TL;DR: Identity programmes now have to govern runtime access use, not just static entitlements, across mixed actor types, as 1Password’s appointment of Dr. Manoj Apte to its board reflects a broader shift toward continuous access, delegated authority, and identity governance for humans, machine identities, and AI agents, according to 1Password.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “1Password Appoints Dr. Manoj Apte to Board of Directors”.
By the numbers:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
Key questions
Q: How should teams govern AI agents that inherit human access rights?
A: Teams should treat inherited access as temporary and bounded to a specific task, owner, and expiry.
Q: Why do shared credentials create risk in agentic workflows?
A: Shared credentials erase the line between requester and operator, so security teams cannot tell whether a Lambda invocation, database query, or EC2 session came from the right agent and task.
Q: What breaks when identity governance is built only for human users?
A: Access review, joiner-mover-leaver processes, and periodic certification break down when the identity is a service account or autonomous agent.
Practitioner guidance
- Define delegated identity boundaries Separate human accounts, service identities, and agentic workflows in policy so each has a distinct purpose, scope, and expiry model.
- Audit runtime access use Log what credentials, secrets, and machine identities are used during execution, not just which identities were granted access.
- Shorten privilege lifetime for workflows Replace broad reusable access with narrowly scoped, ephemeral credentials that expire with the task or session.
Bottom line: AI agents change identity governance because authority now has to be tracked during execution, not only at provisioning.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity is moving from static entitlements to governed execution. That is the central implication of this board appointment. Access no longer describes only what a subject may receive at provisioning time; it increasingly describes how delegated authority is exercised across human, machine, and agentic workflows. The practitioner conclusion is that entitlement review alone is no longer the governing model.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What is the difference between delegated access and standing privilege in AI workflows?
A: Delegated access is meant to exist only for a specific purpose, time, and scope. Standing privilege persists beyond that purpose and can be reused in ways that are hard to justify or audit. For AI workflows, the practical distinction is whether the access disappears when the task ends or remains available for the next action.
👉 Read our full editorial: 1Password’s board move signals identity security for agents