Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic security in practice: are your identity controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19415
Topic starter  

TL;DR: Agentic systems now make decisions, take actions, and touch third-party systems faster than conventional IAM and review cycles can govern, according to Cyberhaven. Cyberhaven describes autonomous security agents used for vulnerability triage, threat modeling, and IT support, including a triage system that reduced false positives by 85%, a design review agent covering 100% of architectural designs, and an IT agent that resolved more than 70% of routine tickets without human intervention.

NHIMG editorial — based on content published by Cyberhaven: Inside a CISO's Playbook, What Agentic Security Looks Like in Practice

By the numbers:

Questions worth separating out

Q: How should security teams govern autonomous agents that use backend tools?

A: Treat autonomous agents as identities with their own scopes, policies, and revocation paths.

Q: Why do AI agents complicate traditional access reviews?

A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.

Q: What breaks when an AI agent can remediate issues directly in SaaS tools?

A: The boundary between recommendation and action breaks first.

Practitioner guidance

  • Define runtime authority boundaries for each agent Map every autonomous agent to the exact actions, tools, and external systems it can touch during execution.
  • Classify agent access as privileged operational access Review integrations with Okta, Slack, ticketing, code, and security tooling as privileged pathways.
  • Audit review cadences against agent decision speed Test whether access certification, recertification, and exception handling can still observe the state an autonomous agent uses before it changes.

What's in the full report

Cyberhaven's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • How Cerberus cross-checks findings across Anthropic, OpenAI, and Google models before issuing a verdict
  • How Vektr applies STRIDE inside the RFC review process to generate threat models for architecture designs
  • How Jarvis executes directly in Okta and other third-party systems to resolve routine IT tickets
  • How the Office of the CISO structured collaboration between autonomous agents and human reviewers

👉 Read Cyberhaven's whitepaper on autonomous security agents in the CISO playbook →

Agentic security in practice: are your identity controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 19006
 

Agentic security creates an identity governance gap, not just a productivity gain. The moment a security system can reason and act across tools, the control problem shifts from who is allowed to trigger a workflow to what the actor itself is allowed to decide at runtime. Existing IAM models were built around stable subjects and predictable requests. That assumption weakens when the identity is an agent that can triage, model, and remediate inside one session. The implication is that governance must move from request-based approval to runtime authority boundaries.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What should organisations measure to know whether agentic security is under control?

A: Measure more than output quality. Track which systems each agent can touch, how often it uses those permissions, whether its access expands over time, and whether every action is attributable to a specific task. If the agent's authority grows faster than governance artefacts, the programme is losing control.

👉 Read our full editorial: Agentic security in practice raises new identity governance questions



   
ReplyQuote
Share: