Sharing credentials does not stop an enterprise from enforcing permissions, but it makes it much harder to tell which agent actually took an action.
In the August wave of VB Pulse’s Agentic Security and Identity tracker, 54 of 137 respondents said their security program enforces scoped permissions at runtime. Thirty-seven of those organizations also have agents in production. Among those 37, only 15 said every agent has its own scoped, managed identity; the other 22 said some or most of their agents still run on shared credentials.
Across the 68 respondents running agents in production, 42 said some or most of those agents share credentials. Sharing means the agent runs on an API key other agents also use, or on a credential borrowed from a human employee or a service account. Only 26 of the 68 said they give every agent its own scoped, managed identity.
A $1 billion acquisition, little use of dedicated identity tools
Agent identity is drawing serious investment from security vendors: Cyera completed its $1 billion acquisition of Oasis Security on September 3, Cisco closed its acquisition of Astrix Security on June 29, and Okta made Agent SSO generally available on August 24, giving supported agents first-class identities in its directory at no additional cost.
Of the 108 respondents who named platforms they use to secure agents, two named Microsoft Entra Agent ID, one named Okta, and two named a non-human identity platform. By comparison, 53 named OpenAI, and 48 each named Microsoft Azure and Google Cloud.
Enforcement without identity
Andrew Obadiaru, CISO at Cobalt, spent years as a KPMG auditor before moving into security leadership. He looks at agent identity through an audit lens: every access decision needs to be traceable and bounded.
"It's easier to extend existing permission controls around what an agent can access or do than it is to redesign the identity model so that every agent has its own unique, scoped and lifecycle-managed identity," Obadiaru told VentureBeat. "What concerns me is that permissions without strong identity eventually create an accountability problem. If several agents are operating through a shared service account, API key or user-delegated credential, you may be able to restrict what that credential can do, but it becomes much harder to answer basic security questions. Which agent actually took the action? Who authorized it? Can I revoke that agent without disrupting everything else using the same identity?"
That maps directly to the 22 respondents who enforce scoped permissions while some or most of their agents still share credentials.
The Medicare breach shows why containment matters
An OpenAI agent accessed Australia’s Medicare Statistics Reporting Service on June 18 after the portal blocked its requests, reaching public and nonpublic files and writing files to the server. OpenAI discovered the activity 54 days later and notified Australia on September 10 — 84 days after the intrusion.
Per-agent identity would not have prevented that breach; the agent was accessing an external site, not crossing an internal permission boundary. But the case shows the separate role of containment: limiting how far an off-task agent can go when other controls fail.
That control remains uncommon in the August Pulse. Only 12 of 137 respondents said high-risk agents run in isolation with a bounded blast radius. At the same time, 64 of the 109 organizations running agents in production or in a pilot reported an agent-caused security incident or near-miss in the past 12 months. The survey does not establish a causal relationship between the two; it shows substantial incident exposure alongside limited use of isolation.
The August data points to two separate gaps: some enterprises are enforcing permissions while agents still share credentials, and few respondents isolate high-risk agents when other controls fail.
Methodology. VentureBeat Pulse fielded the Agentic Security and Identity tracker in August 2026 as part of an ongoing monthly survey series. The qualified sample is 137 respondents at organizations with 100 or more employees, corrected from an initial 141 after four respondents were removed for internally inconsistent answers. Each wave is an independent, self-selected sample. June qualified 107 respondents, July 116, August 137. The data describes what respondents reported and should not be read as representative of all enterprises.
