TL;DR: C1.ai says AI Access Management is generally available for customers, letting organisations govern employee AI assistants and enterprise agents through self-service provisioning, inline policy enforcement, and auditable MCP tool access. The access model now has to move at agent speed, because review cycles built for stable entitlements do not fit session-based tool use.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “AI Access Management Is Now Generally Available”.
By the numbers:
- 78% of employees who use AI tools bring their own, and most security teams do not know it.
Key questions
Q: What should teams do when AI agent tool access changes mid-session?
A: Teams should treat mid-session tool changes as an access event, not a routine operational detail.
Q: Why do unmanaged AI assistants so often create shadow IT and shadow access?
A: Because users will choose the fastest path to the data they need, and slow approval workflows encourage workarounds.
Q: What breaks when AI entitlements are reviewed in a separate workflow?
A: You lose the connection between the action, the identity, and the approval context.
Practitioner guidance
- Define requestable access profiles for AI workflows Group common AI tool entitlements into named access profiles so users can request the exact combination of tools and permissions they need without creating one-off exceptions.
- Classify MCP tools by risk before exposure Tag each tool as read, write, destructive, or sensitive, then attach approval rules to the classification so policy decisions are made at invocation time.
- Log tool calls with full identity context Capture who made the call, which client was used, what tool was invoked, which grant authorized it, and what resource was accessed so audit trails are usable in reviews.
Bottom line: AI access management turns enterprise agents into governed identities rather than unsupervised extensions of human workflows.
What's in the full announcement
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- Step-by-step agent provisioning flow from entitlement request to approved access profile
- Administrative setup for registering MCP servers and classifying tools as read, write, destructive, or sensitive
- Examples of inline policy enforcement for self-approval, auto-approval, and outright denial
- Audit and review workflow details showing how MCP entitlements surface in standard certification campaigns
👉 Read C1.ai's analysis of AI access management for enterprise agents →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI access governance is becoming an entitlement problem, not an AI novelty problem. The article shows that employees and enterprise agents are now using the same enterprise tools, which means identity teams must govern request, approval, and revocation through the same control plane. The material change is that access no longer sits neatly inside a human ticketing loop, so AI access management becomes a lifecycle issue for human, NHI, and autonomous-style access patterns alike. Practitioners should treat this as a core identity operating model change, not a point feature.
A few things that frame the scale:
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: What is the difference between access provisioning for people and for enterprise agents?
A: Human access provisioning is usually tied to a stable user role, while enterprise agents need owner assignment, policy enforcement, and lifecycle review at the service-principal level. Agents also need runtime controls on tool calls, because their useful work happens inside sessions rather than only at login.
👉 Read our full editorial: AI access management changes how enterprises govern agent access