TL;DR: Agentic systems are moving into production with autonomous access to enterprise data, but existing human-centric governance models assume stable roles and predictable access patterns, according to BigID. The governance gap is no longer just visibility, it is that policy must be defined around data, identity type, and runtime behaviour before agents can operate safely.
NHIMG editorial — based on content published by BigID: declarative governance for agentic systems
Questions worth separating out
Q: How should security teams govern agentic systems that access sensitive data?
A: Start with declared policy for what data is sensitive, which identities may access it, and what conditions make the access acceptable.
Q: Why do traditional IAM controls struggle with autonomous AI agents?
A: Traditional IAM assumes predictable users or static machine accounts, but AI agents can act independently, interact with multiple systems, and generate new access needs over time.
Q: What is the difference between access visibility and access governance?
A: Access visibility tells you who or what has access, while access governance decides whether that access should exist and for how long.
Practitioner guidance
- Define data-centric policies before expanding agent use Classify sensitive data, then specify which human, non-human, or autonomous identities may access it, where it may flow, and what behaviour counts as over-privilege or over-exposure.
- Correlate identity, entitlement, and data context Unify access visibility across cloud storage, SaaS, file shares, and data platforms so teams can see which identities accessed which data and under what entitlement conditions.
- Treat monitoring as a governance control Use data activity monitoring to compare actual behaviour against declared policy, especially where agents can move or copy large volumes or propagate errors at scale.
What's in the full article
BigID's full analysis covers the operational detail this post intentionally leaves for the source:
- Data-centric policy examples for sensitive data access across human and non-human identities.
- Operational discussion of how continuous observation and intervention work in agentic environments.
- Examples of how BigID correlates identity, permissions, and data activity across cloud and SaaS.
- The vendor's specific framing of declarative governance for data and AI security teams.
👉 Read BigID's analysis of declarative governance for agentic systems →
Agentic systems and data-centric governance: are controls keeping up?
Explore further
Declarative governance is the right control model for agentic behaviour. Static access control assumes that the important decision is made at provisioning time. That assumption fails when the actor can keep selecting actions, data, and timing during runtime. The implication is that governance must shift from permission assignment to continuously validated intent.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: How can organisations respond when agent behaviour falls outside policy?
A: They should use preplanned interventions that match the sensitivity of the data and the severity of the deviation. That can include tightening access, quarantining data, and triggering guided remediation workflows. The key is to make response proportional and policy-driven rather than manual and ad hoc.
👉 Read our full editorial: Declarative governance for agentic systems: why IAM controls fall short