Home/Answers/What to require of an AI agent management platform if you own IAM
Answer

What to require of an AI agent management platform if you own IAM

Agent identity is a real product category now. Here is what to require of an AI agent management platform when you own enterprise IAM.

An agent identity is a service account that argues back

Your team already runs non-human identity: service accounts, workload identities, machine credentials. An agent looks like one of those until you watch it work. It picks its own next call, it acts for a different person on each run, and the sequence it produces was generated a second ago rather than written into a job definition. Okta's own 2026 research, published alongside its agent product, found 91% of organisations already using AI agents against 10% with a developed strategy for managing non-human identities. That is a vendor with a commercial interest in the gap being wide, so read the numbers as marketing research. The direction still matches what turns up in evaluations. The agents arrived before the identity model did.

The category has two halves, and vendors rarely say which one they are

One half lives in the directory. Okta for AI Agents, generally available since 30 April 2026, discovers agents, manages their access and runs lifecycle governance over them. Microsoft Entra Agent ID gives an agent an account in Entra ID, and since May 2026 Copilot Studio creates one automatically for every new agent it builds. Both put agents under the machinery you already run for people. The other half is what happens in the second the agent tries to do something. Does anything read the actual call with its actual arguments and decide? A directory record cannot answer that, because by the time the agent reaches for a tool the directory has already said yes.

What to require, roughly in the order it gets skipped

Every item here is testable in a demo console. Rank them yourself, but be honest about which ones your current stack would fail today.

  • A distinct identity per agent, owned by a named person who can revoke it, with a defined lifecycle rather than an inherited service account.
  • Authority computed as an intersection: what the agent version binds, and what the person it acts for is entitled to. A vendor that computes a union has built an escalation path.
  • A decision at action time, on the resolved arguments, rather than one decision taken when a token was issued.
  • Behaviour you can name for the case where the deciding component is unavailable. An action that changes something should stop or go to a person, never proceed on a shrug.
  • A record that names who vouched for the person behind the run, and says whether that identity was verified or merely asserted by a calling application.
  • Least privilege you can test by trying to break it. OWASP's Top 10 for Agentic Applications 2026 lists Identity and Privilege Abuse as ASI03, and Excessive Agency is LLM06 in the 2025 LLM list. Both are testable, so test them.
  • Revocation that reaches work already in flight, so removing a person's access stops the agents acting for that person.

A demo script that separates the two halves

Ask for a live console rather than slides, and run these five in order. The answers tell you which half of the category you are looking at inside about twenty minutes.

  • Create an agent. Show the identity it received and who owns it. Ask who can revoke that identity and how quickly revocation bites.
  • Bind a tool the agent should never use, then ask the agent to use it. You want a refusal you can point at, plus a record of the attempt.
  • Run the same agent and the same prompt for a person with narrow entitlements, then for an administrator. The result has to differ. If it does not, authority is being read from the agent rather than from the person.
  • Remove the person's access halfway through a run. Watch what happens to the work already in flight.
  • Read the record afterwards. Ask what it says about the reason the model gave for acting. If that reason is presented as fact, remember the model wrote it, and under a prompt injection an attacker wrote it.

How Difinity.ai binds an agent's authority

Difinity treats this as an architecture question rather than a policy document. An agent is a named assistant with a stable identity, and it carries no configuration of its own. Instructions, model, tool bindings and run limits belong to an immutable agent version, which is the unit that gets reviewed and published. Authority is the intersection of three things: what the version binds, what the caller is entitled to, and what the use case permits. It is never a union, so an agent cannot end up with more reach than the person behind it. A version binds at most 32 tools, each one a deliberate choice. The agent holds no credential and cannot reach a system itself: every action it proposes leaves through the tool gateway, which holds the credential, applies the rules the organisation set, then decides and acts. That gateway is not reachable from the internet, and no customer calls it. Anything effectful is read by a judge before it runs. Where a tool server acts under its own identity rather than the person's, Hub marks it as such, because that is exactly the escalation an IAM reviewer is hunting for.

When this answer changes

This page has the shortest shelf life in the cluster. Okta's agent product reached general availability on 30 April 2026, and on 30 July 2026 Okta announced an agreement to acquire Permiso Security for approximately USD 200 million, so the vendor names here may not survive the year in their current form. Microsoft is still migrating agents created on app-registration identities across to Entra Agent ID, with no completion date published. None of the vendor capabilities described here were tested in a live console for this page: they are the vendors' own product descriptions. Re-check before you shortlist, and re-check again before you sign.

Frequently asked questions

Is there one best AI agent management platform for enterprise IAM?

No. Directory vendors such as Okta and Microsoft give an agent an identity, an owner and a lifecycle. A runtime enforcement platform decides what a particular action may do at the moment it is attempted. Work out which half a vendor covers before you compare feature lists, because the two rarely overlap.

How is an AI agent identity different from a service account?

A service account has a fixed job and fixed credentials. An agent chooses its own next call, acts for a different person on each run, and can be talked into something by content it reads mid-run. Its identity has to carry the person it is acting for as well as itself, or entitlements stop meaning anything.

Should an AI agent hold its own credentials?

It should hold none. In Difinity the agent cannot reach a system directly. It proposes the action. The tool gateway holds the credential, then decides and acts. Provider keys and connector credentials are write-only: they can be replaced or destroyed, and no screen shows one.

What evidence should an IAM reviewer expect after an agent run?

The identity that acted, who vouched for the person behind it and whether that identity was verified, each proposed action with its arguments, the decision taken on it, any approval asked for and answered, and the outcome. In Difinity that record is the run trail, and it is append-only.

Sources and further reading

Have an agent that needs production authority?