Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Infrastructure identity for agentic IT: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19563
Topic starter  

TL;DR: As cloud, automation, and AI agents expand the enterprise identity surface, infrastructure identity must replace credential-reliant workflows, with cryptographic, short-lived access emerging as the new control plane, according to Teleport. The case is strongest where standing privilege, reusable secrets, and unclear actor context are already undermining NHI governance and agent-ready access models.

NHIMG editorial — what this means for AI and NHI governance

By the numbers:

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do standing admin credentials create more risk in modern environments?

A: Standing admin credentials create more risk because they extend the time window in which an account can be abused, misused, or forgotten.

Q: What breaks when organisations rely on password vaults for every privileged identity?

A: Password vaults still help, but they break down when the real risk is persistent authorisation rather than secret storage.

Practitioner guidance

  • Bind infrastructure access to cryptographic session identity Replace reusable secrets with identity-bound sessions for administrators, automation, and service workflows.
  • Eliminate standing privilege outside maintenance windows Inventory infrastructure accounts that retain access after the task ends, then move them to just-in-time issuance with automatic expiry.
  • Bring AI agents into the same access model as workloads Do not let agents inherit broad administrative access because they are fast or convenient.

What's in the full announcement

Teleport's full analysis covers the operational detail this post intentionally leaves for the source:

  • How Teleport expects short-lived cryptographic access to replace vault-mediated workflows in infrastructure administration.
  • The specific operator journey for entering a maintenance window without retrieving a reusable credential.
  • How Cisco and Teleport describe session brokering, recording, and identity-aware enforcement at the network layer.
  • What customers should expect as infrastructure teams move from password-based access to actor-bound access records.

👉 Read Teleport's analysis of infrastructure identity for agentic IT →

Infrastructure identity for agentic IT: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19154
 

Infrastructure identity is the next governance layer because identity now sits inside the control plane. The article is right to treat network location as insufficient once human operators, workloads, and AI agents all reach the same infrastructure surface. IAM programmes that still rely on perimeter context are already behind the operating model they need to govern.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, according to Ultimate Guide to NHIs, which shows why expiry lag is a control weakness.

A question worth separating out:

Q: Who is accountable when a compromised AI agent misuses delegated access?

A: Accountability usually spans the business owner of the workflow, the team that issued or approved the credential, and the vendor if a third-party integration was involved. The critical governance question is not who logged in, but who allowed the delegation chain to exist and remain valid. That chain must be documented before incidents occur.

👉 Read our full editorial: Infrastructure identity for agentic IT: why control plane thinking matters



   
ReplyQuote
Share: