Defender Impact
Conventional IAM platforms govern access as it is configured — they cannot observe what an autonomous AI agent actually does once granted entry to an enterprise system. This framework directly addresses that intent-to-execution gap, giving defenders a structured model to move from policy intent to runtime assurance for non-human identities.
Capability Overview
The framework treats every AI agent as a non-human identity with five mandatory attributes: a human owner, a defined purpose, scoped authorisation, an expiration, and continuous monitoring. This mirrors established principles for service accounts and machine identities, but adapts them to the unique characteristics of AI agents — specifically their capacity to chain tasks dynamically, select tools autonomously, and compose actions that no static entitlement review anticipated.
The framework identifies a structural problem it terms identity dark matter: agent identities created by infrastructure automation, deployment pipelines, or application teams that never pass through HR-driven governance workflows and therefore accumulate outside compliance inventory. These identities carry recurring failure modes: absent ownership (no named human accountable for an agent’s continued existence), long-lived secrets (static API keys persisting across deployments without rotation), and unbounded delegation (agents inheriting wholesale user or service permissions rather than receiving the minimum scope required for their task).
Critically, the framework draws a distinction between two IAM dimensions that conventional platforms handle — design-time lifecycle management and runtime authentication at the application perimeter — and a third dimension they have never addressed: what the agent executed once inside the application. Configuration findings describe possibility; only runtime telemetry describes what occurred. The framework positions this telemetry layer as non-optional for any assurance claim.
The OWASP Top 10 for LLM Applications explicitly names excessive agency (LLM08) as the failure mode where an agent granted broad functionality exercises capability beyond its approved task. This framework provides the governance architecture to bound that behaviour structurally rather than relying on post-incident detection alone.
Defensive Advances
Non-human identity inventory discipline. Defenders can now apply a repeatable model to surface and catalogue agent identities that currently exist outside central IAM visibility, closing the dark matter problem before it becomes an audit or incident finding.
Ownership accountability. Mandating a named human owner for every agent identity creates a traceable accountability chain — essential for incident response, access reviews, and decommissioning workflows that previously had no trigger event for autonomous agents.
Runtime verification posture. By framing runtime telemetry as the evidence layer that validates or contradicts policy intent, the framework gives security teams a concrete requirement to bring to platform and engineering owners: agent execution must be observable, not assumed compliant.
Credential hygiene for agent lifecycle. Linking credential rotation to agent lifecycle events (deployment, purpose change, retirement) rather than calendar schedules reduces the long-lived secret window that static API keys represent.
Residual Gaps
The framework describes architecture and principles — the tooling ecosystem to implement runtime agent telemetry at enterprise scale is still maturing. Organisations without existing non-human identity management platforms will face a sequencing challenge: they must build or acquire inventory capability before they can monitor it meaningfully.
Human ownership assignment sounds straightforward but is operationally demanding in environments where agents are deployed by autonomous pipelines. Governance processes that assume human-initiated provisioning will require re-engineering before the ownership model is enforceable rather than aspirational.
The intent-to-execution gap also requires telemetry instrumented at the application and infrastructure layer, not just at the IAM perimeter. Many enterprises lack the observability coverage in their application estate to produce the runtime evidence this framework requires. Realising the full benefit is therefore dependent on a complementary investment in application-layer logging and behavioural analytics.
Framework Mapping
- AML.T0012 (Valid Accounts) and AML.T0083 (Credentials from AI Agent Configuration): Scoped, time-bounded credential provisioning directly reduces the exploitability of agent credentials obtained through configuration access.
- AML.T0086 (Exfiltration via AI Agent Tool Invocation) and AML.T0098 (AI Agent Tool Credential Harvesting): Runtime telemetry requirements create detection surfaces for anomalous tool invocation patterns.
- AML.T0103 (Deploy AI Agent): Inventory discipline and ownership requirements raise the governance bar for agent deployment, reducing uncontrolled agent proliferation.
- LLM08 (Excessive Agency): The framework’s core value proposition is structural mitigation of excessive agency through scoped authorisation and runtime validation.
Deployment Considerations
Organisations should sequence adoption in three phases. First, complete a non-human identity discovery exercise to establish the current inventory — you cannot govern what you cannot see. Second, apply ownership and scoping controls to the highest-privilege agent identities before addressing the broader population. Third, build toward runtime telemetry coverage, treating it as a programme milestone rather than a day-one requirement.
Existing privileged access management (PAM) platforms often have non-human identity modules that can accelerate the credential hygiene elements. IAM platform vendors are beginning to add agent identity primitives — evaluate whether existing tooling can be extended before procuring net-new solutions.
Security architecture reviews for new agent deployments should gate on ownership assignment and scope definition as hard requirements, not post-deployment additions.
Defender Checklist
- Complete a non-human identity discovery scan across all environments to surface unmanaged agent identities
- Assign a named human owner to every discovered agent identity as a mandatory governance attribute
- Replace static API keys and long-lived tokens with short-lived, scoped credentials tied to agent lifecycle events
- Define minimum-scope authorisation for each agent based on its declared purpose — reject wholesale permission inheritance
- Instrument agent execution contexts to produce runtime telemetry that can be compared against authorised task scope
- Include agent identity decommissioning in deployment pipeline offboarding workflows
- Review existing PAM and IAM platforms for non-human identity features before acquiring additional tooling
- Add agent ownership and scope definition as gates in security architecture review processes for new deployments