TL;DR: A new IETF draft extends SCIM to AI agents and agentic applications, adding Agents and AgenticApplications resource types, owner references, certificates, protocol metadata, and token correlation so non-human identities can be provisioned and deprovisioned through standard identity workflows, according to WorkOS. That shift matters because lifecycle governance, accountability, and revocation now need to treat agents as managed identities, not informal automation.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “SCIM for AI: Inside the new IETF draft for agent and agentic application provisioning”.
Key questions
Q: What breaks when AI agents are managed like ordinary machine identities?
A: What breaks is the assumption that access scope can be fully understood from provisioning data and quarterly review.
Q: Why do AI agent identities need lifecycle governance as well as authentication controls?
A: Because the risk is not only whether an agent can authenticate, but whether it can be created, delegated, monitored, and retired in a controlled way.
Q: How do security teams know an agent token belongs to the right identity?
A: They need a stable subject or equivalent token correlation field that maps runtime authentication back to the SCIM-managed agent record.
Practitioner guidance
- Define agents as first-class identities Create a distinct identity model for agents and agentic applications so provisioning, ownership, and deprovisioning are not hidden inside application configuration.
- Require named owners for every agent Assign a human or group owner to each agent record and use that ownership field as the basis for accountability, access review, and incident triage.
- Correlate runtime tokens to SCIM records Map inbound token subjects and certificate material back to the provisioned agent identity so authentication events can be tied to a specific managed record.
Bottom line: AI agents become materially easier to govern when they are represented as first-class SCIM identities with owners, credentials, and lifecycle state.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SCIM for AI is best understood as lifecycle governance for non-human identities, not as a niche schema extension. The value of the draft is that it places agent provisioning, ownership, and deprovisioning inside an identity protocol security teams already know how to operate. That makes agents governable in the same operational chain as users and service accounts, which is the right direction for identity architecture.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should organisations treat agentic applications differently from ordinary SaaS apps?
A: Yes, because agentic applications do more than host access, they mediate the relationship between the agent, its credentials, and the applications it can act in. That means app governance has to include explicit agent membership, authorisation scope, and stale relationship cleanup, not just normal SaaS inventory.
👉 Read our full editorial: SCIM for AI extends lifecycle control to agent identities