TL;DR: AI native engineering teams can move faster, but the shift also exposes identity sprawl, shadow access, and weaker visibility into who or what is acting on behalf of the organisation, according to Oasis Security. The governance break is that static roles and periodic reviews assume stable identities, while AI-native workflows create dynamic access paths that outpace them.
Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “Building an AI Native Engineering Organization: Lessons in Speed, Culture, and Security”.
Key questions
Q: What breaks when AI native engineering is governed with static roles and periodic reviews?
A: Static roles and periodic reviews fail because they assume identities remain stable long enough to be reviewed later.
Q: Why do access sprawl and AI workflows create more identity risk?
A: Because they multiply the number of places where credentials, approvals, and delegated actions can occur without clear ownership.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.
Practitioner guidance
- Implement comprehensive identity discovery Catalogue developers, CI/CD jobs, AI agents, ephemeral services, and any delegated identities that can act in the delivery path.
- Map access to runtime behaviour Compare what each identity can access with what it actually does in engineering workflows.
- Automate drift detection for entitlement changes Treat new permissions, new connections, and abnormal usage spikes as governance events.
Bottom line: AI native engineering changes the identity problem by making access more dynamic, more distributed, and harder to trace through static roles alone.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI native engineering creates an identity governance problem, not just a productivity shift. The article shows that speed and autonomy change the operational meaning of access, ownership, and review. Once humans and machines both act inside the same delivery loop, fixed-role governance becomes a poor proxy for actual authority. The practitioner conclusion is that identity governance has to move closer to runtime.
A question worth separating out:
Q: What should teams do when access changes faster than their review process?
A: Move governance earlier in the lifecycle and add continuous drift detection for new permissions, connections, and usage spikes. The goal is to catch changes while they are still actionable, because temporary access can still create meaningful exposure even if it never reaches a scheduled review.
👉 Read our full editorial: AI native engineering exposes identity sprawl and access control gaps