Start with inventory, because you cannot govern what you cannot name, own, or scope. Once agents are visible, policy can reduce standing access and enforce time-bound grants, but discovery comes first when ownership and purpose are already unclear.
Inventory First: Why Visibility Beats Policy When Agents Are Unclear
Organisations should start with agent inventory when ownership, purpose, and scope are still unclear. Policy only works against named, classified, and owned agents. Until you can identify what exists, who owns it, and what it can touch, access rules are easy to misapply, miss, or overgeneralise.
That is why discovery and classification are the first control plane. A workable inventory tells you whether an agent is legitimate, duplicated, dormant, shadowed, or business-critical. It also exposes which identities, tools, and environments are actually in play, so the policy question becomes concrete rather than hypothetical. For a broader NHI lifecycle view, see Ultimate Guide to NHIs and the NHI Lifecycle Management Guide.
Inventory also gives policy its target population. Without it, teams tend to write generic rules that either do too little, because unknown agents remain outside scope, or too much, because the policy is broad enough to cover systems that do not need the same access pattern. That is especially relevant where agent populations grow faster than teams can manually track them; NHIs already outnumber human identities by 25x to 50x in modern enterprises, making visibility a prerequisite for governance rather than a reporting nicety.
When Access Policy Becomes the Priority
Once agents are visible and ownership is assigned, access policy should move quickly. The practical goal is to replace standing access with bounded, time-limited, and purpose-specific grants. That reduces blast radius, but it only works after inventory has established what each agent is meant to do and which entitlements are justified.
Policy is most effective when it is tied to actual agent functions, not labels. A deployment bot, customer support assistant, data pipeline agent, and code-review agent may all be “agents,” but they should not inherit the same access pattern. Inventory lets you separate those use cases; policy then constrains each one to the minimum access needed. The governance logic behind that progression is covered in Ultimate Guide to NHIs — Key Challenges and Risks and the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs.
Where teams jump to policy first, they often create rules that are technically sound but operationally weak. The policy may say “least privilege,” yet no one can prove which agent owns which permission, why the permission exists, or whether the agent is still active. In that state, policy becomes a documentation exercise rather than a control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — NHI Discovery and Inventory | Inventory and ownership are central to governing non-human agents. |
| NHI-02 — Secrets and Credential Management | Policy reduces standing access once agents and their credentials are known. | |
| NHI-03 — Least Privilege and Access Governance | The question is about sequencing inventory versus policy for agent access governance. | |
| Recommendation — Inventory all agents before tightening access, and assign each one a clear owner and purpose. Reduce standing access and time-box grants for every discovered agent credential. Apply least privilege only after agent scope is established and documented. | ||
| CIS Controls v8 | 01 — Inventory and Control of Enterprise Assets | Agent inventory is an asset-visibility problem before access tuning. |
| 06 — Access Control Management | Policy is the mechanism that trims and reviews agent access after discovery. | |
| Recommendation — Maintain an authoritative inventory of agents and related assets before enforcing access rules. Limit and review agent access only after the population is fully identified. | ||
| NIST CSF 2.0 | ID.AM — Asset Management | Agent inventory is fundamentally an asset-management prerequisite for governance. |
| PR.AA — Identity Management, Authentication and Access Control | Access policy governs what known agents may do once they are inventoried. | |
| Recommendation — Identify and track agents as assets before assigning access constraints. Define and enforce access rules for each inventoried agent based on its purpose. | ||
| NIST Zero Trust (SP 800-207) | 3.1 — ZTA Logical Components and Policy Engine | Zero Trust policy depends on knowing the subjects and their access context. |
| Recommendation — Use policy enforcement only after the agent population and trust boundaries are mapped. | ||
Practitioner Guidance
What to prioritise: Build the inventory around ownership, purpose, and environment before tightening access. If you cannot answer who the agent is for, what it does, and where it runs, policy will be incomplete and difficult to enforce.
Decision rule: If the agent population is not yet mapped, start with discovery and classification; if the agents are already enumerated and owned, move immediately to access reduction, time-bounded grants, and periodic review. Inventory solves ambiguity, policy solves excess.
What good looks like: Every agent has a named owner, an explicit purpose, a current environment scope, and a documented access profile that can be reviewed without guesswork. The control is working when new agents are visible quickly and unnecessary standing access is removed without waiting for an incident.
Practitioner takeaway: Inventory is the prerequisite control, while policy is the enforcement control. If you reverse that order, you usually end up governing a population you have not yet fully identified.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- How can organisations reduce the blast radius of compromised agent identities?
- Should organisations prioritise secret rotation or access review first
- Should organisations prioritise discovery or access restriction first for shadow AI?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 22, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org