Join our Newsletter — 33% off our NHI Course

AI agent joiner workflows: what IAM teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agents are entering enterprises with no owner, approval record, or access review, according to Opnova, while one survey found 74% of organisations already run credentialed AI agents or automations and 5% of security leaders cannot confirm whether agentic AI is present. Joiner governance breaks when identity is issued before ownership and classification exist, so access control must start at provisioning.

Editorial analysis by NHI Mgmt Group, based on content published by Opnova: “Joiner for AI Agents: The Workforce Nobody Hired”.

By the numbers:

  • 74% of organisations are already running AI agents or automations that require credentials.
  • 5% of security leaders cannot confirm whether agentic AI is running in their environment at all.
  • AI agents and other non-human identities grew 44% year-over-year between H1 2024 and H1 2025.

Key questions

Q: What breaks when AI agents are added to joiner workflows without ownership and approval?

A: The joiner model loses its core governance anchors.

Q: Why do service accounts and AI agents create different identity risk than employees?

A: Service accounts and AI agents create different risk because they are not managed through HR lifecycle events, yet they often hold broad technical permissions and can act at machine speed.

Q: How do security teams know if an AI agent has too much access?

A: Look for agents that can reach multiple systems without task-specific limits, use persistent tokens, or touch high-value services such as email, chat, cloud consoles, and file stores.

Practitioner guidance

  • Define AI agents as first-class identity subjects Create a distinct identity record for every agent with owner, purpose, deploying platform, classification tier, and lifecycle state before any credential is issued.
  • Gate provisioning on named human approval Require a named human owner to approve the agent before the service account, API key, or OAuth grant is created.
  • Set birthright access by classification tier Use risk tiers to limit initial access for customer-facing or production-touching agents, and keep internal agents on a narrower default scope until their task is confirmed.

Bottom line: AI agent joiner failures happen when identity is issued before ownership, approval, and classification exist.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21366
 

AI agent joiner exposes an inventory failure, not just an onboarding gap. The enterprise problem is not that agents are hard to provision, but that most programmes cannot prove they exist in the first place. When there is no canonical identity object, ownership record, or lifecycle state, Joiner becomes invisible at the exact point governance is supposed to begin. The implication is simple: discovery and authoritative registration are now part of Joiner, not a separate hygiene exercise.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who should approve AI agent access and lifecycle decisions?

A: A named human owner should approve both provisioning and later lifecycle changes, because the agent itself cannot accept accountability. The approval chain should include the business purpose, system scope, and segregation-of-duties impact so the organisation can answer audit questions without reconstructing the event after the fact.

👉 Read our full editorial: AI agent joiner governance is breaking the enterprise identity model



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21366
 

AI agent joiner exposes an inventory failure, not just an onboarding gap. The enterprise problem is not that agents are hard to provision, but that most programmes cannot prove they exist in the first place. When there is no canonical identity object, ownership record, or lifecycle state, Joiner becomes invisible at the exact point governance is supposed to begin. The implication is simple: discovery and authoritative registration are now part of Joiner, not a separate hygiene exercise.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who should approve AI agent access and lifecycle decisions?

A: A named human owner should approve both provisioning and later lifecycle changes, because the agent itself cannot accept accountability. The approval chain should include the business purpose, system scope, and segregation-of-duties impact so the organisation can answer audit questions without reconstructing the event after the fact.

👉 Read our full editorial: AI agent joiner governance is breaking the enterprise identity model



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21366
 

AI agent joiner governance is now an identity problem, not a tooling problem. The article shows that agents are appearing without the basic governance artefacts that make joiner controls work for humans: owner, purpose, approval, and record of hire. That means the enterprise is creating machine identities faster than it can classify them. The practitioner conclusion is simple: if the identity cannot be named, owned, and scoped before issuance, it should not enter production.

A few things that frame the scale:

  • 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
  • 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: What should teams check before putting an AI agent into production?

A: Teams should verify three things before production: the agent has a unique identity, its permissions are minimal and explicitly approved, and its actions are fully auditable. They should also confirm that any privacy control used for analytics is layered on top of, not instead of, the access model.

👉 Read our full editorial: AI agent joiner governance is breaking the enterprise identity model


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.