AI & Identity
Identity for AI Agents: Securing Autonomous Systems with Least Privilege
AI agents call APIs, read data and take actions on behalf of users. Treating them as first-class identities — scoped, auditable and revocable — is the foundation of safe agentic AI.
Elane Solutions2 min read
The first wave of generative AI answered questions. The next wave acts: AI agents read records, call internal APIs, draft and send communications, and trigger workflows. Every one of those actions is an access decision. Yet many agent prototypes run on a single shared API key with broad permissions — the exact anti-pattern identity teams have spent a decade removing from service accounts.
Agents are identities, not features
An AI agent should be registered, authenticated and governed like any other workload identity. That means a distinct identity per agent (and often per deployment), credentials issued by your identity provider rather than embedded secrets, and a clear owner accountable for what the agent is allowed to do.
Act on behalf of the user — with the user's permissions
When an agent works for a specific person, it should never see more than that person could. OAuth 2.0 token exchange and on-behalf-of flows let an agent obtain a narrowly scoped, short-lived token that carries the user's identity and consent. Retrieval-augmented generation must apply the same rule: documents are filtered by the caller's entitlements before they ever reach the model.
- Issue short-lived, audience-restricted tokens for each tool the agent can call
- Use fine-grained authorisation (RBAC, ABAC or relationship-based) at the API, not in the prompt
- Apply permission-aware retrieval so the model only sees data the user is entitled to
- Require step-up approval from a human for high-impact or irreversible actions
Never let the prompt be the policy
Instructions such as "do not access payroll data" in a system prompt are not access control. Prompt injection, tool misuse and model error will eventually bypass them. Authorisation must be enforced by systems the model cannot talk its way past: the identity provider, API gateway and policy engine.
Make every action traceable
Log which agent acted, on whose behalf, with which token, against which resource, and why. Correlating agent decisions with identity and API logs turns an opaque AI system into one your security team can investigate and your auditors can review.
Plan for revocation
Agents will misbehave, models will be replaced and integrations will be retired. Being able to disable a single agent identity instantly — without rotating a shared key used by everything else — is what separates a manageable incident from a serious one.
Agentic AI does not need a new security model. It needs the identity disciplines we already know, applied rigorously to a new kind of actor.