Assume Misbehavior: Agentic Identity is the Latest Thing You Need to Govern

agentic identity portnox

Schedule a Portnox Cloud demo today.

Contents

A few months into running a SOC for an engineering-led company that, respectfully, did whatever the hell it wanted, I gave up trying to answer “what’s out there.” I couldn’t answer it. Asset inventory was held together by tribal knowledge and optimism, and every time I thought I had a clean picture, someone spun up a new service over a long weekend and forgot to mention it. So I stopped asking what existed and started asking two better questions instead: First, what can this thing touch? And second, how fast can I cut it off if it does something it shouldn’t?

That’s not really a security philosophy, so much as just what happens when you don’t get the luxury of control and still have to defend the place anyway.

I bring this up because I keep getting some version of the same question lately from customers, from analysts, and even from conversations I’m having with myself at odd hours (that’s normal, right?). It goes something like this: AI is making attackers faster and cheaper to arm, defenders can’t keep pace, so what do you actually do about a threat you can’t predict?

Honestly, you stop trying to predict it. You build for the world where you’re wrong about what’s coming, because you will be.

The inventory problem, now with agentic identities!!!

Every org I talk to this year sits somewhere on the spectrum from “AI agents everywhere” to “AI agents everywhere and nobody told security.” Some of that’s enthusiasm. A lot of it is organizations with a higher risk tolerance who’ve decided that moving fast with an agent that has broad, standing access is a trade worth making. I’m not going to tell them they’re wrong. I’ve run environments like that. I was, functionally, the containment plan for one.

But there’s a real difference between a person doing something reckless and an agent doing it. A person gets tired, second-guesses themselves, or eventually asks permission because they don’t want to get fired. An agent does none of that. It runs at whatever speed and scale it’s built for, with whatever access it was granted, and it doesn’t feel bad about any of it. If your engineering team going rogue is a five-alarm fire, an agent going rogue with the same access is that fire with no fire department coming, because nobody’s watching a process. They’re watching a person.

So the asset inventory problem from that SOC job doesn’t go away with AI. It just gets faster.

Assuming misbehavior

“Assume breach” has been the working posture in security for a while, and it’s a good one. I’d push it further for this era, though: assume misbehavior. Not malice necessarily, just an agent doing exactly what it was told, in a context nobody anticipated, touching something nobody meant for it to touch. That’s not rare. That’s a Tuesday for anyone running this stuff at scale.

So what do you actually do about it. Start with scoping: an agentic identity doesn’t need standing access to everything it might theoretically need someday. It needs access to what it’s doing right now, for the task in front of it. Obvious, sure, and also the thing that gets skipped every time, because scoping is slower than granting broad access once and moving on with your day.

Then there’s revocable identity. Every agent identity should be built on the assumption that you’ll need to kill it fast, without a ticket, without a meeting, without waiting on someone who’s out of office. The moment revocation depends on a process instead of a switch, you don’t actually have a control anymore.

And zero trust, applied honestly, not the marketing version. The actual version, where an agentic identity and its request get verified every single time, not once at provisioning and then trusted forever because re-checking felt like overkill.

This is basically the direction CoSAI’s been pushing with agentic identity. Stop treating an agent like a service account nobody remembers to rotate, and start treating it like an actual identity in your IAM stack, one you can audit, revoke, and hold accountable the same way you would a person’s account.

Underneath all three is the same idea. I can’t predict what an agent will try to do, and neither can you, and neither can the team that built it. What I can control is what happens when it tries.

The department of “how”

I don’t think the answer to “AI agents are everywhere” is to say no. I’ve never been the CISO whose first move is no, and I don’t think that’s a great career strategy for a CISO who wants to stay in the room for the next decision. What I actually believe in is enablement with a leash. Let the business move, but build the access model so that when something goes sideways, and it will, the blast radius is small and containment is fast.

I’ll be honest about the shelf life of that stance too. “Fine, but here’s the leash” works right up until it doesn’t, until agents operate at a speed or level of autonomy where a human-paced leash can’t keep up. I don’t know exactly where that line sits. I don’t think anyone does, no matter how confidently they’ll say otherwise from a conference stage. But I’d rather build the muscle now, scoping, revocation, honest zero trust, while I still have a leash that works at all, than find out the hard way that it doesn’t.

That’s really the whole argument. I can’t govern what’s coming, only what something’s allowed to touch once it’s here, and how fast I can take that away when it does something I didn’t expect. In a year when nobody, including the people building this stuff, can tell you with a straight face what’s coming next, that’s not nothing.

Share

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

Related Reading

Security Trends

AI Agents Need a Birth Certificate. The Government Just Said So.

August 20, 2026
Network Access ControlSecurity TrendsZero Trust

We Gave an AI Agent a Login and Watched It Go Rogue. Here’s What Happened Next. 

August 18, 2026
Cyber Attacks

Hackers Just Vished Wall Street’s Biggest Hedge Funds. Here’s the Access Control Lesson.

August 7, 2026