Offered by JumpCloud
A sensible framework for securing each id within the trendy workforce, human or not.
Your group already has a rigorous course of for governing human identities. New workers undergo onboarding. They get a task, a set of entitlements, and a named supervisor accountable for his or her entry. Once they go away, their credentials are revoked and entry is terminated. It’s a well-known IT course of: each workforce id that may entry your methods must be identified, scoped, and accountable from the second they enter your world, to the second they’re off-boarded.
AI brokers at the moment are working inside those self same methods. They entry Salesforce, create tickets in Jira, provision infrastructure, course of monetary transactions, and talk on behalf of your groups. In each significant sense they’re members of your workforce, besides that in most organizations they have been by no means onboarded, don’t have any named proprietor, and don’t have any offboarding course of when their goal expires.
JumpCloud’s Q3 2026 analysis discovered that non-human identities now outnumber human customers in 83% of organizations, and solely 21% have applied governance controls particularly for them. The framework beneath is designed to shut that hole.
Stage 1: Uncover each agent working in your surroundings
Governance begins with an correct stock, and most organizations are working with an incomplete one. AI brokers are being deployed by product groups, operations leaders, and particular person contributors who’ve each the instruments and the motivation to maneuver quick. IT inherits the governance duty after the very fact, typically with out realizing the total scope of what has been deployed.
Shadow AI is the sensible consequence: brokers working throughout manufacturing environments with no formal report, no outlined proprietor, and no systematic technique to cease them if one thing goes fallacious. Discovering your agent inhabitants is an ongoing observe, not a one-time audit. Construct a listing throughout each surroundings the place brokers might be operating: cloud platforms, managed units, SaaS integrations, and on-premise methods. For every agent, doc what it may entry, what workflows it influences, and what triggers its actions. That stock is the inspiration every little thing else on this framework is determined by.
Stage 2: Register each agent as a proper id with a named proprietor
Each agent that operates in your surroundings ought to exist as a proper id in your listing, with the identical fundamental attributes you assign to any worker: an outlined goal, a scope of approved motion, and a named human proprietor who’s accountable for its habits.
That is the architectural resolution that separates organizations that may govern their brokers from those who can’t. Brokers registered as correct identities might be assigned entitlements, subjected to conditional entry insurance policies, and included in entry critiques. Brokers that exist solely as service account workarounds or API keys in surroundings variables are ungovernable by any systematic means.
Registration can be the mechanism for addressing Zombie Brokers: brokers that outlived their unique goal however stored operating, stored accessing methods, and stored accumulating permissions. When each agent has a named proprietor answerable for its renewal, brokers with out energetic possession naturally lose their entry when that possession lapses. The offboarding occurs as a consequence of course of slightly than as a reactive cleanup after one thing breaks.
Stage 3: Handle agent entry with least privilege and 0 standing credentials
Registered brokers want entry to do their jobs. The governing precept for that entry is least privilege: every agent ought to have entitlements scoped exactly to what its outlined goal requires, with entry that’s time-bounded wherever doable and revocable instantly if the agent’s habits modifications.
Standing credentials in surroundings variables are a persistent legal responsibility. Static API keys that by no means rotate are a persistent legal responsibility. In observe, managing agent entry securely means issuing just-in-time credentials for privileged operations, constructing approval workflows that require human sign-off earlier than brokers attain delicate methods, and sustaining emergency shutdown mechanisms that work on the velocity the state of affairs requires.
For brokers that want entry to privileged internet purposes, SSH servers, or databases, credential shielding is an extra requirement: the agent ought to have the ability to full its activity with out the underlying credentials ever being uncovered to the mannequin operating it. Each privileged session ought to be recorded and obtainable for audit.
Stage 4: Govern agent habits constantly, not simply at deployment
The primary three levels set up the controls. Governance is what retains them present. It’s the ongoing observe of verifying that what brokers are literally doing matches what they’re approved to do, and course-correcting when these diverge.
Each agent motion ought to be logged. Entry critiques ought to occur on a daily cadence, evaluating whether or not every agent’s entitlements stay applicable for its present goal. When an agent’s habits deviates from its outlined scope, the anomaly ought to be detectable earlier than it turns into an incident. When an agent’s goal ends, entry revocation ought to be a procedural step, not a reactive measure triggered by one thing going fallacious.
Governance additionally means sustaining the audit path wanted to reply accountability questions: what did this agent entry, what actions did it take, who approved it, and what was the end result? Organizations that can’t reconstruct that chain for any given agent will not be governing their brokers in any significant sense. They’ve deployed them and hoped for the most effective.
The muse beneath all 4 levels
Every stage of this framework turns into considerably more durable to execute when the underlying IT surroundings is fragmented. Id, entry, gadget administration, and safety controls unfold throughout disconnected methods create the gaps the place agent governance falls via, and organizations find yourself making use of totally different insurance policies somewhere else slightly than constant governance in all places.
JumpCloud’s analysis discovered that organizations working in totally unified IT environments are 5 instances extra prone to deploy brokers in business-critical workflows than these operating fragmented stacks. Whether or not the management layer is coherent sufficient to use constant insurance policies throughout people, units, and brokers concurrently is what determines whether or not governance scales with AI adoption or lags behind it.
That is the core premise of Agentic IAM: that governing people, units, and brokers via a single coherent management layer is what makes the framework above executable at scale slightly than aspirational.
Securing each id, human or not, is the operational basis that makes AI secure to scale. Organizations that construct it now won’t simply scale back danger. They are going to increase AI into extra workflows, transfer sooner, and do it with the arrogance that comes from realizing each id of their surroundings is understood, ruled, and accountable.
JumpCloud’s Q3 2026 IT Developments Analysis report (n=800 IT leaders, US + UK) is obtainable here. The Agentic IAM lifecycle framework referenced on this article was developed by JumpCloud and is obtainable here.
Greg Keller is CTO and Co-founder at JumpCloud.
Sponsored articles are content material produced by an organization that’s both paying for the submit or has a enterprise relationship with VentureBeat, they usually’re all the time clearly marked. For extra data, contact sales@venturebeat.com.