AI Governance Library

Agentic Identity and Access Management

Traditional IAM comprises the identity providers, directories, federation protocols, and access-control systems built for human users and relatively static machine identities. These systems assume long-lived principals, coarse roles, and “authenticate once, trust for the session”
Agentic Identity and Access Management

⚡ Quick Summary

Developed by the Coalition for Secure AI (CoSAI) under OASIS, Agentic Identity and Access Management establishes an interoperable architectural framework for governing autonomous AI agents within enterprise environments. As autonomous agents make operational decisions, orchestrate multi-step workflows, and interface with critical APIs, conventional IAM paradigms—grounded in static service accounts, long-lived credentials, and session-wide trust—fail to contain emerging threat surfaces. This publication outlines nine core imperatives to treat agents as verifiable, first-class identities, decoupling actor identity from authorization scopes while eliminating standing privileges through workload attestation and zero-trust controls.

🧩 What's Covered

The framework delivers a structured technical blueprint for extending existing enterprise IAM platforms (such as IdPs, PKI, OAuth/OIDC servers, and policy engines) to support autonomous non-human actors without standing up redundant identity silos. Core topics analyzed include:

  • Failure Modes and Threat Themes: Practical breakdowns of agent-specific risks, including over-privileged execution, loss of actor clarity, unverified model binary swaps, indirect prompt injection exploits, cross-tenant propagation, and multi-agent proxy chaining.
  • Capability–Risk Classification: A governance matrix correlating agent capability tiers (mapped across an L0–L5 autonomy ladder) with resource sensitivity to mandate proportionate controls—from basic short-lived tokens to hardware-backed attestation and human-in-the-loop gates.
  • Authentication and Cryptographic Attestation: Methods for establishing ephemeral agent identities via SPIFFE SVIDs, Decentralized Identifiers (DIDs), signed model manifests, and Trusted Execution Environment (TEE) hardware enclave quotes (e.g., Intel TDX, AMD SEV-SNP).
  • Delegation and On-Behalf-Of (OBO) Workflows: Preserving full authorization lineage across multi-hop agent chains using OAuth 2.0 Token Exchange (RFC 8693) and Rich Authorization Requests (RFC 9396) with narrowing scopes and cascading revocation.
  • Gateway Enforcement and Lifecycle Governance: Configuring MCP endpoints and API gateways to operate fail-closed, evaluate ABAC/PBAC policies in near-real time, enforce tenant isolation, and record immutable, auditable telemetry mapped to schemas like OCSF and CEF.
  • End-to-End Reference Scenario: A practical walkthrough of an automated invoice-processing agent detailing credential injection, step-up approvals, anomaly detection, and forensic queries.

💡 Why it matters?

Enterprise adoption of autonomous agent workflows exposes acute vulnerabilities when systems rely on shared, static credentials or broad delegated rights. By formalizing Agentic IAM, organizations establish verifiable cryptographic boundaries and auditable lineage across distributed agent actions. The framework enables security teams to enforce Zero Standing Privilege (ZSP) and granular attribute-based access controls at every runtime hop. This ensures organizations can provably isolate compromised agents, prevent lateral privilege escalation, and reconstruct operational lineage on demand for regulatory compliance.

❓ What's Missing

The document explicitly restricts its scope to identity, authentication, and access control boundaries. It deliberately omits model training safeguards, content safety filters, hallucination defenses, and broader AI governance frameworks. While it highlights high-level integrations with standards like RFC 8693, RFC 9396, and MCP security, it leaves underlying model-level guardrail evaluation, automated prompt filtering, and formal schema extensions within emerging logging frameworks (such as OCSF) to external workstreams.

👥 Best For

Chief Information Security Officers (CISOs), enterprise IAM architects, cloud platform engineers, Site Reliability Engineers (SREs), and AI security compliance officers tasked with designing, deploying, and auditing secure access architectures for autonomous agents.

📄 Source Details

  • Title: Agentic Identity and Access Management
  • Author: OASIS Coalition for Secure AI (CoSAI) — Workstream 4: Secure Design Patterns for Agentic Systems
  • Publication Date: March 20, 2026 (Version 1.0)
  • Format: Technical Framework / Non-Standards Track Work Product (18 pages)
  • Reference Standards: NIST SP 800-63, NIST AI 100, RFC 8693, RFC 9396, RFC 7009

📝 Thanks to

Workstream leads Sarah Novotny, Ian Molloy (IBM), Raghu Yeluri (Intel), and Alex Polyakov (Adversa AI); editors Asmae Mhassni (Intel) and Zeal Somani (Evinova); Technical Steering Committee co-chairs Akila Srinivasan (Anthropic) and J.R. Rao (IBM); along with contributing experts from Amazon, Cisco, Dell, EQTY Lab, Google, Meta, Palo Alto Networks, Paypal, ProCap360, Red Hat, and ServiceNow.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.