Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI agents in SaaS: what security teams need to change now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15817
Topic starter  

TL;DR: AI agents are expanding the SaaS attack surface because they operate at machine speed, inherit broad permissions, and can touch sensitive data across multiple apps, according to Obsidian Security. The governance problem is not agent adoption itself but the lack of lifecycle controls, auditability, and least-privilege enforcement around non-human identities.

NHIMG editorial — based on content published by Obsidian Security: AI Agents Are Rewriting SaaS Security. Are You Ready?

By the numbers:

  • Agents move 16x more data than human users, and one Glean agent downloaded over 16 million files while every other user and app combined accounted for just one million.
  • AI agents are routinely over-permissioned by 10x, which leaves them with far more access than their function requires.
  • The Salesloft incident impacted more than 700 organizations and contributed to 1.5 billion records stolen across downstream systems.

Questions worth separating out

Q: How should security teams govern AI features embedded in SaaS applications?

A: Treat embedded AI as a machine identity problem with data access implications.

Q: Why do AI agents increase the blast radius of SaaS compromises?

A: AI agents increase blast radius because they often inherit broad delegated permissions and can execute many actions across connected applications in a short time.

Q: What breaks when AI agents are treated like standard human users?

A: You lose visibility into effective permissions, expected behaviour, and real blast radius.

Practitioner guidance

  • Inventory every AI agent and its delegated scopes Build a live register of agents, linked SaaS apps, token types, and effective permissions so you can see which identities can move across systems.
  • Shrink SaaS permissions to task-level access Replace broad read-all or tenant-wide access with narrowly scoped entitlements that match the agent's specific workflow and revoke anything not used in production.
  • Bind agent actions to immutable audit trails Log each execution with the agent identity, the entitlement used, the dataset touched, and the downstream action so investigations can reconstruct the chain quickly.

What's in the full article

Obsidian Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • Agent visibility workflows for inventorying AI agents, their SaaS connections, and their effective privileges.
  • Continuous observability examples that tie each agent action to the specific entitlement and dataset involved.
  • Misuse detection patterns for trust-chain abuse, privilege escalation, and risky downstream access.
  • Practical mitigation detail for cleaning up excessive access across connected SaaS environments.

👉 Read Obsidian Security's analysis of how AI agents are rewriting SaaS security →

AI agents in SaaS: what security teams need to change now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15402
 

AI agents are becoming non-human identities with human-scale business impact. Once agents can execute workflows, touch data, and chain SaaS actions, they stop being a simple automation feature and become governed identities. That creates a direct identity security problem, not just an application feature problem. IAM and PAM teams should treat every agent as a lifecycle-managed subject with scoped access and revocation paths.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface.
  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.

A question worth separating out:

Q: Who is accountable when an AI agent performs an unauthorized action in a SaaS product?

A: Accountability stays with the organisation that granted the agent authority, but investigators need evidence to prove what the actor was allowed to do and what it actually did. That is why audit logs, scope controls, and session-level attribution matter across human, service, and agent activity.

👉 Read our full editorial: AI agents are rewriting SaaS security and exposure models



   
ReplyQuote
Share: