Join our Newsletter — 33% off our NHI Course

Computer use agents: are your identity controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Anthropic’s Computer Use and OpenAI’s Computer Using Agent point to a new class of AI that can act inside desktop and browser environments, exposing identity controls that were built for predefined access rather than runtime action selection, according to WorkOS. Access review models assume a stable identity with predictable scope, but these agents can choose actions across arbitrary software within a task.

Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Anthropic’s Computer Use versus OpenAI’s Computer Using Agent (CUA)”.

Key questions

Q: What breaks when computer-use agents are given broad desktop access?

A: Broad desktop access breaks the assumption that identity scope can be enumerated in advance.

Q: Why do computer-use agents create more risk than ordinary workflow automation?

A: They create more risk because the sequence of actions is chosen at runtime, not pre-scripted as a fixed workflow.

Q: What signs show that a computer-use agent is operating outside its intended boundary?

A: Look for unexpected application switching, repeated retries across unrelated screens, and task completion that depends on software the original request never mentioned.

Practitioner guidance

  • Define agent execution boundaries Specify whether the agent may use a browser, a desktop, or both, and map that choice to the smallest feasible software surface and network reach.
  • Separate task approval from access scope Record who approved the task, which applications are in scope, and which actions remain prohibited even when the agent is operating legitimately.
  • Instrument session-level observability Log screenshots, action sequences, and application transitions so you can reconstruct what the agent did inside a session and where it crossed boundaries.

Bottom line: Computer-use agents blur the line between access and execution because they can choose actions across applications during a task rather than follow a fixed integration path.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21364
 

Computer-use agents create an identity control gap because task intent is not the same as execution scope. The article shows that a high-level instruction can unfold into clicks, navigation, typing, and cross-application state changes that no provisioning-time policy fully describes. That is a governance problem, not just a product-design problem. Practitioners should treat the gap between intent and runtime behaviour as the central control question.

A question worth separating out:

Q: Should organisations use browser-only agents or direct desktop agents for sensitive work?

A: Browser-only agents are easier to contain and observe, so they are usually the safer choice when the use case can be satisfied in the web layer. Direct desktop agents should be reserved for workflows that truly require native applications, local files, or system-level interaction.

👉 Read our full editorial: Computer use agents are exposing a new identity control gap


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.