Skip to main content
All insights

AI & Identity

Identity for AI Agents: Securing Autonomous Systems with Least Privilege

AI agents call APIs, read data and take actions on behalf of users. Treating them as first-class identities — scoped, auditable and revocable — is the foundation of safe agentic AI.

Elane Solutions2 min read

The first wave of generative AI answered questions. The next wave acts: AI agents read records, call internal APIs, draft and send communications, and trigger workflows. Every one of those actions is an access decision. Yet many agent prototypes run on a single shared API key with broad permissions — the exact anti-pattern identity teams have spent a decade removing from service accounts.

Agents are identities, not features

An AI agent should be registered, authenticated and governed like any other workload identity. That means a distinct identity per agent (and often per deployment), credentials issued by your identity provider rather than embedded secrets, and a clear owner accountable for what the agent is allowed to do.

Act on behalf of the user — with the user's permissions

When an agent works for a specific person, it should never see more than that person could. OAuth 2.0 token exchange and on-behalf-of flows let an agent obtain a narrowly scoped, short-lived token that carries the user's identity and consent. Retrieval-augmented generation must apply the same rule: documents are filtered by the caller's entitlements before they ever reach the model.

  • Issue short-lived, audience-restricted tokens for each tool the agent can call
  • Use fine-grained authorisation (RBAC, ABAC or relationship-based) at the API, not in the prompt
  • Apply permission-aware retrieval so the model only sees data the user is entitled to
  • Require step-up approval from a human for high-impact or irreversible actions

Never let the prompt be the policy

Instructions such as "do not access payroll data" in a system prompt are not access control. Prompt injection, tool misuse and model error will eventually bypass them. Authorisation must be enforced by systems the model cannot talk its way past: the identity provider, API gateway and policy engine.

Make every action traceable

Log which agent acted, on whose behalf, with which token, against which resource, and why. Correlating agent decisions with identity and API logs turns an opaque AI system into one your security team can investigate and your auditors can review.

Plan for revocation

Agents will misbehave, models will be replaced and integrations will be retired. Being able to disable a single agent identity instantly — without rotating a shared key used by everything else — is what separates a manageable incident from a serious one.

Agentic AI does not need a new security model. It needs the identity disciplines we already know, applied rigorously to a new kind of actor.

  • Engineering Leadership2 min read

    How to Scale Engineering Without Expanding Headcount

    Hiring senior engineers is slow and expensive. Here is how engineering leaders are adding delivery capacity while keeping architecture and accountability close to the business.

  • Cloud & Security2 min read

    Building a Secure Azure Platform for FinTech

    Landing zones, identity, network isolation and auditability: the foundations a FinTech needs in Azure before the first production workload goes live.

Discuss this with our experts

If this topic is relevant to your team, we're happy to share how we'd approach it in your environment.