An AI agent that can call tools or APIs acts through credentials and delegated authority. Security starts by identifying the agent, limiting what it can do, binding consequential actions to accountable approval, and retaining evidence.
Current as of 2026-08-15
NIST’s 2026 agent identity concept paper focuses on identification, authentication, authorization, delegation, auditing, non-repudiation, and human-in-the-loop authorization.
Decision summary
- Create a unique identity for each agent and environment.
- Use short-lived, audience-bound credentials and minimum scopes.
- Require approval for high-impact or irreversible actions.
- Log intent, authority, inputs, actions, outputs, and result.
Treat the agent as a principal
Do not let multiple agents share a broad human account or API key. Record an owner, purpose, environment, approved tools, data classes, risk tier, and expiration for every deployed agent identity.
Constrain delegation
- Separate read from write capabilities.
- Limit resources, tenants, records, and time windows.
- Bind tokens to the intended audience.
- Use just-in-time elevation for exceptional actions.
- Require fresh approval when scope or context changes.
Bind actions to human authority
A human approval should identify the target, action, impact, and expiration. The execution system—not only the model prompt—should enforce it. High-impact financial, identity, production, data removal, and external-communication actions deserve stronger confirmation and separation of duties.
Monitor and revoke
The NIST AI RMF Core calls for documented roles, monitoring, oversight, incident response, and change management. Retain tamper-resistant logs and test whether an agent, credential, tool, or workflow can be disabled quickly without disrupting unrelated services.
Next step for your environment
Create an agent identity register and deny production access until ownership, scope, approval, logging, and revocation are testable. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.
Sources and update trigger
Review trigger: Review when NIST publishes final agent identity guidance or agent tools and permissions change.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles