AI agents are part of your team now. Here’s how to secure all of them.
Presented by JumpCloud A practical framework for securing every identity in the modern workforce, human or not. Your organization already has a rigorous process for governing human identities. New employees go through onboarding. They get a role, a set of entitlements, and a named manager accountable for their access. When they leave, their credentials are revoked and access is terminated. It’s a…
Title: Securing AI Agents in Modern Workforce
JumpCloud's recent research reveals that non-human identities outnumber human users in 83% of organizations, yet only 21% have put in place governance controls specifically for these AI agents. The framework provided below aims to address this gap and ensure secure management of AI agents within an organization.
Stage 1: Discover AI Agents
The first step in securing AI agents is to identify all agents operating within the organization's environment. AI agents can be deployed by various teams such as product, operations, and individual contributors, often without prior IT knowledge. Shadow AI agents pose a significant challenge as they operate in production environments without formal records or defined owners.
It is essential to build a comprehensive inventory across all environments, including cloud platforms, managed devices, SaaS integrations, and on-premise systems. Document each agent's access, influence on workflows, and action triggers for proper inventory management.
Stage 2: Register AI Agents as Formal Identities
Each AI agent that operates within the organization should be registered as a formal identity with a defined purpose, authorized action scope, and a named human owner. This registration process enables the assignment of entitlements, implementation of conditional access policies, and inclusion in access reviews. This approach is crucial in distinguishing organizations capable of governing their AI agents from those that cannot.
It also aids in addressing zombie agents, which continue to access systems even after their original purpose has ceased. By assigning a named owner responsible for renewal, agents without active ownership will naturally lose access.
Stage 3: Manage Agent Access with Least Privilege and Zero Standing Credentials
For the agents that require access to perform their tasks, the principle of least privilege should be applied. Agents should have entitlements precisely scoped to their defined purpose, with time-bound access where possible and immediate revocation if their behavior changes. Static API keys and environment variables represent a persistent liability, as they never rotate and are easily exposed.
Implementing just-in-time credentials for privileged operations, approval workflows for agent actions in sensitive systems, and emergency shutdown mechanisms can help secure agent access. Additionally, credential shielding should be employed to prevent the exposure of underlying credentials to the agent models.
Stage 4: Continuous Governance of Agent Behavior
The previous stages establish the foundational controls. Continuous governance is essential to maintain these controls as they evolve. All agent actions should be logged for auditing purposes, and regular access reviews should be conducted to ensure the continued appropriateness of entitlements for each agent. Anomalies in agent behavior should be detectable before they escalate into incidents.
Finally, as an agent's purpose ends, its access revocation should be a proactive measure rather than a reactive reaction to an incident. Throughout this process, maintaining an audit trail of all agent activities is vital for accountability.
In conclusion, securing AI agents within an organization demands a meticulous approach that encompasses discovery, registration, access management, and continuous governance. By adhering to these stages, organizations can effectively manage their AI agents, mitigate potential risks, and maintain a secure environment.
Written by urgent.news from VentureBeat's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.