Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agent identity and MCP: what IAM teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15817
Topic starter  

TL;DR: Agentic systems are turning every AI agent into a distinct identity that can query data, call APIs, and orchestrate workflows, while most enterprises still govern them like application extensions, according to AppSOC. That mismatch leaves actions without accountability and makes identity the real control plane, not MCP integration details.

NHIMG editorial — based on content published by AppSOC: The Agentic Identity Crisis: Why AI agent security requires an identity-first approach

Questions worth separating out

Q: How should organizations manage the identity risks associated with AI agents?

A: Organizations should enhance visibility into AI agents by incorporating robust monitoring and evaluation processes within their IAM frameworks.

Q: Why do AI agents break traditional IAM assumptions?

A: AI agents break IAM assumptions because they do not behave like predictable users.

Q: What breaks when AI agents are managed like ordinary machine identities?

A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review.

Practitioner guidance

  • Inventory agents as first-class identities Map every deployed agent, connector, and runtime token to an accountable owner, business purpose, and review cycle.
  • Separate authentication from action authorisation Require per-tool and per-operation authorisation for agent actions, especially where agents can read data, modify records, or trigger workflows across multiple systems.
  • Apply lifecycle governance to agent credentials Track provisioning, rotation, revocation, and offboarding for agent tokens and OBO relationships the same way you would manage other non-human identities.

What's in the full article

AppSOC's full article covers the operational detail this post intentionally leaves for the source:

  • How the PointGuard MCP Security Gateway applies strong agent authentication and OBO tokenisation in practice
  • How runtime guardrails and DLP are combined with identity context for agent actions
  • How continuous discovery is used to inventory AI assets and reduce shadow AI exposure
  • How tool-level authorisation changes the control model for agentic environments

👉 Read AppSOC's analysis of the agentic identity crisis in AI security →

AI agent identity and MCP: what IAM teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15402
 

Every AI agent is a non-human identity, and treating it as anything else creates governance blind spots. The article is right to frame MCP as an identity problem because the security consequence is not connectivity alone, it is the creation of machine identities that can act across systems. Once agents can query, modify, and orchestrate workflows, they belong in the same governance model that already covers service accounts, tokens, and certificates. The practitioner conclusion is simple: if the identity is not governed, the agent is not governed.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
  • Our research also found that only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who should own AI agent identity governance in an enterprise?

A: AI agent identity governance should sit jointly with IAM, platform security, and application owners because the risk crosses the runtime, the proxy, and the receiving service. No single team can see the whole delegation chain unless identity context is preserved end to end.

👉 Read our full editorial: MCP exposes an identity crisis in AI agent security



   
ReplyQuote
Share: