Join our Newsletter — 33% off our NHI Course

In-platform agent runtimes: are your IAM controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: P0 Security says SaaS-built agent runtimes inherit the privileges of the role that invokes them, stay inside the platform boundary, and can evade CASB, SSE, and endpoint visibility. The control problem is not the interface but the broken assumption that identity governance can wait for network-layer observation.

Editorial analysis by NHI Mgmt Group, based on content published by P0 Security: “Agentforce and Cortex aren’t SaaS features, they’re agent runtimes”.

By the numbers:

  • Gartner forecasts that the average Fortune 500 will run 150,000 agents in production by 2028, up from fewer than fifteen in 2025.
  • Only 13% of organisations think they have the governance to handle it.
  • A January 2026 survey of 235 CISOs at large enterprises found that 71% use AI tools that access core business systems like Salesforce and SAP.

Key questions

Q: What breaks when SaaS agents inherit the same role as the user who creates them?

A: The control assumption that a human role can safely govern a machine workload breaks first.

Q: Why do boundary controls miss in-platform agent activity?

A: Because the relevant action happens inside the SaaS trust boundary, not across the network edge.

Q: How should teams tell when a SaaS agent has become overprivileged?

A: Look for the gap between the agent’s stated purpose and the data or functions it can actually touch.

Practitioner guidance

  • Treat embedded agents as named non-human identities Assign an explicit owner, inventory them alongside service accounts, and apply lifecycle controls for creation, change, review, and retirement.
  • Scope the underlying role to the task Create purpose-built roles for each agent and remove inheritance from broad analyst, admin, or shared service permissions.
  • Add activation review before deployment Require a security and data-access review before an agent is enabled, especially where the builder is available to business users.

Bottom line: In-platform SaaS agents are identity-bearing workloads, not harmless product features, because they inherit the role that invokes them and operate inside the platform boundary.

What's in the full article

P0 Security's full analysis covers the operational detail this post intentionally leaves for the source:

  • The specific SaaS runtime patterns in Salesforce and Snowflake that create internal, not boundary-crossing, data access.
  • The detailed control differences between Agentforce activation, Cortex Agent creation, and the underlying permission sets or roles.
  • The cited research examples, including ForcedLeak, PipeLeak, and PromptArmor's Cortex Code findings, with their exact attack paths.
  • The January 2026 survey findings and the governance questions raised by the 71% and 16% figures.

👉 Read P0 Security's analysis of in-platform agent runtimes and NHI governance gaps →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

In-platform agent runtimes are named non-human identities, not software features: Once an embedded agent can read records, run queries, and write back inside the SaaS platform, it has crossed from feature logic into identity territory. That shift matters because identity governance, not perimeter inspection, becomes the relevant control plane. Practitioners should treat these agents as governed workloads with explicit ownership, scope, and lifecycle.

A few things that frame the scale:

  • Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
  • 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: Should organisations govern in-platform agents as features or as non-human identities?

A: They should govern them as non-human identities. The article shows that these agents have ownership, privileges, lifecycle events, and audit implications that look much more like workloads than product features. Treating them as features underestimates the need for scoping, review, monitoring, and offboarding across the full identity lifecycle.

👉 Read our full editorial: Agent runtimes inside SaaS expose a new NHI governance gap


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.