TL;DR: Agentic AI is turning scheduled access certification into a weak control because autonomous agents can gain, chain, and change authority between review cycles, according to Saviynt. The governance problem is no longer assigned access alone, but whether an identity should still be trusted to act in its current runtime context.
NHIMG editorial — based on content published by Saviynt: From Periodic Reviews to Continuous Trust: Why Agentic AI Forces a Complete Rethink of Access Certification
By the numbers:
- Industry analysts validate this massive shift, predicting that up to 40% of enterprise applications will integrate task-specific AI agents by the end of the year.
- In a modern enterprise network, non-human identities now vastly outnumber human employees by an alarming ratio of 82:1.
- Only 5.7% of organisations have full visibility into their service accounts.
Questions worth separating out
Q: How should security teams govern access-chains in agentic AI environments?
A: Security teams should govern access-chains as the primary unit of control, not isolated entitlements.
Q: Why do AI agents complicate traditional access reviews?
A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.
Q: What breaks when certification is based only on assigned access?
A: The programme misses the difference between paper entitlement and effective authority.
Practitioner guidance
- Redesign certification around runtime trust changes Replace purely quarterly or annual attestations with controls that can flag when an agent's effective authority changes because of new tools, inherited entitlements, or shifted task context.
- Inventory delegated tool paths for every agent Document each MCP connection, inherited credential, and downstream system path so reviewers can see the live authority chain instead of a static approval record.
- Define ownership for drift-triggered remediation Assign a clear decision maker for when an agent exceeds its original trust posture, including when a human manager, policy engine, or combined workflow is responsible for intervention.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- How the vendor frames continuous certification of trust for AI agents in day-to-day identity governance.
- The operational questions raised for identity architects around ownership, remediation, and alert fatigue.
- The product context behind identity security for AI agents, including the implementation lens the source article only references.
- The surrounding commentary on how the vendor positions agentic AI governance within its platform view.
👉 Read Saviynt's analysis of continuous trust for agentic AI access certification →
Agentic AI certification gaps: what IAM teams need to change?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Access certification was designed for stable identities, not for actors whose authority changes mid-session. That assumption holds when privilege is tied to a human role or a service account with a mostly fixed operating pattern. It fails when an agent can gain new tools, new relationships, and new execution paths after approval. The implication is that certification is no longer a complete governance answer for autonomous behaviour, even when the original entitlement record is accurate.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: Who should own remediation when an AI agent's trust posture drifts?
A: Ownership should be explicit before deployment, not improvised during an incident. The accountable party may be a manager, an automated policy engine, or a hybrid workflow, but the organisation must define who can interrupt the agent, who can approve recovery, and who records the governance decision.
👉 Read our full editorial: Agentic AI breaks point-in-time access certification models