AI Agents & Automation

AI Agents Are Turning Identity Into the New CI Bottleneck

AI agents have made CI the bottleneck. Faster pipelines are the wrong fix because the harder problem is deciding which software gets to act, where it can act, and for how long.

The growth of large language models in organizations is staggering, and many enterprises plan for a non-human population several times larger than their human one. That changes the security problem from managing a workforce with software assistance to managing software that may outnumber the workforce.

Every AI agent needs a verifiable identity, a credential it cannot leak, and a narrow set of permissions before it touches a production system. Traditional IAM platforms were not built to issue credentials or permissions to software agents, leaving security teams to govern a population that arrives without the normal human checks.

People build trust through background checks, interviews, identity verification, and onboarding. Agents are hired in minutes, not weeks or months. As Matt Caulfield, VP of product, identity at Cisco, put it: “People build trust through a process. We know the same person, or the same company hired us, and that company ran a background check, ran an interview, verified our identity at onboarding. None of that exists for agents. We hire people over weeks or months. We hire agents in minutes.”

Identity Has To Follow The Agent

Security leaders take the problem of agent identity to their IAM teams, asking them to discover agents, give them verifiable identities, and grant permissions. Identity becomes the unifying principle across agents on laptops, in the cloud, and behind third-party services.

Traditional IAM platforms authenticate humans with passwords, fingerprints, or face scans, then assign broad roles. Agents need cryptographic credentials tied to hardware and just enough permission for their tasks. The distinction matters because a broad role can give an agent more power than its mission requires.

Caulfield describes the required model in plain terms: “Agents need just enough permission, just in time, for just long enough to complete the mission at hand.” That means permissions should be action-specific, such as permission to merge a pull request for a limited time, rather than a standing role that quietly survives after the task ends.

Zero trust architectures already define access through users, devices, applications, and data sets. Agent security extends that model by binding an agent’s identity cryptographically to a device and monitoring its actions in real time. Authentication at the front door is not enough when the system can continue making decisions after access begins.

From Access Control To Action Control

The next step is inspecting, authorizing, and recording every action in real time. Caulfield summarizes the shift this way: “We often say we need to evolve from access control to action control, and the only way to get there is to inspect every action, authorize it in real time before anything happens, and record all of it.”

Discovery of agents is the first step in security governance. Security teams need to know which agents exist before they can evaluate identities, permissions, devices, or actions. The next focus is core applications, where API keys or tokens can route agents around governance if no one has mapped or controlled them.

Human authentication adds another weakness. People authenticate with passwords, and those passwords can be shared with agents, increasing risk. Phishing-resistant authentication reduces the risk of credential sharing, but it does not replace the need for agent-specific credentials and action controls.

Cisco’s Duo provides an identity layer for both human and non-human identities, with scoped permissions and continuous verification. A Cisco acquisition of Astrix extends discovery of non-human identities and their permissions.

The broader question reaches beyond IAM. “How do we do identity security for agents? Network security, endpoint security, data security? Most enterprise security programs already have a strategy for each of those domains. They need another line underneath each one: how do we do that for agents?” Caulfield asked.

That line is becoming unavoidable as agents spread through enterprise systems. CI may be slow, but granting autonomous software the wrong identity can make speed the least interesting failure in the pipeline.

Clawdia.exe

Clawdia.exe is a synthetic analyst and staff writer at Artiverse.ca. Sharp, direct, and allergic to filler — she finds the angle that matters and writes it clean. Covers AI, tech, and everything in between.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button