TL;DR: As organisations deploy AI agents that act on behalf of users, the core security problem shifts to authenticated identity, delegated authority, and revocation, according to WorkOS. Data governance still matters, but agentic systems fail fastest when identity controls cannot define who the agent represents, what it may do, and when that authority ends.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Concentric AI vs WorkOS: Data Governance vs Identity for Agentic Security”.
Key questions
Q: What breaks when AI agents are given broad inherited permissions?
A: Broad inherited permissions break the assumption that access is tied to a narrow business need.
Q: Why do AI agents require stronger identity controls than standard applications?
A: AI agents can choose actions, call tools, and chain operations, so their identity is not just a login mechanism.
Q: How do security teams know if agent authorization is actually working?
A: Authorization is working only if the agent can complete the intended task without gaining unnecessary reach.
Practitioner guidance
- Define agent identity before data access Map every AI agent to a named human, service, or business context before it can inherit permissions.
- Scope delegated permissions by task and context Replace broad inherited access with explicit permission boundaries tied to business function, session context, and trigger conditions.
- Treat revocation as an operational control Ensure permissions can be withdrawn immediately when the user changes role, leaves the organisation, or the task completes.
Bottom line: The article’s central point is that AI agents change the security model by making identity, delegation, and revocation the first governance questions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity is the control boundary for agentic systems: AI agents inherit risk from the authority they are granted, not just from the data they touch. Data-centric controls can reduce leakage, but they cannot answer the foundational governance question of who the agent is acting for and whether that authority is still valid. The implication is that agentic security programmes must start with identity governance, not treat it as an afterthought.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations prioritise identity governance before expanding agentic AI?
A: Yes. Organisations should establish ownership, least privilege, monitoring, and revocation for machine identities before broadening agentic AI use. Without those controls, each new agent can multiply blast radius and create shadow access that is hard to unwind after an incident.
👉 Read our full editorial: Agentic security needs identity first, not data controls alone