Identity

AI agents are joining your workforce, and nobody is onboarding them

Somewhere in your organisation, an AI agent is probably already working. It drafts responses, reconciles invoices, triages tickets, summarises documents or moves data between systems. A team stood it up because it was useful, and it is. It also signs in to things.

Now compare its arrival to a human's. A new starter gets a contract, an onboarding process, access requests that someone approves, a manager who answers for them, and an offboarding checklist when they leave. The agent got an API key pasted into a configuration file. Nobody approved its access in any meaningful sense, nobody reviews it, and if the person who built it changes roles, it keeps running with whatever it was given, indefinitely.

Shadow AI has an access problem

The pattern repeating across organisations right now looks a lot like shadow IT a decade ago, with higher stakes. Agents appear department by department, authenticated with static keys, shared service accounts and hardcoded secrets, often holding standing access to production systems. There is rarely a register of them, rarely a named owner, and rarely a review cycle.

What makes agents different from the scripts and integrations we have always had is breadth and unpredictability. A script does the same thing every run. An agent decides what to do, which means its access needs to be scoped for everything it might do. Least privilege was designed for exactly this problem, and almost no agent deployment applies it.

The board-level questions write themselves: how many AI agents are operating in your environment today, what can each of them reach, and who owns each one? Most organisations cannot answer the first question, which makes the other two academic.

The third act of the identity story

This is the same story playing out for the third time. Workforce identity matured first: most organisations now govern how people sign in, what they can access and what happens when they leave. Machine and device identity lagged behind, which is the gap we wrote about in OT and IoT security. AI agents are the newest arrival, and they combine the worst of both: machine credentials with a human-like breadth of action, minus the predictability of either.

The discipline that works is the one identity teams already know, applied to a new population. A joiner process: agents get registered, owned and granted scoped access before they touch production. A mover process: when an agent's purpose, tooling or underlying model changes, its access gets reviewed, because a changed agent is a different agent. And a leaver process: agents get decommissioned deliberately, credentials revoked and rotated, rather than left running because everyone forgot they existed.

The platforms are moving

The identity industry has recognised the gap. Okta, whose partner we are, has brought agents into the identity platform as first-class identities: discovery of unmanaged agents, registration and ownership, credential vaulting and rotation, and governance workflows that treat agent access like any other access that needs certifying. Other vendors across the identity stack are heading the same direction. The platform capabilities are arriving; as always, the right answer depends on the estate you already run, and the harder work is the governance model the platform enforces.

What good looks like

The organisations getting ahead of this are building the same five things.

  • Find them. An honest discovery of the agents already running, including the ones nobody registered.
  • Give each an owner. A named human accountable for what the agent does and what it can access.
  • Scope the access. Least privilege applied properly: brokered credentials instead of hardcoded keys, time-bound instead of standing, and no shared accounts.
  • Govern the lifecycle. Registration at birth, review on change, deliberate decommissioning, the joiner-mover-leaver discipline for a non-human workforce.
  • Watch what they do. Logging and review of agent activity, so behaviour that drifts from purpose gets noticed.

Where to start

Not with a platform purchase, and not with a ban. Prohibition produces shadow agents; governance produces useful ones. The starting point is the same as any identity work: know your population, assign ownership, and put a policy in place that makes the safe path the easy path. That sits exactly where responsible AI adoption meets identity governance, which is the intersection we work in.

If agents are already appearing in your environment and nobody has been asked the three questions yet, that is the conversation to have before the register gets any longer. Talk to us.