Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should IAM teams do first when they…
Governance, Ownership & Risk

What should IAM teams do first when they discover unmanaged agent access?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Start with complete visibility before trying to reduce scope. Build a live inventory of agents, NHIs, and MCP connections, then use it to identify stale credentials, duplicate access paths, and approvals that no longer match the current operating context.

Why Visibility Comes Before Scope Reduction

Unmanaged agent access is usually a visibility problem before it is a cleanup problem. If you cannot see which agents exist, how they authenticate, and which connections they can use, any attempt to shrink access is likely to miss hidden paths or break active workflows. The first job is to establish a trustworthy inventory, then use that inventory to make scope decisions.

That inventory needs to cover more than obvious service accounts. It should include agents, Non-Human Identities, and MCP connections that may expose the same underlying capability through multiple routes. When teams start with visibility, they can separate genuine operating need from inherited access, abandoned approvals, and duplicated credentials that no longer match current use.

A practical way to frame the first pass is simple: discover what exists, identify what is active, and compare that to what is formally approved. That sequence matters because unmanaged access often persists through stale tokens, forgotten test integrations, shadow deployments, and old approvals that were never withdrawn after a role, tool, or environment changed.

What the First Inventory Should Actually Capture

The inventory should be live enough to answer three questions: who or what is connecting, what secret or trust path it uses, and which systems it can reach. For IAM teams, the key is to inventory the relationship, not just the account object. An agent with two authentication paths is materially different from one with one, even if both appear to belong to the same owner.

That is why agent discovery should include duplicate access paths and approval state, not only account names. A connection may be “managed” in one tool but still remain effectively unmanaged if the credential is long-lived, the owner is unclear, or the approval chain no longer reflects how the agent is actually deployed. Current access reality has to be compared with intended access, not with last quarter’s diagram.

The first pass should also surface stale credentials and abandoned links to systems that no longer need them. In practice, this is where teams find the highest-value cleanup candidates: credentials that have not rotated, approvals attached to retired use cases, and shared access patterns that hide which agent is doing what. Those are the items most likely to create excess blast radius.

How To Turn Discovery Into a Safe Reduction Plan

Once the inventory is complete, the next step is to group findings by risk, not by org chart. Access that is unused, duplicate, or impossible to trace should be treated before access that is merely inconvenient to review. The goal is to remove uncertainty first, because uncertainty is what makes later scope reduction brittle and politically harder to defend.

Teams should compare each unmanaged access path against current business need, operational dependency, and owner accountability. If the path is still needed, formalise it. If the path is no longer needed, remove it. If the path is ambiguous, keep it visible until the owner, approval basis, and rotation state are confirmed. This avoids the common mistake of revoking based on guesswork and then discovering an undocumented dependency in production.

For teams managing agent access at scale, lifecycle processes for managing NHIs provide the right sequence for discovery, governance, rotation, and offboarding. A parallel view is also useful in operational programmes, and the Identity Security Programme Guide shows how to assign ownership and governance so cleanup does not become a one-time exercise.

Risk and Threat Considerations

Unmanaged agent access creates hidden exposure because it often combines stale credentials, excessive privilege, and weak ownership. The immediate risk is not just unauthorized use, but the inability to tell whether a connection is legitimate, which makes containment slower and scope reduction less reliable.

Failure mechanism: dormant or duplicated access paths survive because the environment has no complete inventory, so old approvals, long-lived secrets, and forgotten MCP connections remain usable after the business context has changed.

Impact: attackers or internal misuse can exploit those leftover paths for lateral movement, unauthorized actions, or persistence, while defenders lose the ability to prove which agent had access to what at the time of an incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingUnmanaged agent access often persists after ownership or use case changes.
NHI-07 — Long-Lived SecretsStale credentials are a core finding when unmanaged access is discovered.
NHI-05 — Overprivileged NHIDuplicate and unmanaged paths usually indicate excess access beyond current need.
Recommendation — Remove obsolete agent access paths as soon as ownership or purpose is no longer current. Inventory and rotate long-lived credentials before narrowing access scope. Review actual runtime access and reduce every privilege that is not required.
NIST SP 800-53 Rev 5CM-8 — System Component InventoryThe question starts with building a complete live inventory before remediation.
IA-5 — Authenticator ManagementThe answer centers on stale credentials and authentication paths that need control.
Recommendation — Maintain an accurate inventory of agents, connections, and credentials before changing access. Track, rotate, and retire authenticators that no longer match current use.

Practitioner Guidance

What to prioritise: inventory first, then remediation. Start with a live map of agents, NHIs, secrets, and MCP connections, and flag anything with unclear ownership, duplicated authentication paths, or no obvious business justification.

What to verify: each retained access path should have an owner, an active use case, and a current approval basis. If any one of those is missing, treat the path as a candidate for containment, not as a default keep.

Decision rule: if the access path is still needed but cannot be explained, freeze changes until the owner is identified; if it is not needed, remove it; if it is duplicated, consolidate before you rotate or revoke so you do not strand production dependencies.

Practitioner takeaway: unmanaged agent access is safest to fix from the inventory outward, because you cannot reduce scope responsibly until you can distinguish current, necessary access from inherited access that is only still present by accident.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org