2 min read

AI agents need access without seeing secrets

As AI agents take on enterprise tasks, identity systems must treat them like managed digital workers without exposing credentials.

Image: TechRadar

AI agents are starting to act like digital employees, and that is forcing a rethink of enterprise identity. In this TechRadar Pro Perspectives piece, the Field CTO for EMEA at Ping Identity argues that companies need to give agents enough access to do useful work without handing them the credentials and secrets behind that access.

The core problem is that most identity and access management (IAM) systems were built for human users and one-time verification. In an agentic enterprise, access requests may also come from autonomous software acting on behalf of people, which means organizations need continuous visibility into who or what is accessing systems and whether those permissions are still appropriate.

How AI agents change identity management

The article says AI has created a new category of digital identity. Like employees, autonomous agents need to be discoverable, governed, and tied to accountability so organizations know:

  • what systems and data they can access
  • who is responsible for their actions
  • how their activity can be audited throughout their lifecycle

At the same time, machine-native interfaces are letting agents help with identity operations, including managing human users' access, troubleshooting issues, and supporting security workflows. That may cut costs and improve efficiency, but only if companies put strong guardrails around what those agents can do.

Recommended reading

Hugging Face hit by AI agents, then blocked by LLM guardrails

A unified identity model for AI

The piece argues that organizations should not bolt AI security onto legacy human-focused identity systems. Instead, they need a single framework that governs both human and machine identities, reducing tool sprawl and avoiding security blind spots.

That framework should include AI-first headless interfaces for autonomous agents and builders, full visibility across the entire agent lifecycle, and a designated human owner for every AI identity. Crucially, agents should not get direct access to long-lived credentials or secrets. The recommended alternative is just-in-time privileged controls, which can broker access to enterprise resources while preserving oversight of how permissions are granted, governed, and audited.

The argument is straightforward: AI agents cannot deliver value without enterprise access, but unrestricted access creates new risk. For the agentic enterprise to work, identity has to become programmable, auditable, and designed to govern both people and software under one model.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechRadar

// Keep reading