Subscribe to the Non-Human & AI Identity Journal
NHI & Agentic AI Security

NHI & Agentic AI Security FAQ

Practitioner-driven questions and answers on non-human identity and agentic AI security, governance, and risk management across IAM, cloud, and enterprise cybersecurity.

NHI Mgmt Group Editorial Knowledge Base  · 
Reviewed by Lalit Choda
🔍
Domain:
Filter by domain, or search to filter the results
Written by practitioners, for practitioners. These answers are grounded in extensive real-world experience in non-human identity and agentic AI security programmes across global enterprises, and informed by insights from the NHI Mgmt Group community and education curriculum. For deeper reading on any topic, visit our Editorial Research Articles in the Knowledge Centre.
🔐 Foundations & NHI Taxonomy
Q Why do consumer accounts need different IAM controls from workforce identities?
Q Why do online portals matter so much in customer identity programmes?
Q How can practitioners tell whether their team is reading deeply enough?
Q Why does Active Directory still matter to modern identity programmes?
Q What breaks when purchases and identity are not unified across channels?
Q Why do customer identities need different controls from workforce identities?
Q Why do RAG systems need more than a single quality score?
🔄 NHI Lifecycle Management
Q Why does contractor access often outlive the business need that created it?
Q What do teams get wrong about secrets in AI-built apps?
Q When does secret rotation stop being a meaningful PAM control?
Q When does dynamic credential use justify higher transaction volume?
Q What is the difference between lifecycle automation and simple account provisioning?
Q Why do AI-driven attacks change the value of secrets management?
Q What breaks when secrets are left inside generated code?
🔑 Authentication, Authorisation & Trust
Q How do IAM teams know whether Firebase custom token use is expanding blast radius?
Q How can security teams test whether token-based sign-in is actually safe?
Q Should organisations prefer native passkey flows over browser-based sign-in for mobile apps?
Q How should teams govern external token exchange in mobile apps?
Q What breaks when the external subject does not match the Firebase UID?
Q What breaks when OAuth consent is writable by too many identities?
Q Why do service principals with app-only permissions increase tenant risk?
🏗️ Architecture & Implementation
Q How should security teams tell true JIT access from time-limited access?
Q Why do vaulted credentials still create risk in privileged access programs?
Q When does approval-based access still leave too much privilege in place?
Q What should security teams do when remediation is part of the detection workflow?
Q Why do administrator-level IAM user policies create disproportionate risk?
Q How do teams know a remediation workflow actually fixed the issue?
Q What breaks when cloud remediation changes are applied without approval?
🏛️ Governance, Ownership & Risk
Q What is the difference between approval built into authorization and manual review after the fact?
Q Who is responsible for revoking over-scoped MCP credentials?
Q How should security teams prove that access policy is actually enforced?
Q Why do role-based models break down in complex enterprises?
Q What should organisations do when access spans multiple systems and business units?
Q How do IGA teams know whether their programme is producing real control value?
Q Who is accountable when acquired systems stay outside identity governance?
⚠️ Threats, Abuse & Incident Response
Q What breaks when a mobile app depends on a privileged service account to mint backend tokens?
Q What breaks when credential abuse is no longer the first step in a breach?
Q Why do AI agents increase the blast radius of SaaS compromises?
Q Who is accountable when an MCP client exposes tokens or executes hostile input?
Q What breaks when URL schemes are not restricted in agent clients?
Q Why do long-lived tokens increase risk in cloud data platforms?
Q What accountability exists when an AI agent misuses enterprise access?
🤖 Agentic AI & Autonomous Identity
Q How do security teams prove accountability for agent actions through MCP?
Q What breaks when delegated access is not visible at the resource boundary?
Q What breaks when organisations rely on packet controls for MCP governance?
Q Why do AI agents complicate OAuth and OIDC-based access models?
Q How should security teams implement approval controls for AI assistants?
Q What breaks when an AI assistant accepts instructions before a human reviews them?
Q How should security teams govern MCP requests without relying on session state?
🌐 Identity Beyond IAM
Q How should security teams use device intelligence in fraud prevention without overblocking users?
Q Who is accountable when webview-based identity checks fail?
Q What breaks when embedded browsers do not preserve session state?
Q How do teams know whether visitor recognition is working in webviews?
Q Why do embedded browsers increase fraud risk in mobile flows?
Q Why do eligibility rules matter in digital identity workflows?
Q What breaks when biometric identity checks are used without fallback processes?
🤖 AI Security
Q Why do AI assistants with file or memory access increase security risk?
Q How should security teams defend against payload splitting in AI systems?
Q Who is accountable when a model follows a hidden instruction and triggers an action?
Q Why do payload splitting attacks bypass traditional prompt filters?
Q What breaks when an organisation blocks an AI model only at the proxy layer?
Q Why do self-hosted AI models still need strict governance?
Q Who should decide whether a high-risk AI model is allowed in enterprise use?
🛡️ Cyber Security
Q How should security teams use MCP for SaaS identity response?
Q What breaks when SaaS investigations depend on manual follow-up?
Q How do security teams know if provider provisioning is actually working?
Q What breaks when cloud providers are onboarded manually at scale?
Q Why do bulk cloud onboarding workflows create identity risk?
Q Why do GitHub repository defaults increase supply chain risk?
Q How should security teams harden GitHub repositories used in CI/CD pipelines?
No questions match your search.
Try a different keyword or clear search

Want to build your NHI knowledge further? Or need tailored advice for your organisation?

NHI Foundation Level Course → Advisory Services → Discussion Forum →