AI agents are changing the scale and speed of identity activity inside the enterprise. They can create records, call APIs, retrieve data and initiate workflows faster than a human operator, but many organisations still govern them as if they were ordinary software accounts. The growing gap between agent capability and identity governance creates a new control problem: an agent may act with broad permissions, unclear ownership and limited traceability while attackers look for ways to redirect or abuse those actions.

Traditional IGA assumes a relatively stable relationship between a person, a role and an entitlement. Agentic systems break that assumption. An agent can invoke multiple tools, inherit a user context, create temporary identities or pass data between services. Permissions that appear reasonable in isolation can become dangerous when chained together. A compromised prompt, tool or token can turn a helpful workflow into an unauthorised transaction.

The first requirement is inventory. Organisations need to identify agents, service accounts, API keys, delegated tokens and the applications they can reach. Each identity should have an owner, business purpose, risk classification and expiration or review date. Discovery must include development environments and shadow deployments, where agents are often introduced before formal security review.

Governance must then move closer to runtime. Least privilege should be enforced at the tool and action level, not only at the application level. High-impact actions should require step-up approval, policy checks or human confirmation. Logs need to capture the initiating user, the agent identity, the tools called, the data accessed and the outcome. That evidence is essential for both incident response and access certification.

IGA leaders should treat agent governance as an extension of identity lifecycle management. Joiner, mover and leaver processes need equivalents for agent creation, model changes, ownership transfers and retirement. Without those controls, organisations will accumulate invisible privilege at machine speed. Identity governance administration has to become adaptive enough to manage not just who can access a system, but what an autonomous identity is allowed to do in a specific context.