Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Zero standing privilege for AI agents and humans: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15799
Topic starter  

TL;DR: The core issue is not entry control but the collapse of standing privilege assumptions once AI agents and workloads can act continuously, according to Britive. Cisco Duo and Britive integration extends Zero Trust from authentication into runtime privilege control, with ephemeral access, policy enforcement, and auditability across human, non-human, and agentic identities.

NHIMG editorial — based on content published by Britive: Cisco Duo and Britive: Extending Zero Trust to Human, Non-Human, and Agentic Identities

By the numbers:

Questions worth separating out

Q: How should security teams implement just-in-time access for AI-related work?

A: Start by tying each privilege grant to a specific task, identity, and expiry condition.

Q: Why do standing credentials create outsized risk in cloud and SaaS environments?

A: Standing credentials turn a single successful compromise into reusable enterprise reach.

Q: What breaks when AI agents are given standing privileges?

A: Auditability, containment, and accountability all degrade.

Practitioner guidance

What's in the full article

Britive's full blog covers the operational detail this post intentionally leaves for the source:

  • Step-by-step architecture for Duo, Britive, and AgentCore integration across human, non-human, and agentic identities
  • Runtime policy examples for just-in-time privilege across AWS, Azure, GCP, SaaS, Kubernetes, and on-prem systems
  • Operational logging flow into Splunk for privilege grants, denials, and revocations
  • MCP gateway enforcement details for agent tool calls and downstream access

👉 Read Britive's analysis of continuous Zero Trust for human, NHI, and agentic access →

Zero standing privilege for AI agents and humans: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15384
 

Zero Trust has to move from entry control to runtime control. Authentication alone does not meaningfully contain modern identity risk when the same identity can hold privilege for the life of a workflow. The important change is not just where trust starts, but where it expires. For IAM and PAM teams, that means runtime authorisation is no longer optional plumbing, it is the control boundary.

A few things that frame the scale:

  • AI agents have already performed actions beyond their intended scope in 80 percent of organisations, according to AI Agents: The New Attack Surface report.
  • Another finding from the same research shows that only 52% of companies can track and audit the data their AI agents access, leaving a 48% compliance and investigation blind spot.

A question worth separating out:

Q: Who is accountable when a non-human identity causes an access failure?

A: Accountability sits with the business owner, the identity governance process, and the system team that allowed the entitlement to persist. A non-human identity does not remove responsibility. If an access failure occurs, organisations need traceable approval, clear ownership, and a revocation path so the failure can be explained and corrected without ambiguity.

👉 Read our full editorial: Cisco Duo and Britive extend zero trust to human and agentic access



   
ReplyQuote
Share: