Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic discovery in zero trust: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: The NSA’s 2026 Zero Trust Discovery guidance reinforces a familiar enterprise problem: if applications, datasets, and owners cannot be described reliably, enforcement becomes guesswork, and manual discovery becomes too slow to scale, according to Tonic. The shift is toward continuous, evidence-based discovery as an operating model, not a quarterly cleanup exercise.

NHIMG editorial — based on content published by Tonic: Agentic discovery turns zero trust inventory into a continuous control

Questions worth separating out

Q: How should security teams use agentic discovery in zero trust programmes?

A: Use agentic discovery to reconcile asset, owner, and dependency data across the sources where truth actually lives, then route only uncertain cases for human confirmation.

Q: Why does discovery drift slow zero trust enforcement?

A: Discovery drift means the organisation’s asset and ownership records no longer match the live environment.

Q: What do teams get wrong about automated discovery?

A: They assume automation is enough if it can inventory assets faster than humans can.

Practitioner guidance

  • Create an authoritative discovery workflow Build a reconciliation process that compares cloud telemetry, CMDB records, tickets, and runbooks before an asset is approved for policy enforcement.
  • Track discovery drift as a control metric Measure how often ownership, app names, or dataset classifications disagree across systems, and treat unresolved disagreements as operational risk.
  • Link NHI governance to asset truth Map service accounts, workload identities, and API dependencies to the same ownership records used for applications and data.

What's in the full article

Tonic's full article covers the operational detail this post intentionally leaves for the source:

  • Evidence examples showing how the agent pulls ownership from tickets, runbooks, and collaboration threads
  • Workflow detail on how uncertain cases are routed for one-click human confirmation
  • Operational examples of how enriched context is pushed into ServiceNow and Jira
  • The specific way the discovery loop is used to keep the system of record current

👉 Read Tonic's analysis of agentic discovery for zero trust implementation →

Agentic discovery in zero trust: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Discovery debt is now a governance problem, not an administrative inconvenience. The article’s central point is that zero trust programmes do not fail only at policy design. They fail when the organisation cannot maintain a reliable map of assets, services, and data ownership. That is a governance gap because enforcement depends on trusted context, and fragmented inventories create a permanent exception state. Practitioners should treat discovery quality as a security control outcome, not a housekeeping metric.

A question worth separating out:

Q: Who is accountable when discovery data is wrong?

A: The accountable owner is the programme that depends on the data for enforcement, usually security, platform, or identity governance leadership. If inventory accuracy determines access policy, then data quality becomes a control responsibility, not a back-office issue. Frameworks such as NIST SP 800-207 and NIST SP 800-53 both imply that governance must be tied to current, validated context.

👉 Read our full editorial: Agentic discovery turns zero trust inventory into a continuous control



   
ReplyQuote
Share: