Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI agents and access campaigns: what changes for identity teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15737
Topic starter  

TL;DR: Opal’s GA release adds Paladin, Access Campaigns, OpalScript, and MCP updates to a single access graph across employees, service accounts, and AI agents, while citing 43.5% of granted access as unused and therefore standing risk. The deeper issue is that access governance now has to handle agent-speed decisions, policy consistency, and non-human access paths at the same time.

NHIMG editorial — what this means for AI and NHI governance

By the numbers:

Questions worth separating out

Q: How should security teams govern IAM access for AI agents in AWS?

A: Treat each AI agent as a non-human identity with its own execution role, trust policy, and review cycle.

Q: Why do access review programmes struggle when human and machine identities share the same control plane?

A: Because reviewers need context that spans different identity types, yet many programmes still handle them as separate queues.

Q: What breaks when access management policy is written but not enforced?

A: When policy is not enforced, access decisions drift away from business need.

Practitioner guidance

  • Unify human and non-human entitlement views Build one access model that includes employees, service accounts, and AI agents so reviewers can see inherited privilege, unused grants, and cross-system drift in the same workflow.
  • Convert approval rules into versioned policy Move access decision criteria into tested policy-as-code so the same request produces the same outcome regardless of reviewer, shift, or escalation path.
  • Scope agent access by task and expiry Require AI agents to use scoped, expiring access for MCP-connected tools, with revocation tied to the end of the task or workflow.

What's in the full announcement

Opal Security's full product post covers the operational detail this post intentionally leaves for the source:

  • How Paladin applies context to individual access decisions across live requests and policy exceptions
  • How Access Campaigns structures reviewer assignment, reminders, and bulk cleanup for large entitlement sets
  • How OpalScript encodes access policy into versioned logic for separation of duties, duration limits, and auto-approval criteria
  • How the MCP updates and OAuth for Opal MCP scope agent access in production environments

👉 Read Opal Security's post on Paladin, Access Campaigns, and OpalScript GA →

AI agents and access campaigns: what changes for identity teams?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15322
 

Access governance is becoming an identity graph problem, not just an approvals problem. When employees, service accounts, and AI agents share one entitlement plane, the old assumption that reviews can be handled in separate silos breaks down. The practical issue is not simply volume. It is that policy decisions now depend on cross-identity context that many IGA programmes still cannot model cleanly.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to The State of Secrets in AppSec.

A question worth separating out:

Q: When should organisations prioritise cleanup of unused access over adding more approval steps?

A: When a large share of access is granted but never used, review friction is no longer the main problem. The bigger issue is standing privilege that continues to exist after need has passed. In that situation, cleanup reduces attack surface faster than adding another layer of approval ever will.

👉 Read our full editorial: Opal’s access campaigns and agent governance shift IGA assumptions



   
ReplyQuote
Share: