Presented by Cisco
Enterprises are adding AI agents, applications, workloads, and machine identities far faster than they add employees. Many now plan for a non-human population several times larger than their human one, and identity architecture is what decides how far that growth goes.
Every AI agent needs a verifiable identity, a credential it cannot leak, and a narrow set of permissions before it touches a production system, and the identity and access management (IAM) platforms most enterprises run today weren’t built to issue any of those things to software.
What’s missing is an agentic equivalent to a human onboarding process, which is what gives an employer confidence in a new hire, says Matt Caulfield, VP of product, identity, at Cisco.
“People build trust through a process,” he says. “We know the same person, or the same company hired us, and that company ran a background check, ran an interview, verified our identity at onboarding. None of that exists for agents. We hire people over weeks or months. We hire agents in minutes.”
That question of trust comes back at every hand-off, from a person to an agent, from that agent to the next one it calls, and from the last in the chain to the applications and data it reaches. Resolving that question at machine speed takes four capabilities traditional IAM never had to provide: discovery of the agents already running in the environment, cryptographic credentials tied to hardware, authorization at the level of individual actions, and a continuous record of what every agent did.
Why identity became the control plane for AI agents
Security leaders securing their first serious agentic AI deployments consistently take the problem to their IAM team rather than endpoint or application owners. They need to know how to discover the agents already running, give those agents verifiable identities, and grant permissions narrow enough to prevent damage to core systems.
“That's because whether agents are running on your laptop or in the cloud or in a data center, or behind third-party services, they all need identity," Caulfield says. “That’s the only unifying principle across all of them. Identity is the one layer that reaches all of them.”
Network policy, observability, and threat detection all depend on that identity layer. Architecturally, that means identity is a prerequisite, instead of just another control among many others. Network segmentation, threat detection, and observability for agents all remain necessary, but each assumes the identity of the actor has already been established.
What traditional IAM gets wrong in the agentic era
IAM platforms carry the assumptions of the era that produced them. They authenticate humans who arrive with a password, a fingerprint, or a face scan, and they sort those humans into roles broad enough to cover a job function: admin, user, read-only, and so on. Those roles weren’t designed for agents, which leaves identity teams building the fundamentals from scratch.
“We need to issue a credential, and it’s usually cryptographic, tied to hardware so nobody can steal it,” Caulfield says. “Then we get to permissions. Saying an agent can access email leaves it free to move mail around or email the board of directors. Agents need just enough permission, just in time, for just long enough to complete the mission at hand.”
From access control to action control
Zero trust architectures define access in terms of users, devices, applications, and data sets. That level of granularity answers whether an agent may connect to GitHub, for example, but says nothing about whether it may force-push to a production branch at two in the morning.
“Zero trust was never really zero trust. It was trust in the identity systems,” Caulfield says. “We often say we need to evolve from access control to action control, and the only way to get there is to inspect every action, authorize it in real time before anything happens, and record all of it.”
The distinction appears in how a permission reads. Least privilege access groups permissions around applications and resources, giving engineering access to GitHub and the cloud console while finance gets the accounting system. Agents need those same systems to do useful work, so application-level access can give them all the permissions the human already has. The right way to handle it is action control.
“In other words, you have permission to merge a pull request in GitHub for the next five minutes, and that’s the only action you’re allowed to take,” Caulfield says. “You can’t read the whole repository or make changes to other repositories. This repository, this action, this window.”
Continuous verification requires a position in the path
One-time authentication has been losing ground for human users for years, and it collapses completely for agents whose actions can change every few minutes. Continuous verification starts by binding an agent’s identity cryptographically to a device, then opening a secure channel to whatever the agent works through.
“Getting in line between agents and resources, agents and other agents, and humans and agents is the only way to inspect every action as it happens,” Caulfield says. “That position gives you continuous verification of the identity, continuous policy enforcement, and a full audit log of everything the agent did.”
What to lock down now
Discovery comes first, since security teams can’t govern agents they don’t know are operating in the environment. Core applications come next, because anyone who can mint an API key or a personal access token can route an agent around governance entirely. And how employees authenticate deserves the same scrutiny.
“If humans in your organization authenticate with passwords, people will hand those passwords to their agents,” Caulfield says. “The agent then acts as the person, and the two become indistinguishable. Phishing resistant authentication gives employees nothing they can share.”
How Duo extends identity security to AI agents
Cisco’s Duo provides the identity layer alongside the company’s endpoint, network, and data security offerings. For people, it provides credentials designed to remain bound to the user or device, along with continuous verification of identity and activity. That reduces the risk of credentials being passed inadvertently to an agent or deliberately to an attacker.
For non-human identities, Duo delegates scoped permissions through OAuth, supports the authorization specifications MCP (Model Context Protocol) relies on today. It also treats agents as first-class identities in its directory. Cisco’s acquisition of Astrix extends that into discovery, showing customers the non-human identities in their environment and the accounts, permissions, and secrets those identities use.
“We need to almost rethink the past 30 years of security through the lens of agents,” Caulfield says. “How do we do identity security for agents? Network security, endpoint security, data security? Most enterprise security programs already have a strategy for each of those domains. They need another line underneath each one: how do we do that for agents?”
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
