AI Agents Are Digital Workers. Govern Their Identities Like It.

Share
AI Agents Are Digital Workers. Govern Their Identities Like It.
Governing the non-human identities behind agentic AI

Five questions second-line risk teams should be asking about the non-human identities behind agentic AI.

Every AI workflow you put into production has an identity behind it. It might be a service account, a workload identity, a managed identity, an API key, an OAuth application, or another non-human identity that allows the workflow to interact with enterprise systems.

As those workflows become more autonomous, the identity behind them stops being plumbing and starts becoming a governance problem.

The reassuring part is that the technology is new, but most of the governance challenges aren't. These are the same identity, access, and lifecycle problems we've managed for years—just amplified. A person can make one bad decision. An AI workflow can make thousands before anyone notices.

That's why I don't think organizations need an entirely new governance model for AI identities. They need to extend the identity governance disciplines they already have.

Six control areas every AI workflow identity should satisfy — the same foundation you'd expect for any privileged non-human identity.
Right-size the oversight: a read-only summarizer and a payment-approving agent don't need the same governance. Tier by business impact.
Policies don't prove governance — evidence does. Ten artifacts to request for any high-risk AI workflow.
Reconstruct the full sequence — who requested, which agent, what it accessed, what it decided, what happened — and keep the human, the workflow, and the owner as three distinct identities.
Don't invent a separate AI risk framework. Report through the four questions your Board already understands.
Most AI governance failures are familiar identity problems, amplified — with a few genuinely new ones layered on top.

Here are the five questions I'd want every second-line risk team to be able to answer.

1. Are AI workflow identities governed like every other privileged identity?

One of the biggest mistakes I see is treating AI workflow identities as something fundamentally different from other non-human identities. They're not.

Every AI workflow identity should have the same governance foundation I'd expect for any privileged non-human identity:

  • a named business owner
  • a documented business purpose
  • formal provisioning
  • least-privilege access
  • credentials managed securely through managed identities or a secrets vault
  • logging and monitoring
  • periodic access reviews
  • a defined retirement process

None of those controls are new. The difference is that AI workflows can act with far greater speed and scale than traditional automation.

The question I'd ask is simple:

Can you demonstrate that every AI workflow identity has only the access required to perform its approved function?

If the answer is no, you've already identified a governance gap.

2. Are you applying the right amount of governance?

Not every AI workflow deserves the same level of oversight.

A read-only summarization workflow shouldn't carry the same governance burden as one that approves payments, modifies production infrastructure, or accesses sensitive customer information.

That's why I recommend a risk-based approach.

Lower-risk workflows may only require ownership, inventory, logging, and periodic review.

Higher-risk workflows should introduce stronger controls such as privileged access management, just-in-time elevation, segregation of duties, human approval checkpoints, enhanced monitoring, and more frequent recertification.

The goal isn't to make governance heavier. It's to make it proportional to business risk.

3. Can you prove the controls actually exist?

Policies don't prove governance.

Evidence does.

For any high-risk AI workflow, I'd expect to see evidence such as:

  • inventory record
  • approved business use case
  • risk assessment
  • business owner
  • access approvals
  • current entitlements
  • least-privilege justification
  • credential management approach
  • monitoring and audit records
  • latest access review

If producing those artifacts is difficult, that's valuable information in itself. Mature governance should make that evidence straightforward to retrieve.

4. Can you reconstruct every important action?

This is where identity governance becomes accountability.

If an AI workflow performs a significant action six months from now, could you answer:

  • Who requested it?
  • Which workflow performed it?
  • Which identity authenticated?
  • Which version of the workflow or agent executed?
  • What information did it use?
  • What tools or systems did it access?
  • What decision did it make?
  • What action occurred?
  • What was the outcome?

If you can't reconstruct that sequence, you don't have complete accountability.

I also think it's important to keep three identities separate throughout the workflow:

  • the requesting human
  • the executing workflow
  • the accountable business owner

Those are three different responsibilities. Treating them as one makes governance significantly harder.

5. Are you reporting AI risk through your existing governance program?

One question I hear regularly is whether organizations need a separate AI risk framework.

In most cases, I don't think they do.

AI changes the speed, scale, and likelihood of existing risks far more than it creates entirely new categories of risk.

Rather than inventing new reporting structures, extend the enterprise risk reporting your executives and Board already understand.

I'd organize reporting around four questions:

  • What AI capabilities are deployed?
  • Which ones present the greatest business risk?
  • Are key controls operating effectively?
  • Where are we accepting residual risk?

That's a much more meaningful discussion than introducing a single "AI risk score."

What actually goes wrong?

Despite all the attention AI receives, most governance failures today are surprisingly familiar.

Organizations struggle with unclear ownership, excessive permissions, long-lived credentials, shared human accounts, poor lifecycle management, weak monitoring, and forgotten service accounts.

There are newer risks as well, including autonomous tool use, agent-to-agent delegation, expanding memory, and increasing autonomy over time.

But those are the exception, not the rule.

Most organizations don't need entirely new governance disciplines. They need to consistently apply the identity governance practices they already know work—and extend them to AI workflows.

The bottom line

As AI workflows become digital workers, they should be governed like digital workers.

The organizations that succeed won't necessarily be the ones with the most sophisticated AI models. They'll be the ones that can confidently answer three questions for every significant AI action:

  • Who authorized it?
  • Why did it happen?
  • Can we prove it?

If you can answer those consistently, you're well on your way to building an AI governance program that will scale as autonomous systems become part of everyday business operations.