Identity lifecycle management (ILM) was architected around human principals with employment records, managers, and departure dates. AI agents have none of these, creating structural blind spots in traditional IGA tools. This article explores how the joiner-mover-leaver model breaks for AI agents, which are created via deployment pipelines, lack authoritative HR sources, and exhibit dynamic, runtime-expanding access scopes. Key gaps include no governed entry point, no entitlement recalculation for scope changes, no access review signals, and no deprovisioning triggers. The article outlines risks such as over-permissioned defaults, ungoverned credentials, and stale access paths. It proposes extending ILM with automated discovery across deployment surfaces, attribute modeling for agent behavior, and policy-driven provisioning scoped to agent function.
Companies: Workday, SAP, ServiceNow, Microsoft, Amazon Web Services, LangChain, AutoGen
Products: Workday, SAP SuccessFactors, ServiceNow HR, Active Directory, Azure AD, Entra ID, AWS IAM, AWS Bedrock Agents, LangChain, AutoGen
Original source: thehackernews.com