The system does not become more autonomous in a useful way. It becomes more confident about incomplete context, which leads to weak triage, poor correlation and unreliable closures. In practice, missing identity telemetry, inconsistent schemas and thin log retention cause the agent to scale error, not insight.
Why This Matters for Security Teams
agentic ai depends on trustworthy identity context to decide what it can do, which actions belong to which actor, and whether a result is safe to close. Without complete identity and telemetry data, the system cannot distinguish a legitimate workflow from a compromised one, or a normal service account from an overprivileged agent. That gap undermines detection, response, governance, and auditability at the same time. Guidance from the NIST AI Risk Management Framework stresses that AI systems need measurable oversight, traceability, and risk controls, not just better model output.
The practical issue is that many teams treat identity and telemetry as a backend logging concern, when they are actually part of the control plane for agentic behaviour. If the agent cannot reliably map actions to identities, entitlements, tools, and session context, it will infer structure that is not really there. That creates false confidence, especially in triage and containment workflows where speed can mask missing evidence. In practice, many security teams encounter this only after an agent has already closed the wrong incident, escalated the wrong account, or missed a lateral movement path.
How It Works in Practice
Complete identity and telemetry data gives an agent the minimum context needed to reason about who acted, what was accessed, when it happened, and whether the action fits the expected pattern. In security operations, that typically means correlating human users, non-human identities, API tokens, device posture, workload identity, and tool invocation logs across systems. When that correlation is intact, the agent can support investigation, privilege review, and policy enforcement with far less guesswork.
Missing or inconsistent data breaks that chain in predictable ways. The agent may over-trust an event because it sees a valid login but not the subsequent token exchange. It may miss a privilege escalation because the entitlement record is stale. It may fail to join events across SIEM, identity provider, cloud control plane, and ticketing data because schemas do not align. The result is not just lower accuracy. It is distorted reasoning.
- Identity data must link users, NHIs, agents, and delegated sessions.
- Telemetry must preserve source, timestamp, action, and authorization context.
- Retention must be long enough to support correlation across the full incident window.
- Schema normalisation must be consistent across cloud, endpoint, and identity platforms.
This is where the OWASP Agentic AI Top 10 and the OWASP Top 10 for Agentic Applications 2026 are useful, because they highlight how tool misuse, unsafe delegation, and weak oversight become exploitable when the control boundary is unclear. MITRE’s MITRE ATLAS adversarial AI threat matrix also matters when telemetry gaps prevent defenders from seeing prompt abuse, model manipulation, or inference-time attacks. These controls tend to break down when logs are fragmented across tenants and the agent is allowed to act on partial evidence because the environment treats missing data as harmless.
Common Variations and Edge Cases
Tighter identity and telemetry control often increases integration and retention overhead, requiring organisations to balance better assurance against operational complexity. That tradeoff is real, especially in fast-moving environments where multiple agents, ephemeral workloads, and short-lived credentials are normal.
Best practice is evolving for how much context an agent should require before acting, and there is no universal standard for this yet. In highly regulated environments, the safer pattern is to gate high-impact actions behind explicit identity proof, enriched audit trails, and human confirmation. In lower-risk automation, teams may accept partial telemetry for low-severity triage, but only if the agent is prevented from closing incidents or changing access based on incomplete evidence.
Edge cases also matter. Cross-domain investigations often fail when one system records the human approver, another records the service identity, and a third records only the orchestration layer. Similarly, deleted or rotated credentials can make historical correlation fragile unless the platform preserves immutable linkage records. For agentic AI, that means an incident may look resolved when it is actually only under-observed. The CSA MAESTRO agentic AI threat modeling framework is a useful reference for deciding where those operational boundaries should sit.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, MITRE ATLAS and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | AI risk governance depends on traceability and oversight for agent decisions. | |
| OWASP Agentic AI Top 10 | Weak identity and telemetry amplify agentic misuse, delegation, and tool abuse. | |
| MITRE ATLAS | Telemetry gaps reduce visibility into adversarial AI manipulation and evasion. | |
| NIST CSF 2.0 | DE.AE | Anomalies are harder to identify when identity telemetry is incomplete. |
| CSA MAESTRO | MAESTRO addresses control boundaries for agentic AI systems and their evidence trail. |
Correlate model, prompt, and tool events so adversarial behavior can be detected and investigated.
Related resources from NHI Mgmt Group
- How should security teams govern machine identity credentials in agentic AI environments?
- What breaks when data governance is used as a substitute for AI agent identity controls?
- What breaks when deception is used without identity telemetry?
- What breaks when AI tools can query identity data without strong auditability?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org