TRACK: BASICS

Agent identities explained

SHORT ANSWER

An agent identity is an account for the agent itself, linked to the person or team who answers for it. It lets an agent have narrow permissions, its own log entries and an off switch that does not disable anyone else.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

3 min read

When an AI agent needs to reach a system, the quickest route is to hand it something that already works: an API key, a service account or the session of the person who started it. Each of those makes the agent indistinguishable from something else. The key is shared with other software, the service account has permissions set for a different job, and the borrowed session carries everything the person can do.

What an agent identity adds

An agent identity is an account that belongs to the agent. It separates three things the shortcuts blur: the agent, the person or team responsible for it, and the platform it runs on. With its own identity an agent can be given permissions for its task only, appear under its own name in logs, and be switched off without affecting the person's access or the platform's other agents.

Three kinds of agent

Vendors describe the relationship between agent and person in different terms. NewCore names three kinds: agents acting on behalf of a person, agents with delegated authority, and autonomous agents, and treats each as a first-class identity. Microsoft Entra Agent ID creates agent identities from blueprints and gives each one owners and sponsors. Okta treats the agent as a principal in its own right, with delegation from the user it works for. Aembit's Blended Identity combines the agent's identity with that of the human operating it.

The distinction matters for permissions. An agent acting for one person should never be able to do more than that person can. An autonomous agent running a scheduled job has no person present at the moment it acts, so its permissions and its owner have to be set in advance.

What each agent identity should record

  • A named owner: a person or team who answers for the agent.
  • Its purpose, in one sentence.
  • What it can reach, and for how long.
  • The credentials it uses, and whether they are short-lived.
  • Where its actions are logged.

Agents nobody registered

Identities only help for agents that have them. Okta and Silverfort both describe discovering agents that were never registered: Okta surfaces unsanctioned agents and registers them in a central directory, and Silverfort finds sanctioned and rogue agents through read-only connections to Entra ID, Okta, AWS, Azure and GCP. The criterion on finding agents you did not register, on the AI agent security page, measures this.

How agents relate to other non-human identities

OWASP's Non-Human Identities Top 10 covers service accounts, keys and tokens, and AI agents inherit every item on it. What sets agents apart is that they choose their own next step. That is why per-call checks, covered in the AI agents and MCP track, matter more for an agent than for a script that always does the same thing.

See AI agent security platforms compared

Related pages

Sources

NEXT LESSON

The OWASP Non-Human Identities Top 10, in plain terms

2 min read