TL;DR: AI agents now make decisions, execute tasks, and adapt in runtime, which means identity controls must track delegation, auditability, and scope as first-class requirements, according to Strata Identity. The old assumption that access can be reviewed after the fact breaks when agents act and re-act within a session, leaving accountability gaps that human-centric IAM cannot close.
Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “Why agentic identities matter and what you need to know”.
Key questions
Q: How should security teams govern AI agents that inherit authority from other identities?
A: Security teams should govern AI agents by tracking identity lineage, not just credentials.
Q: Why do AI agents complicate traditional access reviews?
A: AI agents complicate access reviews because they can accumulate permissions across tools and environments faster than manual certification cycles can observe.
Q: What breaks when AI assistants borrow human sessions or tokens?
A: What breaks is attribution.
Practitioner guidance
- Define agent identities as distinct governance objects Create a separate lifecycle, ownership and scope model for AI agents instead of reusing human accounts or generic service identities.
- Preserve delegation context in every downstream action Propagate origin, scope and on-behalf-of metadata through tokens, logs and API calls so each action can be traced back to the initiating human or parent agent.
- Constrain agent actions to task-bound scopes Limit agents to the APIs, tools and workflows needed for one task and revoke scope when the task closes or context changes.
Bottom line: AI agent identity changes the IAM problem from proving login to proving accountable delegation across a runtime chain.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agent identity exposes an accountability gap, not just a control gap. The central failure is not that AI agents can authenticate, but that enterprises still struggle to prove who initiated delegated action once the agent starts executing. Human-centric IAM assumes a clear operator behind the event trail, while agentic systems can interleave intent, execution and re-execution inside one workflow. The implication is that accountability must be designed into the identity model itself, not reconstructed from logs after the fact.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What is the difference between delegated identity and shared service accounts for agents?
A: Delegated identity ties an agent’s authority to a user or approved workflow, while a shared service account gives broad standing access that is hard to attribute and harder to contain. For agentic systems, delegated identity is the safer governance model because it preserves accountability and allows scope to be reduced at the point of action.
👉 Read our full editorial: AI agent identity requires a new model for accountability