Join our Newsletter — 33% off our NHI Course

AI agent agency and identity controls: what IAM teams need

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: At AWS re:Invent 2025, founders and builders reported that 70-80% of code is now AI-written, Intercom’s AI agent resolves 86% of customer conversations without human involvement, and Claude Code is crossing from assistant to agent, according to WorkOS. The identity problem is no longer access to AI tools, but governance for systems that can act on their own.

Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “10 takeaways from AWS re:Invent 2025”.

By the numbers:

  • Multiple founders said 70-80% of code at their companies is now written by AI.
  • Intercom's AI agent resolves 86% of customer conversations without human involvement.

Key questions

Q: What breaks when AI agents can act faster than human approval processes?

A: Human approval workflows lose their value when an autonomous system can chain reconnaissance, credential use, and lateral movement in seconds.

Q: Why do autonomous AI systems create more identity risk than normal automation?

A: Normal automation follows a fixed path, but autonomous systems can interpret goals, choose actions, and continue without waiting for a person.

Q: How can teams tell whether an AI agent is safely governed?

A: A governed AI agent has explicit ownership, narrowly defined tool access, visible decision paths, and tested failure modes under adversarial input.

Practitioner guidance

  • Define the agentic execution boundary Map exactly where an AI system is allowed to move from suggestion into action, including tool use, code changes, and deployment triggers.
  • Scope agent permissions to a single task Assign the narrowest workable set of tools and resources for one workflow, then revoke or invalidate that scope as soon as the task ends.
  • Instrument every agent action end to end Require logs that show tool selection, execution timing, and downstream state changes across source control, CI, and deployment systems.

Bottom line: AI agents are moving beyond answer generation into independent workflow execution, which changes the identity problem from access assignment to action governance.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21403
 

Runtime authority is now the identity problem, not just access permission. When an AI system can commit code, run tests, and deploy changes, the control objective shifts from granting access to governing action sequence. That means the important question is no longer what the actor can theoretically reach, but what it can do in a live workflow before any human review occurs. Practitioners should treat agency as a governance boundary, not an implementation detail.

A question worth separating out:

Q: Should organisations treat AI agents like human users in IAM?

A: No. Human IAM assumes a person logs in, works within a session, and can be reviewed later as a stable identity holder. Agents can act at machine speed, across multiple systems, and with changing runtime context, so they need identity governance built around execution and delegation rather than human authentication patterns.

👉 Read our full editorial: AI agent agency is reshaping enterprise identity controls


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.