Join our Newsletter — 33% off our NHI Course

AI agent access visibility: what IAM teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agents are scaling faster than many enterprises can map their underlying access, and one case study found 400 GPTs, 250+ active agents, and multiple high-risk exposures across BigQuery, Jira, and shared data sources, according to Astrix Security. The real control problem is not orchestration but identity-layer visibility, because governance cannot work when teams do not know what agents can reach.

Editorial analysis by NHI Mgmt Group, based on content published by Astrix Security: “How a Major Enterprise Implemented a Control Plane Layer for AI Agents Using NHI Security”.

By the numbers:

  • The organisation gave enterprise licenses to 200 developers within a broader engineering organisation of thousands.
  • Within the first week, Astrix uncovered 250+ GPTs active in the environment.
  • About 10% of the GPTs had direct API access to external systems such as BigQuery and Atlassian.

Key questions

Q: What breaks when AI agents are given access without identity governance?

A: What breaks is accountability.

Q: When does AI agent access create more risk than it reduces?

A: AI agent access creates more risk when the business benefit depends on broad permissions, weak ownership, or uncontrolled tool invocation.

Q: How do security teams know if agent governance is actually working?

A: It is working only if the team can answer three questions quickly for any agent: what it can reach, what it did recently, and whether that behaviour matches intent.

Practitioner guidance

  • Build an agent-to-identity inventory Catalogue every AI agent alongside the API keys, OAuth tokens, service accounts, and integrations it uses.
  • Reconcile agent access with system ownership Assign a business and technical owner to each credentialed access path, then remove any agent connections that cannot be attributed to a responsible team.
  • Scope agent privileges to least access Review whether agents have admin-level or broad read access to production data stores, collaboration tools, and analytics platforms, and reduce scopes that exceed the task.

Bottom line: AI agent control planes fail when organisations can see activity but not the non-human identities that authorize access.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Identity visibility is the control plane, not a supporting feature. A governance model for AI agents fails if it starts with orchestration and monitoring but cannot enumerate the non-human identities that actually grant access. The article shows that access control was already breaking before any malicious activity was needed. Practitioners should treat identity inventory as the control plane's foundation, not its sidecar.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Should organisations treat AI SOC agents like governed identities?

A: Yes, because the practical risk is delegated access, not just model output. If an AI agent can read evidence, prepare actions, or trigger connected tools, it needs scoped permissions, defined task boundaries, and revocation when the workflow ends. That is the identity control model SOC teams already use for other non-human actors.

👉 Read our full editorial: AI agent control planes fail when identity visibility is missing


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.