TL;DR: AI agents are being instantiated at runtime, scoped to a task, and retired when that task ends, creating a governance problem that conventional identity systems were not built to handle, according to Strata Identity. The core issue is not just scale but assumption collapse: access review models assume identities persist long enough to review, while agent identities may not.
Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “How Just-in-Time Provisioning Creates Artificial Agent Identities on Demand”.
Key questions
Q: What breaks when AI agents are never deprovisioned?
A: When agents are never deprovisioned, they become zombie identities that continue to consume resources and preserve access long after their business purpose ends.
Q: Why do AI agents make access review and recertification less effective?
A: Because the review model assumes access changes are visible through human behaviour such as job changes, approvals, or offboarding.
Q: How should security teams separate temporary agents from recurring services?
A: Treat one-off agents as ephemeral identities with token-based claims and short-lived scope, while recurring services can justify a fuller profile only when reuse is real.
Practitioner guidance
- Design issuance-time controls for agents Define runtime policy checks that evaluate task sensitivity, delegator identity, and agent type before credentials are created, instead of trying to certify access after the fact.
- Separate ephemeral and recurring agent patterns Use lightweight token-based identities for one-off agents and fuller profiles only for recurring services that genuinely need a directory record.
- Bind every agent action to delegation context Require provenance fields for task ID, delegator, expiry, and purpose so audit trails remain usable after the agent has been retired.
Bottom line: AI agents do not fit human-style identity lifecycles because they are created for work, not assigned for permanence.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Assumption collapse, not just scaling pressure, is the real governance break: access review and joiner-mover-leaver models were designed for identities that persist long enough to be certified. That assumption fails when an AI agent can be instantiated, act, and retire inside the same task window. The implication is that identity governance has to move from post-issuance review to issuance-time control for autonomous execution contexts.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What should teams do to keep agent actions attributable after the task ends?
A: Every agent action should carry delegation context, including who initiated the task, what the agent was allowed to do, and when the identity expires. That makes post-event audit and incident reconstruction possible even after the agent has been retired. Without that record, logs show activity but not accountable authority.
👉 Read our full editorial: JIT identity provisioning for AI agents is becoming necessary