Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Managed agent boundaries: what IAM teams need to review now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Three managed agent platforms now target enterprise buyers, but their documented security boundaries differ sharply across runtime isolation, delegated authority, and governance, according to Mint’s review of Anthropic Claude Managed Agents, OpenAI ChatGPT Workspace Agents, and Google Gemini Enterprise. The governing question is no longer whether agents can work, but what they can reach, under whose authority, and with what evidence trail.

NHIMG editorial — based on content published by Mint: Executive summary and comparative audit of Anthropic Claude Managed Agents, OpenAI ChatGPT Workspace Agents, and Google Gemini Enterprise Agent Platform

Questions worth separating out

Q: How should security teams govern managed agents that can access real systems?

A: Treat each managed agent as a non-human identity with explicit authority, runtime bounds, and an audit trail.

Q: Why do managed agents need identity governance?

A: Managed agents need identity governance because they can perform actions, access resources, and influence business processes without being human.

Q: What do identity teams get wrong about instant approvals?

A: They often focus on transaction speed and ignore whether the approval path still has enough decision points to detect fraud.

Practitioner guidance

  • Inventory every managed agent as an identity object Catalogue each agent, its connected apps, its credentials, its trigger paths, and the systems it can touch.
  • Separate invocation authority from execution authority Require a distinct record of who triggered the agent and which principal it used to act.
  • Bound runtime reach before permitting production use Review whether the platform exposes sandbox isolation, container egress controls, and secret non-exposure guarantees.

What's in the full report

Mint's full audit covers the operational detail this post intentionally leaves for the source:

  • Per-platform control-plane breakdowns for Anthropic, OpenAI, and Google that show exactly where runtime, authority, and governance differ.
  • Documented boundary details on sessions, sandboxes, vaults, approvals, agent identity, and observability that implementation teams need before rollout.
  • Comparative notes on preview versus private-preview features so buyers can assess maturity before building policy around them.
  • The underlying references and documentation trail that support the audit's control-plane comparison.

👉 Read Mint's audit of managed agent control planes and security boundaries →

Managed agent boundaries: what IAM teams need to review now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Managed agents are now privileged non-human identities, not just AI features. Once an agent can hold credentials, call tools, and leave logs, it belongs in the same governance conversation as service accounts and workload identities. The operational difference is that the agent may also act through a user-facing workspace, which blurs traditional ownership models. Security teams should treat the control plane as the identity object, not the model wrapper.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and another 47% reporting only partial visibility, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when a managed agent takes the wrong action?

A: Accountability should be split across the human invoker, the platform owner, and the system owner that exposed the connected credential or integration. If the organization cannot tell which principal acted and under what policy, then accountability has been designed too loosely for enterprise use. That is a governance failure, not just an operational one.

👉 Read our full editorial: Managed agent control planes are converging, but boundaries differ



   
ReplyQuote
Share: