Traditional identity management systems were never built for AI agents, and because there is no 'leaver' event equivalent to an employee's departure, valid API keys, OAuth grants and service accounts are left behind—creating a structural governance gap. The security outlet The Hacker News detailed the issue in an analysis published on July 2, 2026 (The Hacker News ).
July 2, 2026 · Identity Governance
AI Agents Have No HR Record — And Your IGA Can't See Them
Identity governance was built for humans: a joiner, a mover, a leaver. Autonomous agents have no manager, no offboarding date, and no employment event — so permissions drift, credentials go stale, and "ghost agents" linger unmanaged.
0
HR events generated when an AI agent is spun up
1
Object IGA sees — a lone service account, hiding the real access
Dozens
Parallel instances per agent, each with its own credentials
The visibility gap, drawn to scale
IGA sees one static identity — but a single agent carries a whole stack of live access behind it.
1
What IGA sees (service account)
Many
API access · OAuth grants · stale credentials
Where the human lifecycle breaks for agents
The joiner-mover-leaver model has no equivalent event at any stage.
Create
Starts over-permissioned — no joiner event to govern it
→
Run
Scope expands at runtime via tool-calling / RAG — no mover event
→
Finish
Ghost agents & stale credentials linger — no leaver event to deprovision
Today's blind spots vs. the extensions agents need
Creation trigger
HR employment events
Config file · platform API · orchestration layer
Visible object
Static machine identity (account, API key, OAuth client)
Unique identifier, owner, business purpose
Runtime behavior
Invisible
Tracking of dynamic scope expansion
Lifecycle
Joiner-mover-leaver
Create / change / retire workflow + risk classification
Treat agents as first-class identities
Extend existing IGA to curb shadow AI and privilege creep
Agent-specific discovery and inventory across cloud environments
Apply least privilege plus continuous monitoring
Standardization advancing — Microsoft Entra Agent ID, MCP and SPIFFE/SPIRE integration at the OpenID Foundation
The industry aligns on the diagnosis, but detailed real-world credential-drift cases remain scarce — the debate is still early.
Continue reading The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in ✓ Signed in — this article isn’t included in your current plan.Unlocking the full article…