Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

KAi v2 and governed agent writes in Konnect


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Approved agent actions can now create services, routes, plugins, consumers, dashboards, and exportable artifacts in Konnect while keeping human approval and org controls in place, according to Kong’s KAi v2 research. The shift matters because agent-assisted infrastructure work now touches identity, privilege, and change-control boundaries at runtime.

NHIMG editorial — what this means for AI and NHI governance

Questions worth separating out

Q: How should security teams govern AI assistants that can make infrastructure changes?

A: Treat the assistant as a privileged non-human identity with narrowly scoped write permissions, explicit ownership, and mandatory approval for every state-changing action.

Q: What fails when an agent can move from advice to write access too quickly?

A: Least privilege stops being meaningful if a read-only assistant can be promoted to a change-making identity without reclassification, scoped permissions, and transaction-level approval.

Q: How do organisations know whether agent approvals are actually working?

A: Check whether every create, update, and delete request is blocked until an explicit human decision is recorded, and whether the logs show the proposed plan, the approval event, and the executed result.

Practitioner guidance

  • Classify the assistant as a privileged non-human identity Map KAi-style assistants into your NHI inventory with explicit owners, allowed operations, and escalation boundaries.
  • Enforce closed-loop approval for all state changes Require human approval for every create, update, and delete action, and validate that approval is enforced in the execution path rather than only in policy documentation.
  • Restrict the MCP tool surface to the minimum viable set Expose only the operations the agent genuinely needs, then verify that discovery, schema lookup, and execution cannot be chained into unintended administrative workflows.

What's in the full announcement

Kong's full product release covers the operational detail this post intentionally leaves for the source:

  • How the Code Mode MCP integration structures the exact tool chain behind create, update, delete, and execution flows
  • How the approval workflow is implemented in Konnect before a write operation is allowed to proceed
  • How decK and Terraform artefacts are generated, displayed, copied, and reused from agent output
  • How org settings can disable write operations or MCP access for staged rollout and containment

👉 Read Kong’s update on KAi v2 and governed agent writes in Konnect →

KAi v2 and governed agent writes in Konnect?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Governed agent writes are now a privileged identity pattern, not a novelty feature. KAi v2 crosses the line from advisory assistant to state-changing actor, which puts it squarely in the identity governance stack. The important question is no longer whether the assistant can understand requests, but whether its write authority is constrained like any other high-risk NHI. Practitioners should classify the assistant as an identity with operational blast radius, not as a simple productivity layer.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • The same research says 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: What should teams do with agent-generated config files and dashboards?

A: Apply the same governance you would use for any operational change artefact. Review generated configuration before reuse, track provenance, and retain enough context to reconstruct why the agent created it. Dashboards and exported files are part of the control chain, not just convenience output.

👉 Read our full editorial: KAi v2 makes agentic platform changes a governed write path



   
ReplyQuote
Share: