Managing AI Agents Transparently and Securely: How an AI Agent Identity Assessment Lays the Foundation
Managing AI Agents Transparently and Securely: How an AI Agent Identity Assessment Lays the Foundation
Are identities within the organization adequately protected? Many companies would respond with an enthusiastic “Of course!” Yet they often have human users primarily in mind. What they overlook is that machine identities - also known as non-human identities , or NHIs - and, increasingly, AI agents are emerging as a distinct class of digital identities. They introduce new risks around access, control and traceability, ultimately affecting the security of the entire organization. An AI Agent Identity Assessment provides clarity on where an organization currently stands - and does so within just a few weeks.
Human Identities vs. AI Agents
They have long outnumbered human identities. Service accounts, technical accounts, workload identities, API keys and other secrets - the list of non-human identities is extensive. As AI agents become more widespread, their number continues to grow. According to SAP LeanIX’s “Agentic AI Survey 2026”, 98 percent of companies already use AI agents or plan to introduce them in the near future.
The problem is that 48 percent have not defined clear roles or permissions for their AI agents. Without technical guardrails, however, AI agents can act as they see fit - and their actions may not always align with security requirements.
This challenge is compounded by the specific characteristics of AI agents. They are created dynamically, often within seconds, request permissions at runtime, independently call tools and APIs, delegate tasks to one another and chain actions across multiple systems.
Why Traditional IAM Is Reaching Its Limits
Traditional Identity and Access Management (IAM) can only keep pace with these developments to a limited extent. Most IAM systems were designed for stable, long-term and well-known human identities. AI agents, by contrast, act dynamically and based on context, and they are often short-lived - or ephemeral. Traditional approaches are therefore not ideally suited to managing them.
But the challenge is not purely technical.
From an organizational perspective, AI agents also put existing IAM structures to the test. Companies often lack a complete overview of which AI agents exist, where they are used, which systems they connect and what permissions they hold. It may also be unclear who is accountable from a business perspective and who is authorized to approve technical changes.
The result is overly broad permissions, a lack of traceability and identity lifecycles that are not terminated in a controlled manner.
Where the Risks Lie
Where governance is missing, security risks quickly emerge. This is largely due to the autonomous nature of many AI agents. If they hold excessive permissions, access APIs without sufficient controls or perform actions that are not properly logged, blind spots arise across Identity Security.
The situation becomes particularly critical when AI agents operate without human oversight. A human-in-the-loop approach is therefore essential. Employees should retain the final say in situations such as granting or changing permissions, accessing particularly sensitive data, deleting or transferring large volumes of data, making changes to production Systems, approving financial transactions, or making decisions that affect customers, employees or compliance.
AI Agent Identity Assessment: The Path to Controllable Agent Identities
Before taking action, companies should first establish maximum transparency across their existing non-human identities and AI agents. Only then can governance gaps be identified and appropriate next steps defined. This process consists of three phases.
#1 Discovery
The first step is to answer a wide range of questions:
- Which non-human identities already exist?
- Which AI agents, copilots and automations are currently in use?
- Which systems, APIs and data sources do they access?
- Who holds business and technical responsibility?
- Which permissions are genuinely required?
- How are secrets managed?
- How are actions logged?
- Which operations require human approval?
- How are agents decommissioned?
- Which standards and architectural approaches should apply in the future?
The most valuable and practical answers come from involving IT and security teams as well as business departments. Even where individual aspects have been documented in a strategy paper, this does not necessarily mean they have been implemented in day-to-day operations.
Data from directory services, cloud IAM platforms and secrets-management systems can provide additional transparency.
#2 Gap Analysis
The gap analysis examines the difference between the current and target states. Organizations should assess six key dimensions:
- Inventory and ownership: Which non-human identities and AI agents already exist? Where are they used? Has an accountable business owner been assigned to every identity?
- Lifecycle: Are there defined processes for creating, changing, operating and decommissioning agent identities? Is there a regular review of whether agents, accounts, tokens and secrets are still required?
- Least privilege and permission scope: Do AI agents have only the permissions they genuinely need for their specific tasks? Are permissions restricted by time, purpose and context?
- Authentication and secrets hygiene: How do agents authenticate to systems, tools and APIs? Are API keys, tokens and secrets stored securely, rotated regularly and revoked when necessary?
- Logging and traceability of agent actions: Can the organization determine which agent performed a particular action, which access rights it used, the context in which it acted and the data on which the action was based?
- Human-in-the-loop controls: Which actions may AI agents perform autonomously, and where must humans retain final control? This applies, for example, to privileged access, sensitive data, system changes and compliance-relevant decisions.
Experts who have already developed a governance model for agent identities can reduce the analytical workload and help companies arrive at a robust assessment more quickly.
#3 Reference Architecture and Roadmap
Based on these findings, organizations can develop a target architecture for non-human identities and AI agent identities. It is important to incorporate open standards and architectural approaches such as OAuth 2.0, token exchange, fine-grained authorization, security for MCP and A2A communication, and delegation models. Because AI agents operate across system and vendor boundaries, open standards provide an effective shared security foundation.
ℹ️ Bring in the Experts
What sounds straightforward on paper can be challenging in practice - especially alongside day-to-day responsibilities. An AI Agent Identity Assessment can therefore often be completed more efficiently with expert support.
Our umbrella.associates team typically plans for a delivery period of three to four weeks: one week for Phase 1, one week for Phase 2, and one to two weeks for Phase 3.
The main advantage is that proven governance models are already available, allowing the roadmap to be developed more quickly and with a clearer focus on practical outcomes.
At the end of the assessment, companies receive:
- an inventory of non-human identities and AI agents, including classification and ownership status,
- a risk heatmap showing the identified governance gaps across the six assessment dimensions,
- a policy framework for securely managing the lifecycle of agent identities - from creation and operation through to decommissioning - which can be incorporated into the organization’s own policies,
- a reference architecture containing integration recommendations for the existing IAM landscape, and
- a roadmap and management presentation outlining prioritized implementation steps for the next 12 to 18 months.
Take a Holistic Approach to IAM
Non-human identities and AI agent identities have become commonplace in organizations. Yet they are often not sufficiently embedded in Identity and Access Management, creating significant security risks. Organizations should therefore begin with an assessment of their current environment to establish transparency and clarity across the identities in use. This creates the basis for securing them appropriately in the next step.
Do non-human identities and AI agents still play only a minor role in your Identity and Access Management
strategy? Together, we can change that - and strengthen security across your organization.