Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do AI agents increase segregation-of-duties risk in…
Governance, Ownership & Risk

Why do AI agents increase segregation-of-duties risk in identity governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

AI agents can hold roles, permissions, and group memberships that extend a human user’s effective reach. When those access paths are assessed separately, the governance team may miss a conflict that only appears when the human and agent are considered together. The risk comes from composite access, not from the agent alone.

Why composite access changes segregation-of-duties analysis

Segregation-of-duties checks usually assume one person, one role set, one effective path to sensitive actions. AI agents break that assumption because they can inherit access through delegation, shared workspaces, tokens, groups, or workflow permissions, then act alongside the human who initiated them. The control problem is not the agent in isolation, but the combined authority set that emerges when human and agent access is evaluated together.

That means a governance review can look clean at the individual identity level while still failing at the workflow level. If the human has approval rights and the agent has execution rights, or if both sit inside related groups, the organisation may have created a split path that still enables an end-to-end sensitive action. A useful way to think about it is that the agent can become an extension of the user’s effective reach, not a separate access island.

This is why AI agents belong in AI agent authorisation reviews and not only in account inventory. The question is whether the combination of user intent, delegated authority, and runtime access creates a prohibited business capability that neither identity would appear to hold alone.

Where identity governance teams miss the conflict

The most common miss is treating the agent as a technical tool instead of an acting principal with permissions. Once an agent can create records, move data, approve requests, or call downstream systems, it can satisfy one side of a SoD rule while the human satisfies the other. That creates a composite violation that simple role-to-role comparison will not catch.

Governance also gets harder when permissions are indirect. An agent may not have a direct high-risk role, but it may inherit authority through app scopes, service links, shared mailboxes, privileged workflow tokens, or nested groups. In that case, the relevant question is whether the effective action path crosses a prohibited boundary, not whether the agent has a named privileged role.

Top 10 agentic AI identity issues is a useful reminder that shared credentials, overprivilege, and human use of agent access are not edge cases. They are the failure modes that make composite SoD conflicts easy to miss in reviews built for human-only access models.

Where organisations rely on agents for operational work, the governance rule should be: assess the human and the agent as one effective access chain whenever either can influence the same control objective, transaction, or approval path.

How to reduce the risk without blocking useful automation

The practical response is to model agent access as task-scoped and time-bounded, then test SoD at the action level rather than only at the identity level. If an agent needs to create, approve, and publish within one workflow, that is a design signal to split duties, insert a human checkpoint, or narrow the agent’s authority.

Good practice is to bind the agent to a narrow purpose, keep its permissions separate from the human’s standing access, and require explicit approval when the agent would cross a policy boundary. The goal is not to remove automation, but to prevent the automation layer from collapsing the very separation that the control is meant to preserve.

Zero Trust for AI Agents is relevant here because SoD becomes much easier to enforce when each action is verified in context, standing privilege is removed, and access is re-evaluated per request. That approach fits especially well where the same workflow can be executed by different combinations of humans and agents.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIComposite agent access can silently exceed intended duties and cross SoD boundaries.
NHI-10 — Human Use of NHISoD breaks when human authority and agent authority are combined in one effective access path.
Recommendation — Limit agent permissions to the minimum task scope and remove any standing access that can complete restricted workflows. Separate human and agent action paths and require review when one identity can amplify the other.
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseThe issue is privilege accumulation across human and agent roles, scopes, and delegation.
Recommendation — Assess delegated authority and composite privilege before allowing an agent to execute sensitive actions.
NIST SP 800-53 Rev 5AC-5 — Separation of DutiesThe subject is explicitly about SoD conflicts caused by combined human-agent authority.
AC-6 — Least PrivilegeRestricting agent authority reduces the chance that combined access becomes a SoD violation.
IA-9 — Service Identification and AuthenticationAgents often act through service-style credentials, making machine authorization part of the control path.
Recommendation — Enforce role splitting and independent approval paths for sensitive transactions. Constrain agent permissions to the smallest action set needed for the task. Authenticate non-human actors separately so delegated access is visible and controllable.
ISO/IEC 27001:2022A.5.15 — Access controlAccess governance must account for effective access created by combined user and agent permissions.
A.5.18 — Access rightsRights review must catch hidden conflicts created by delegated or inherited agent access.
Recommendation — Define access rules that consider composite authority across users, apps, and agents. Review access rights for workflows where humans and agents jointly reach sensitive outcomes.
CIS Controls v8CIS-5 — Account ManagementAccount and permission lifecycle controls help prevent agent access from silently expanding SoD scope.
Recommendation — Inventory and review accounts, groups, and delegated permissions that can combine into restricted access.

Practitioner Guidance

What to verify: Review SoD controls at the workflow level, not just the account level. The key check is whether the human and the agent together can complete a sensitive transaction that should require separation, even if each looks acceptable on its own.

Decision rule: If an agent can execute a step that completes, enables, or materially influences a restricted business process, treat its permissions as part of the user’s effective authority and require explicit conflict review before deployment.

Common mistake: Teams often focus on whether the agent has admin rights, but the real risk is subtler, composite access through ordinary permissions that become privileged only when combined with the initiating user’s role.

Practitioner takeaway: AI agents raise SoD risk when they blur the boundary between who approves and who acts; the control only works if governance measures the combined path to the outcome, not the agent or the human in isolation.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org