Directory-first governance breaks because AI agents are ephemeral, may never be fully enumerable, and can disappear before enrollment or certification completes. That means the control plane sees a record of an identity rather than the runtime actor itself. Security teams should treat the directory as inventory support, not as the point where protection begins.
Why directory-first governance fails for AI agents
Directory models assume a stable population: something is enrolled, stays present long enough to be reviewed, and can be certified on a schedule. AI agents do not behave that way. Their runtime existence, delegated authority, and tool access can appear and disappear faster than a directory workflow can finish, so the directory becomes a record system rather than the control point.
That matters because the security decision is not “does this agent exist in the directory?” but “does this runtime actor have the right authority right now?” In practice, the control has to follow the agent’s live permissions, not just its registration state. AI Agent Authorisation Guide is useful here because it treats task-scoped access, just-in-time approval, and per-action policy as the real governance layer.
Directory-first thinking also breaks when teams confuse inventory with protection. A directory can help you discover agents, owners, and intended purpose, but it does not guarantee that an agent is still active, still trusted, or still limited to the permissions it should have. That is why Shadow AI and AI Agent Discovery Guide is a better complement to governance than a directory alone, because discovery and governance are not the same thing.
What is the control-plane mismatch?
The mismatch is between lifecycle speed and administrative workflow. Directories are good at representing entities, ownership, and intended entitlements, but AI agents often act through short-lived sessions, delegated tokens, or temporary tool access. By the time a human review catches up, the actor may have already completed the risky action or vanished before certification closes.
This is why the control plane must observe the live request path. A mature approach verifies the principal, the action, and the context at the moment of execution, then constrains what the agent can do based on that request. Zero Trust for AI Agents aligns with that model because it shifts the trust decision from enrollment status to continuous verification and no standing privilege.
It also explains why agent identity and agent lifecycle matter more than directory completeness. If the agent can obtain access outside the directory’s review window, then the directory has become an audit artifact instead of an enforcement layer. Agentic AI Identity Guide covers the underlying identity, delegation, registration, and retirement issues that directory-only governance tends to miss.
What should teams govern instead of the directory record?
Teams should govern the live permission boundary: who or what the agent is acting for, what it can do, which tools it can reach, and under what approval or policy conditions. That means focusing on delegated authority, per-action authorization, short-lived access, and explicit offboarding when the agent is no longer needed.
Good governance also requires observability. If an agent can act, the organisation should be able to attribute that action, detect when behaviour drifts, and revoke access quickly. AI Agent Observability, Audit and Incident Response Guide is relevant because it ties logging, attribution, and kill-switch design to the actual runtime behaviour of agents.
For broader security framing, the issue is not unique to one product or one identity store. It is a governance pattern: the asset to protect is the action surface, not the directory row. NIST AI Risk Management Framework supports that view by emphasizing governance, measurement, and ongoing risk management around AI systems rather than one-time enrollment checks.
Risk and Threat Considerations
Directory-first governance creates a blind spot when an agent can obtain or use access before it is fully inventoried, certified, or retired. That opens the door to overprivilege, stale access, and unobserved action, especially when agents are provisioned quickly or chained through multiple tools and services.
Failure mechanism: The organisation treats registration as protection, but the real risk occurs at runtime, where the agent can exercise delegated authority, inherit excess permissions, or disappear before a review catches up.
Impact: A short-lived or unmanaged agent can still steal data, trigger destructive actions, or persist through tokens and tool access even after the directory record is removed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Agent governance depends on short-lived credentials and revocation. |
| AC-6 — Least Privilege | Directory-first failure often leaves agents overprivileged at runtime. | |
| AU-2 — Event Logging | Runtime enforcement needs attributable agent activity and reviewable evidence. | |
| Recommendation — Enforce credential lifecycle controls so agent access can be revoked and rotated quickly. Constrain each agent to the minimum privileges needed for the current task. Log agent actions and approvals so runtime behaviour can be audited and investigated. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | The question hinges on verifying the agent and request at runtime, not trusting directory state. |
| Recommendation — Verify each agent request continuously before granting tool or data access. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Directory-only governance fails when access decisions are not enforced at use time. |
| Recommendation — Define and enforce access rules that apply to live agent requests, not only records. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Agent authority can outlive directory review, creating privilege abuse risk. |
| Recommendation — Limit delegated authority and remove standing access for agents. | ||
Practitioner Guidance
What to prioritise: Put runtime authorization and revocation ahead of directory completeness. If the agent can reach production tools, the first question is whether access is bounded and observable, not whether the record is clean.
What to verify: Confirm that every agent has an owner, a purpose, an expiry or retirement path, and a policy decision point that can deny or narrow access per action. If those controls do not exist, the directory is not a governance control, only an inventory source.
Common mistake: Teams often try to certify agents the same way they certify human accounts. That fails when the agent’s useful life is shorter than the approval cycle. NIST SP 800-53 Rev 5 Security and Privacy Controls remains relevant as a control catalogue, but only when mapped to live authorization, credential lifecycle, and audit outcomes rather than static record-keeping.
Practitioner takeaway: Govern AI agents at the point of action, because a directory can describe an agent, but it cannot by itself stop an ephemeral actor from doing harm.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org