Our State of Authorization: AI Edition is now available Get it now »

Agentic AI and NHIs: Why authorization is a must-have

Non-human identities are rapidly evolving, Agentic AI being at top of mind. Authorization methods, like Zero Trust, are impartive now more than ever.

Whether you’re a seasoned expert or a beginner in the identity access and management (IAM) realm, you’ve most likely heard the conversation happening around non-human identities (NHIs).

NHIs are typically referring to identities used for machine-to-machine communication. For example: service accounts, API keys, tokens, certificates, and workloads, just to name a few.

NHIs are nothing new and have been around for over a decade. What is new, however, is the pace that they are evolving as well as a newer form of non-human identity: artificial intelligence (AI). Along with AI came agentic AI, a type of artificial intelligence that can make autonomous decisions on behalf of human users, such as making reservations or booking flights.

NHIs were already no stranger to acting autonomously, but now with the introduction of agentic AI, the scale at which that is happening is much larger than ever before. Additionally, while overarching system accounts were being accepted as identities in the past, it is now more desirable for each workload, process, and account to have its own identity. Those identities may be fleeting, existing for a mere seconds, but they still exist.

Authorization was already a necessary process for all types of cybersecurity processes. But, with the evolution of artificial intelligence and NHIs as a whole, authorization — specifically a Zero Trust strategy — is important now more than ever in securing data. With authorization, NHIs can be effectively managed, and because everything now has an identity, we can securely apply authorization to them.

Concerns of NHIs

NHIs operate autonomously, often bypassing traditional security controls designed for human identities. Without proper governance, they can expand attack surfaces, create operational blind spots, and introduce compliance risks.

Here’s a deeper look at the most pressing concerns:

  1. Overprivileged access: While users within the organization often give NHIs unique permissions (i.e. the duration of a token or context for which a job can be completed), they can ignore the principle of least privilege (POLP) creating holes within the infrastructure.
  2. Identity Sprawl: As of 2024, one report found that for every 1,000 human identities, there are 10,000 non-human identities. Much like role explosion, this can happen in the blink of an eye before organizations even realize it is a problem.
  3. Management and visibility: NHIs are typically not managed all from one place. It’s easy to lose track of them and identify whether they’re even non-human or human.

Many of these vulnerabilities can be enhanced with the deployment of authorization.

How authorization can help

1. Controlling Access

Authorization ensures that only the right data, systems, or processes are accessed by NHIs, preventing unauthorized interactions that could lead to security breaches. This is particularly important because NHIs often operate autonomously, meaning they must be explicitly restricted to prevent unintended actions.

  • Policy-driven authorization ensures NHIs can only interact with approved systems and datasets.
  • Continuous verification ensures NHIs are reevaluated before each access request, reducing exposure to unauthorized actions.

2. Limiting Overprovisioning with ABAC

NHIs often receive excessive permissions that go beyond their intended purpose.Attribute-based access control (ABAC) prevents privilege escalation by granting access based on predefined attributes rather than static roles.

  • Least privilege enforcement ensures NHIs only receive necessary access permissions based on contextual attributes.
  • Adaptive policies revoke excessive permissions dynamically, reducing exposure if an NHI is compromised.
  • Automated privilege reviews detect and adjust permissions based on real-time usage patterns.

3. Enabling Access Delegation

Many NHIs act on behalf of human users, requiring both the NHI’s identity and the user’s identity to be considered in authorization decisions. This is crucial for scenarios like agentic AI travel agents booking flights for human users or AI financial assistants executing transactions.

  • Delegated authorization models ensure NHIs inherit permissions only when acting on behalf of a verified user.
  • Identity binding links NHIs to specific human users, ensuring accountability.
  • Scoped delegation policies prevent NHIs from acting beyond their intended purpose, reducing unauthorized actions.

Staying ahead of the curve with authorization

With the evolution of AI happening so rapidly, it’s clear that managing NHIs are important. Don’t let your organization fall behind. Ready to take the next steps? Check out our State of Authorization: Playbook Edition to arm your organization with the defense of knowledge.

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About David Brossard

As Chief Technology Officer, David has experience leading the design and development of Salesforce’s identity offering including customer identity and access management (CIAM). He is a founding member of IDPro, a co-author of the OASIS XACML standard, and an expert on standard-based authorization as part of an overall IAM implementation.