Practitioner guidance

  • Define a separate agent identity control plane Map which controls apply to human users, which apply to non-human identities, and which must be added for runtime agent behaviour.
  • Review authorisation models for runtime drift Test whether current policy engines can handle an agent that changes tool use or task sequence mid-session.
  • Instrument audit trails with governance context Capture approved scope, session boundaries, and escalation conditions alongside raw logs.

What's in the full article

Ory's full article covers the operational detail this post intentionally leaves for the source:

  • Practical explanation of how the Agent IAM model is positioned for authentication, authorisation, and compliance workflows.
  • Implementation context for teams evaluating identity controls around autonomous decision-making systems.
  • Editorial framing on why most organisations remain unprepared for agentic AI identity risk.
  • Additional operational detail on the identity and access management challenges that agentic AI introduces.

👉 Read Ory's analysis of Agent IAM and agentic AI identity readiness →

Agent IAM readiness: what identity teams need to fix now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Agent IAM is becoming a distinct governance layer, not a feature of existing IAM. Agentic systems change the unit of control from user or workload to runtime-decisioning software, which means access, assurance, and accountability have to be designed together. Existing IAM tools can still authenticate and authorise, but they do not automatically govern the behavioural layer that agentic systems introduce. The implication is that identity programmes now need a separate operating model for agent identities.

A few things that frame the scale:

  • From our research: 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to the AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Which identity evidence do auditors need for agent IAM?

A: Auditors need more than activity logs. They need approved scope, execution boundaries, escalation rules, and records showing when delegated authority changed. Without that context, the organisation can describe what the agent did but cannot demonstrate whether the access was still legitimate at the time of action.

👉 Read our full editorial: Agent IAM readiness is lagging behind autonomous AI adoption



   
ReplyQuote
Share: