A credential tells you who walked in. It says nothing about what they carried out.
Why Non-Human Identity Matters Now
Machine identity management has been a real discipline for a decade: service accounts, API keys, certificates, workload identities. Vendors have extended it to agents, and the pitch is reasonable: give every agent an identity, rotate its secrets, revoke it when it misbehaves. That is necessary. It is also a hedge against the wrong risk.
An identity program is a book of registered positions. It can only mark to market what somebody entered into the ledger. The agents that create tail risk are the ones running on laptops, in browser sessions and inside SaaS tenants that nobody registered. You cannot revoke a credential you never issued.
| Signal | Figure | Source |
|---|---|---|
| Enterprises with agents in use that IT did not sanction | 88% | Ospiri published research |
| Added breach cost attributed to shadow AI | +$670K | Ospiri published research, consistent with IBM Cost of a Data Breach findings |
| Typical time to put governance in place | 12-18 months | Ospiri published research |
Identity vs Authorization: Two Different Ledgers
Identity answers who is this agent. Authorization answers what may it touch, call and send right now. Conflating them is the category error behind most “agent identity” purchases.
| Question | NHI / identity control | Runtime authorization |
|---|---|---|
| Who is acting? | Yes: credential, certificate, agent ID | Inherited from the session |
| Was this agent registered? | Yes, by definition | Not required |
| Which files did it read? | No | Yes |
| Which MCP server did it call? | Only if routed through a gateway | Yes, at the process boundary |
| Where did the output go? | No | Yes: destination host, bucket, app |
| Covers agents nobody registered? | No | Yes |
Notice the third column’s last row. Identity controls are scoped by enrollment. Enforcement at the endpoint is scoped by behavior.
Anatomy of the Fully-Pinned Install
Take the best case for identity. A coding agent such as Claude Desktop, Cursor or Cline is installed with org-pinned credentials, single sign-on, and a managed settings file. Every box on the NHI checklist is green. The failure patterns still show up:
- The unsigned skill. A teammate pulls a skill or plugin off GitHub. The agent’s identity is unchanged; its capabilities are not.
- The unapproved MCP server. The agent is pointed at a local or remote MCP server nobody reviewed. Identity is intact; the tool surface just doubled.
- The personal bucket. The agent writes output to a personal cloud folder or an unmanaged SaaS workspace. The credential that did it is perfectly valid.
- The inherited session. The agent acts with the employee’s own access, so DLP sees a user, not an agent, and UEBA sees normal behavior at abnormal speed.
- The embedded agent. Microsoft 365 Copilot, Slack AI or Salesforce Einstein reasons over data under a platform identity that your NHI inventory never listed.
In every case the identity layer reports a healthy position while the exposure grows. That is what a hedge that doesn’t cover the underlying looks like.
The Authorization Gap Score
Quants price this as frequency times severity, adjusted by how much of the estate you can actually see.
Authorization Gap = (Unregistered Agent Share × Reachable Data Sensitivity) + (Unreviewed Capability Share × Egress Exposure)
| Factor | What you measure | Where it comes from |
|---|---|---|
| Unregistered Agent Share | Agents observed running vs agents in the identity registry | Endpoint discovery vs NHI inventory |
| Reachable Data Sensitivity | Sensitivity of paths, tables and mailboxes an agent can reach under inherited access | Labels (Purview), DLP classification |
| Unreviewed Capability Share | Skills, plugins and MCP servers in use vs on an approved list | Skills-file and MCP scan |
| Egress Exposure | Destinations the agent can write to outside managed tenants | Network and process telemetry |
The point is not the decimal. The point is that the first factor is invisible to a program that starts from the registry.
What Authorization Actually Requires
Authorization for agents is enforced where the action happens, not where the credential was issued.
| Control point | What it enforces | Identity alone? |
|---|---|---|
| Process | Which binaries can spawn an agent and its children | No |
| Filesystem | Which paths an agent may read or write; copy-on-write for the rest | No |
| Network | Which hosts and buckets an agent may reach | Partly, via gateways |
| Capability | Signed or approved skills and MCP servers only | No |
| Identity | Who the agent is, revocation, rotation | Yes, and worth keeping |
Keep the identity program. Treat it as the ledger and runtime enforcement as the risk desk. Sequencing matters too; we have argued elsewhere that identity-first is a trap when it delays visibility, and that identity and runtime enforcement answer different questions. Our agent firewall and agent governance pages lay out the enforcement side.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Diff observed agents on endpoints against the NHI registry | Unregistered Agent Share, as a number | 1-2 weeks |
| 2 | Inventory skills and MCP servers in use against an approved list | Unreviewed Capability Share | 1 week |
| 3 | Map reachable data and egress destinations for the top agents | Reachable Data Sensitivity and Egress Exposure | 2 weeks |
| 4 | Move the highest-gap agents into a sandbox with explicit allow rules | Reversible default with an audit trail | 2-4 weeks |
The Bottom Line
Identity tells you who the agent is; authorization decides what it is allowed to do, and only one of them covers the agents nobody registered. Let’s step back: if your NHI program is the only agent control you can show an auditor, you are reporting on the book you entered, not the book you hold. If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, compute your Authorization Gap against your current registry, and scope a deployment. Expect a first readout within two weeks.