verifiedagents.ai
All posts

5 min readAI Agents · Privilege Changes for AI Agents

How Do You Govern Non-Human Identities at Agent Scale?

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: How Do You Govern Non-Human Identities at Agent Scale?

TL;DR: Non-human identities outnumber humans 10 to 50 times in cloud-native enterprises, and AI agents are the fastest-growing slice. A 2026 GitGuardian survey found 84 percent of organizations lack effective NHI governance. The fix is five capabilities, in order: discovery, ownership, scope, expiration, and audit.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai: the five capabilities in order, then the agent-to-agent trap and the four numbers your board actually wants.

What is the NHI governance problem?

Ask a cloud-native enterprise how many identities can reach production and the answer undercounts by an order of magnitude. The CISO quotes the employee count. Reality: for every human in the directory, 10 to 50 non-human identities run with credentials on production data, and most were never approved through any formal review.

Marketing spins up agents that authenticate against six SaaS tools. Engineering ships agents holding database credentials. Each one is an NHI. A separate RSAC 2026 report found 71 percent of CISOs say agents have access to core systems, while only 16 percent govern that access effectively. Boards started asking because regulators started asking, and the question now stops at the CISO's desk.

Whether agents even belong in the NHI bucket is its own argument, covered in are AI agents the same as non-human identities. Either way, somebody has to govern them.

Why does traditional IAM fail here?

Three assumptions break, and they're structural.

IAM assumes

Agents deliver

Identity is stable: one person, one role

One credential acting as summarizer, writer, and executor inside three minutes

Behavior is stable week to week

A normal that changes with every prompt, model version, and memory update

Access patterns repeat: the same five apps daily

Read access for this task, write access for the next, broad access granted by default

The fix isn't retrofitting human IAM onto agents. It's treating NHIs as their own governance category with their own controls and audit cadence.

What are the five capabilities of real NHI governance?

In order, because each depends on the one before it.

  1. Discovery.

    A continuous inventory of every NHI: service accounts, API keys, OAuth tokens, certificates, agent credentials, CI/CD secrets. New ones surface within seven days via network logs, API gateway logs, finance audits, and secrets-manager reconciliation.

  2. Ownership.

    One named human per NHI. Not a team. If you can't name the owner, the NHI doesn't belong in production.

  3. Scope.

    Documented by action, not by system. "Can read contact records" is scope. "Has access to the CRM" isn't.

  4. Expiration.

    Every credential rotates on a schedule. No tokens surviving twelve months unreviewed, no service accounts untouched since 2023.

  5. Audit.

    Every action logged with enough context to replay the decision: inputs, reasoning, action, result. Without it you can't run forensics or satisfy a regulator.

What's the agent-to-agent trap?

Inherited privilege. An orchestrator agent calls a worker agent and passes its token, and the worker now holds the orchestrator's full access. Nobody decided that. It's the default, and in 2026 it's one of the fastest-growing privilege escalation paths in cloud environments. A compromised low-privilege agent doesn't need an exploit. It just asks another agent to do something that agent is allowed to do.

The fix: treat every agent-to-agent call like an external API call. Authenticate it, no shared tokens. Scope it to the specific request, with no privileges carried forward from past calls. Log both sides so you can replay the chain. Then put the same controls on it you'd put on a third-party API: review, rate limits, anomaly detection. Most identity platforms don't support this out of the box yet. Write the policy anyway and make the technology match it. The truth-checking side of those handoffs is in how to verify AI agent handoffs.

What should the board slide say?

Four numbers, one slide.

  • Total NHI count.

    If it isn't churning quarter over quarter, discovery isn't working.

  • Percentage with named owners.

    The target is 100. Anything less is a backlog nobody answers for.

  • Percentage with task-level scope.

    Most start in single digits. The trend counts more than the number.

  • Out-of-scope actions last quarter.

    Each one is either an honest misconfiguration or a compromise, and the investigation says which. Show the count and the time-to-fix trend.

Those four tell the board whether you're governing NHIs or just naming them.

Frequently asked questions

How do we find NHIs we don't know about?

Run three sweeps at once: reconcile the secrets manager against active services, scan network logs for traffic to AI provider endpoints from unregistered systems, and audit finance for AI-platform charges with no matching record. The overlap surfaces almost every shadow NHI.

How is task-level scope different from role-based access?

Roles are persistent grants. Task scope exists only while the task runs and expires with it. Agents need the second, because their work changes minute to minute.

What about NHIs inside third-party SaaS tools?

Same program. An identity inside Salesforce or Snowflake that touches your data belongs in your inventory. Most organizations forget these first, and regulators now ask about them specifically.

Where does the ATF fit?

NHI governance is the broad category. The five ATF elements, from Identity Management through Incident Response, are what you layer on the AI agent subset to handle reasoning and behavioral change.

Key takeaways

  • 10 to 50 NHIs per human, and agents growing fastest.

  • 84 percent of organizations lack effective NHI governance. 71 percent of CISOs admit core-system agent access; 16 percent govern it.

  • Five capabilities in order: discovery, ownership, scope, expiration, audit.

  • Treat agent-to-agent calls as external API calls. Inherited tokens are the escalation path.

  • Four numbers on one slide tell the board the truth.

Count yours before someone else does

The free ATF assessment takes about ten minutes and shows where your agent identities stand against the five elements.

The 2026 board is asking politely. The 2027 regulator won't.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.