Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI identity: what changes when agents act across systems?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Enterprise AI agents are splitting into company, employee, and agent-to-agent models, and each creates different identity and authorization problems because agents behave more dynamically than static service accounts, according to C1.ai. The core governance issue is that traditional IAM assumes relatively stable identities, while agentic access is ephemeral, cross-system, and harder to audit.

NHIMG editorial — based on content published by C1.ai: The Divergent AI Landscape: Making Sense of Agentic AI

Questions worth separating out

Q: How should security teams govern personal AI assistants that act on behalf of employees?

A: Treat each assistant as a distinct non-human actor with its own identity, policy scope, and audit trail.

Q: Why do agent workflows create more governance risk than standalone models?

A: Agent workflows create more governance risk because they combine reasoning with action.

Q: What breaks when AI agents are given broad inherited permissions?

A: Broad inherited permissions break the assumption that access is tied to a narrow business need.

Practitioner guidance

  • Classify AI agents by operating model Separate app-embedded company agents, user-delegated employee agents, and agent-to-agent workflows before assigning ownership, policy, and audit controls.
  • Constrain delegated permissions below human baseline access Build policy so an employee agent receives only the minimum permissions required for its task, even if the human user has broader rights.
  • Inventory agent trust edges across systems Map every place an agent can request data, trigger actions, or hand off to another agent, then require explicit authorisation for each edge.

What's in the full article

C1.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The article’s full breakdown of the three agent types and the operating model differences between them.
  • The vendor’s examples of how company agents, employee agents, and agent-to-agent flows map to real enterprise workflows.
  • The source post’s discussion of why current IAM assumptions around static identities and long-lived access do not fit agentic systems.
  • The article’s own framing of future authorization frameworks for granular, task-specific permissions.

👉 Read C1.ai's analysis of the divergent agentic AI identity landscape →

Agentic AI identity: what changes when agents act across systems?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Agentic AI identity is not a new branding layer on top of IAM. It is a different operating model that breaks the assumption that identities are stable enough to be governed through static provisioning alone. Once an agent can act across tools and make runtime choices, authorization becomes behavioural rather than purely declarative. The implication is that identity architecture must distinguish between human intent, delegated machine action, and autonomous execution.

A few things that frame the scale:

  • 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which explains why delegated machine access is so often under-governed.

A question worth separating out:

Q: How do IAM teams know whether agentic AI is actually under control?

A: Look for evidence that every agent identity is discoverable, every session has a clear end point, and every high-risk action is observable in context. If the team cannot trace credentials from issuance to retirement, or cannot explain unusual tool use, the programme is not yet governing agentic identity.

👉 Read our full editorial: Agentic AI identity diverges across company, employee, and peer agents



   
ReplyQuote
Share: