A credential tells you who walked in. It says nothing about what they carried out.

Why Non-Human Identity Matters Now

Machine identity management has been a real discipline for a decade: service accounts, API keys, certificates, workload identities. Vendors have extended it to agents, and the pitch is reasonable: give every agent an identity, rotate its secrets, revoke it when it misbehaves. That is necessary. It is also a hedge against the wrong risk.

An identity program is a book of registered positions. It can only mark to market what somebody entered into the ledger. The agents that create tail risk are the ones running on laptops, in browser sessions and inside SaaS tenants that nobody registered. You cannot revoke a credential you never issued.

Signal Figure Source
Enterprises with agents in use that IT did not sanction 88% Ospiri published research
Added breach cost attributed to shadow AI +$670K Ospiri published research, consistent with IBM Cost of a Data Breach findings
Typical time to put governance in place 12-18 months Ospiri published research

Identity vs Authorization: Two Different Ledgers

Identity answers who is this agent. Authorization answers what may it touch, call and send right now. Conflating them is the category error behind most “agent identity” purchases.

Question NHI / identity control Runtime authorization
Who is acting? Yes: credential, certificate, agent ID Inherited from the session
Was this agent registered? Yes, by definition Not required
Which files did it read? No Yes
Which MCP server did it call? Only if routed through a gateway Yes, at the process boundary
Where did the output go? No Yes: destination host, bucket, app
Covers agents nobody registered? No Yes

Notice the third column’s last row. Identity controls are scoped by enrollment. Enforcement at the endpoint is scoped by behavior.

Anatomy of the Fully-Pinned Install

Take the best case for identity. A coding agent such as Claude Desktop, Cursor or Cline is installed with org-pinned credentials, single sign-on, and a managed settings file. Every box on the NHI checklist is green. The failure patterns still show up:

  1. The unsigned skill. A teammate pulls a skill or plugin off GitHub. The agent’s identity is unchanged; its capabilities are not.
  2. The unapproved MCP server. The agent is pointed at a local or remote MCP server nobody reviewed. Identity is intact; the tool surface just doubled.
  3. The personal bucket. The agent writes output to a personal cloud folder or an unmanaged SaaS workspace. The credential that did it is perfectly valid.
  4. The inherited session. The agent acts with the employee’s own access, so DLP sees a user, not an agent, and UEBA sees normal behavior at abnormal speed.
  5. The embedded agent. Microsoft 365 Copilot, Slack AI or Salesforce Einstein reasons over data under a platform identity that your NHI inventory never listed.

In every case the identity layer reports a healthy position while the exposure grows. That is what a hedge that doesn’t cover the underlying looks like.

The Authorization Gap Score

Quants price this as frequency times severity, adjusted by how much of the estate you can actually see.

Authorization Gap = (Unregistered Agent Share × Reachable Data Sensitivity) + (Unreviewed Capability Share × Egress Exposure)

Factor What you measure Where it comes from
Unregistered Agent Share Agents observed running vs agents in the identity registry Endpoint discovery vs NHI inventory
Reachable Data Sensitivity Sensitivity of paths, tables and mailboxes an agent can reach under inherited access Labels (Purview), DLP classification
Unreviewed Capability Share Skills, plugins and MCP servers in use vs on an approved list Skills-file and MCP scan
Egress Exposure Destinations the agent can write to outside managed tenants Network and process telemetry

The point is not the decimal. The point is that the first factor is invisible to a program that starts from the registry.

What Authorization Actually Requires

Authorization for agents is enforced where the action happens, not where the credential was issued.

Control point What it enforces Identity alone?
Process Which binaries can spawn an agent and its children No
Filesystem Which paths an agent may read or write; copy-on-write for the rest No
Network Which hosts and buckets an agent may reach Partly, via gateways
Capability Signed or approved skills and MCP servers only No
Identity Who the agent is, revocation, rotation Yes, and worth keeping

Keep the identity program. Treat it as the ledger and runtime enforcement as the risk desk. Sequencing matters too; we have argued elsewhere that identity-first is a trap when it delays visibility, and that identity and runtime enforcement answer different questions. Our agent firewall and agent governance pages lay out the enforcement side.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Diff observed agents on endpoints against the NHI registry Unregistered Agent Share, as a number 1-2 weeks
2 Inventory skills and MCP servers in use against an approved list Unreviewed Capability Share 1 week
3 Map reachable data and egress destinations for the top agents Reachable Data Sensitivity and Egress Exposure 2 weeks
4 Move the highest-gap agents into a sandbox with explicit allow rules Reversible default with an audit trail 2-4 weeks

The Bottom Line

Identity tells you who the agent is; authorization decides what it is allowed to do, and only one of them covers the agents nobody registered. Let’s step back: if your NHI program is the only agent control you can show an auditor, you are reporting on the book you entered, not the book you hold. If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, compute your Authorization Gap against your current registry, and scope a deployment. Expect a first readout within two weeks.