Join our Newsletter — 33% off our NHI Course

AI agent offboarding: what happens when the worker never leaves?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Improper offboarding remains the top non-human identity risk, and AI agents are now exposing why: dormant credentials, disconnected applications, and vendor-dependent revocation leave access active long after projects end, according to Opnova. The real failure is not policy design but coverage, because access review and deprovisioning models assume a clean termination event that agents do not produce.

Editorial analysis by NHI Mgmt Group, based on content published by Opnova: “Leaver for AI Agents: You Fired the AI. Did It Actually Leave?”.

By the numbers:

  • 38% of all accounts in the enterprises it analyzed are dormant.

Key questions

Q: What breaks when AI agents are not included in offboarding?

A: When AI agents are excluded from offboarding, they can keep accessing data and systems after the human owner leaves.

Q: When should organisations prioritise agent offboarding over other NHI work?

A: They should prioritise it when agents touch production systems, customer data, regulated workloads, or disconnected applications that cannot be revoked through one identity provider.

Q: What are the signs that AI agent authorization is failing?

A: Watch for agents reaching systems outside their intended task, holding broad permissions after the job changes, or producing incomplete audit trails for sensitive actions.

Practitioner guidance

  • Define an AI agent leaver playbook Create a written offboarding path for each agent class, with named owners, required checks, and explicit revoke steps for production, customer data, and regulated systems.
  • Inventory every agent credential at issuance Register each OAuth grant, API key, service account, certificate, and direct permission when it is created so revocation has a complete target list.
  • Verify revocation in the destination system Confirm the token, account, or grant no longer authenticates in the target console or application before the offboarding case closes.

Bottom line: AI agent offboarding is a lifecycle governance problem because access can persist across multiple credentials after the work is finished.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Improper offboarding is not a process nuisance, it is the structural failure mode of NHI governance. When access lives in disconnected applications, the enterprise cannot rely on a single termination event to remove it. The article shows that the problem is not whether a workflow exists in theory, but whether every credential path is actually inside the control boundary. Practitioners should treat offboarding coverage as the real measure of leaver maturity.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable when an AI agent keeps access after it should have left?

A: Accountability should sit with the team that issued, approved, and maintains the agent’s entitlements, not with the eventual incident responder. If ownership is not assigned at issuance, offboarding becomes a shared assumption and the last revoke never happens. Governance frameworks should make entitlement ownership explicit before the agent goes live.

👉 Read our full editorial: AI agent leaver workflows expose the NHI offboarding gap



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Improper offboarding is not a process nuisance, it is the structural failure mode of NHI governance. When access lives in disconnected applications, the enterprise cannot rely on a single termination event to remove it. The article shows that the problem is not whether a workflow exists in theory, but whether every credential path is actually inside the control boundary. Practitioners should treat offboarding coverage as the real measure of leaver maturity.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable when an AI agent keeps access after it should have left?

A: Accountability should sit with the team that issued, approved, and maintains the agent’s entitlements, not with the eventual incident responder. If ownership is not assigned at issuance, offboarding becomes a shared assumption and the last revoke never happens. Governance frameworks should make entitlement ownership explicit before the agent goes live.

👉 Read our full editorial: AI agent leaver workflows expose the NHI offboarding gap



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Improper offboarding is a lifecycle failure, not a documentation problem: The governance model for AI agents breaks when access can outlive the project, the owner, and the termination signal. In human IAM, the leaver event is anchored to a person and propagated from a known source. With AI agents, the leaver event must be inferred across scattered credentials and disconnected systems. The implication is that offboarding has to become an inventory and revocation discipline, not a policy statement.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who should be accountable when an AI agent retains access after a project ends?

A: The accountable party should be the current human sponsor who can explain why the agent still exists and approve its continued access. Creator history is useful, but it is not sufficient once teams change, projects end, or identities are reused. Accountability has to follow operational ownership, not historical creation metadata.

👉 Read our full editorial: AI agent leaver workflows expose the NHI offboarding gap


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.