Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic security in practice: are your identity controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13274
Topic starter  

TL;DR: Agentic systems now make decisions, take actions, and touch third-party systems faster than conventional IAM and review cycles can govern, according to Cyberhaven. Cyberhaven describes autonomous security agents used for vulnerability triage, threat modeling, and IT support, including a triage system that reduced false positives by 85%, a design review agent covering 100% of architectural designs, and an IT agent that resolved more than 70% of routine tickets without human intervention.

NHIMG editorial — based on content published by Cyberhaven: Inside a CISO's Playbook, What Agentic Security Looks Like in Practice

By the numbers:

Questions worth separating out

Q: How should security teams govern autonomous agents that use backend tools?

A: Treat autonomous agents as identities with their own scopes, policies, and revocation paths.

Q: Why do AI agents complicate traditional access reviews?

A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.

Q: What breaks when an AI agent can remediate issues directly in SaaS tools?

A: The boundary between recommendation and action breaks first.

Practitioner guidance

  • Define runtime authority boundaries for each agent Map every autonomous agent to the exact actions, tools, and external systems it can touch during execution.
  • Classify agent access as privileged operational access Review integrations with Okta, Slack, ticketing, code, and security tooling as privileged pathways.
  • Audit review cadences against agent decision speed Test whether access certification, recertification, and exception handling can still observe the state an autonomous agent uses before it changes.

What's in the full report

Cyberhaven's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • How Cerberus cross-checks findings across Anthropic, OpenAI, and Google models before issuing a verdict
  • How Vektr applies STRIDE inside the RFC review process to generate threat models for architecture designs
  • How Jarvis executes directly in Okta and other third-party systems to resolve routine IT tickets
  • How the Office of the CISO structured collaboration between autonomous agents and human reviewers

👉 Read Cyberhaven's whitepaper on autonomous security agents in the CISO playbook →

Agentic security in practice: are your identity controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
Share: