Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Access management and AI agents: what IAM teams need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Access management breaks when access creation is distributed across teams, apps, contractors, and AI agents while governance remains centralized, according to Cakewalk. The article argues that ticket queues, permanent exceptions, and lifecycle gaps turn growth into silent privilege accumulation, and that role clarity plus lifecycle automation matter more than adding headcount.

NHIMG editorial — based on content published by Cakewalk: Talk the Walk on scaling securely in 2026 without growing the IT team

By the numbers:

Questions worth separating out

Q: How should security teams govern access when growth outpaces the IT team?

A: They should move from manual approval queues to lifecycle-driven governance.

Q: Why do AI agents create more risk than traditional automation?

A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.

Q: What breaks when access reviews are the main control for fast-growing companies?

A: Reviews become retrospective paperwork if permissions are changing faster than the review cycle.

Practitioner guidance

  • Map access creation to lifecycle triggers Tie joiner, mover, and leaver events to automated access changes so permissions do not depend on someone remembering a checklist.
  • Replace ticket queues with policy-backed decision paths Keep approvals close to the business context, but enforce the rule set centrally and capture evidence automatically for every access grant.
  • Classify AI agents as privileged NHIs Assign explicit owners, document intended systems, and require time-bounded permissions for every agent before production use.

What's in the full article

Cakewalk's full article covers the operational detail this post intentionally leaves for the source:

  • The conversation-level examples behind the distributed decision model for access approvals.
  • The practical sequence for tying RBAC to joiner, mover, and leaver events.
  • The specific metrics Peter Kovacs uses to measure access hygiene and audit readiness.
  • The internal approval path pattern for AI initiatives and non-human access requests.

👉 Read Cakewalk's analysis of access management, RBAC, and AI agent governance →

Access management and AI agents: what IAM teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Access management is now an operating model problem, not an approval problem. The article is right that the central failure is structural: access is created where work happens, but governance still expects a central team to keep pace. That model collapses as headcount, apps, contractors, and AI agents expand. The practitioner conclusion is that governance has to move with the business event, not behind it.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
  • 52% of companies can track and audit the data their AI agents access, while 48% still operate with a blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who should own access decisions in a distributed access model?

A: Policy should stay central, but decisions should sit with the people who understand the business need, such as managers or app owners. The security team should define guardrails, enforce evidence capture, and review exceptions that exceed policy.

👉 Read our full editorial: Access management in 2026 fails when governance stays centralized



   
ReplyQuote
Share: