TL;DR: AI agents are becoming a governed identity class with short-lived credentials, policy-enforced actions, and human-in-the-loop controls, according to Strata Identity research and Gartner’s Emerging Tech Impact Radar for agentic identities, which named Strata Identity a Sample Vendor in the report. Traditional IAM still struggles to manage dynamic, delegated agent behaviour, so least privilege and lifecycle management must be reworked for runtime decision-making.
Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “Strata Identity Recognized by Gartner ® as a Sample Vendor for Agentic Identities in Emerging Tech Impact Radar: Global Attack Surface Grid”.
By the numbers:
- By 2026, 40% of enterprise apps will be integrated with task-specific agents, up from less than 5% now.
Key questions
Q: What breaks when AI agents are treated like standard human users?
A: You lose visibility into effective permissions, expected behaviour, and real blast radius.
Q: Why do AI agents need runtime controls instead of only pre-approved access?
A: Pre-approved access cannot tell you what the agent will do once prompts, tools, memory, and sub-agents start interacting.
Q: How should identity teams handle short-lived credentials for autonomous agents?
A: They should tie credentials to task scope, expire them with the work, and make issuance contingent on explicit policy.
Practitioner guidance
- Define agent identities as governed principals Inventory every AI agent that can independently request tools or take actions, then assign it an identity lifecycle, ownership model, and approval path.
- Issue short-lived, task-scoped credentials Replace persistent access with credentials that expire with the task and bind each credential to the specific scope the agent needs.
- Enforce policy at the action boundary Require policy-as-code checks before sensitive agent actions execute, including explicit review for high-risk operations.
Bottom line: Agentic identities are being treated as a governable identity class, not as a side effect of automation.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic identities create an identity class, not just an AI feature. Strata Identity’s positioning reflects a broader shift: once an AI agent can perceive, reason, and act autonomously, the enterprise has to govern it as an identity subject with lifecycle, authorisation, and audit requirements. That changes how IAM programmes define an account, an entitlement, and an action. The practitioner implication is that agentic identity governance belongs inside IAM architecture, not on the edge of it.
A question worth separating out:
Q: How do organisations govern agentic identities without changing every application?
A: Use an identity-aware enforcement layer that sits in the path between the agent and the systems it uses. That lets teams apply authentication, authorisation, and audit controls without rewriting every app or microservice. The key requirement is that policy is enforced where the agent actually executes work.
👉 Read our full editorial: Agentic identities force IAM to extend governance to AI agents