Organizations are beginning to connect AI agents to the same administrative tools their engineers use.
The convenient approach is to let the agent operate through an existing human account, service account, SSH key, or automation credential.
But human access was designed around human judgment.
Consider a platform engineer who can restart services, modify configuration files, deploy containers, and inspect production logs. These permissions may be appropriate because the engineer understands the environment, recognizes unusual conditions, and can stop when an action becomes unsafe.
If an AI agent inherits those same credentials, it may also inherit the entire permission boundary.
A request to “restore the application” could lead the agent to restart the wrong service, alter an unrelated configuration, expose sensitive log data, or continue making changes after the original problem has changed.
Traditional access controls can confirm that the credential was valid and permitted to execute the command. They may not answer:
• Was this specific action appropriate for the agent?
• Was the target and scope fixed before approval?
• Did the action remain within an acceptable blast radius?
• Did the environment change between authorization and execution?
• Was the intended outcome independently verified?
• Can we distinguish the agent’s actions from the human credential owner’s actions?
Identity and access management remain essential, but access alone does not provide operational governance.
AI agents need identities and authority boundaries designed for machine execution—not borrowed human access with broad permissions.
That may require task-specific capabilities, resource-level policy, immutable execution scope, expiration, approval for consequential actions, and evidence of the resulting state.
The question is no longer only, “Can this identity run the command?”
It is also, “Should this agent perform this exact operation, on these resources, under these conditions, right now?”
How is your organization approaching this?
Are AI agents receiving dedicated identities and constrained permissions, or are they operating through credentials originally designed for people and conventional automation?