Join our Newsletter — 33% off our NHI Course

AI agents as the new developer interface: what changes for IAM teams?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Tiger Data says customers are seeing up to 70% of code generated by agents, while the company’s own Eon Slack bot reached 60% daily adoption in three weeks, underscoring how quickly agents are moving from novelty to core interface, according to WorkOS. The governance shift is that agent-facing systems now need identity, access, and observability models built for machine-paced API calls, not human UI sessions.

Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Tiger Data sees agents as the new developer”.

By the numbers:

  • customers are reporting 70% of their code comes from agents

Key questions

Q: What breaks when AI agents are treated like standard human users?

A: You lose visibility into effective permissions, expected behaviour, and real blast radius.

Q: Why do agents need stricter tool boundaries than traditional apps?

A: Agents do not just consume a single workflow.

Q: How can security teams tell whether agent permissions are too broad?

A: The clearest signal is whether the agent can still complete its job after permissions are reduced in a sandbox.

Practitioner guidance

  • Define agent-specific access boundaries Map each AI agent to the exact APIs, databases, and internal tools it can call, then remove any capability that is not required for a named workflow.
  • Separate human entitlements from machine entitlements Create distinct governance paths for employee access and agent access so that certification, approval, and revocation logic does not blur the two identity types.
  • Instrument agent activity for reconstruction Log tool selection, retrieved context, chained calls, and downstream writes so incident responders can reconstruct what the agent actually did.

Bottom line: AI agents are moving developer and data tooling toward machine-paced access patterns that do not fit human-centric identity governance models.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

AI agents are becoming a new non-human identity tier, not just a new user interface. The article shows agents moving from novelty to routine execution, with code generation, API calls, and internal tools increasingly mediated by machine-driven workflows. That changes governance because the actor making the call is no longer a human with stable intent and predictable pacing. The implication is that identity programmes need to classify agent activity as a distinct access class rather than a UI variant.

A few things that frame the scale:

  • Claude Code-assisted commits leaked secrets at a rate of 3.2%, more than double the human-only baseline of 1.5%, with peaks reaching 31 secrets per 1,000 commits in August 2025, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: What should security teams do when agents can call databases and internal APIs?

A: Treat those calls as privileged machine actions and apply the same discipline you would use for high-risk service accounts: narrow scope, separate environments, logged execution, and explicit approval for sensitive writes. The point is to govern the access path at runtime, not just register the agent in inventory.

👉 Read our full editorial: AI agents are becoming the new developer interface for data tools


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.