From Service Accounts to Agent Identities: Governing AI Access at Enterprise Scale
25 July 2026AI agents are beginning to act across enterprise applications, data platforms and external services rather than merely generate text. This changes identity and access management fundamentally. An agent must be identifiable as a distinct non-human actor, while the organisation must also preserve the identity of the user, process owner or approver who delegated authority to it.
This article presents a vendor-neutral architecture for agent identity, workload authentication, delegated authorisation, token exchange, policy enforcement, approval and audit. It explains why shared service accounts and borrowed user credentials are unsuitable, compares RBAC, ABAC, policy-based and capability-based security, and shows how permissions can be restricted by agent, user, task, tool, data classification, value, location, time and risk. It also provides enterprise examples, implementation guidance, decision criteria and a phased adoption roadmap.
