Descope’s partnership with IDMWORKS points to a broader shift in identity architecture: the same control plane must increasingly serve people, applications and autonomous software. As enterprises adopt AI agents that can call APIs, handle workflows and make decisions, customer identity and non-human identity are becoming closely connected security concerns.
The identity problem moves beyond login
Traditional customer identity programmes focus on registration, authentication, consent and account recovery. Agentic workloads introduce another class of actor. An AI agent may act on behalf of a customer, service or employee, but it can also create sessions, invoke tools and pass data between systems without a human present at each step.
That makes a simple user-centric model inadequate. Security teams need to know which principal initiated an action, which agent performed it, what authority it received and whether that authority remains appropriate as the workflow changes. Without that context, an authenticated request can still be an unmanaged machine identity.
Why the partnership matters for NHI security
A delivery partnership can help translate identity technology into operating practice. For CISOs, the important question is not only whether an organisation can authenticate an agent, but whether it can govern the full lifecycle: issuance, delegation, monitoring, rotation and revocation.
Modern identity services can provide a foundation for risk-based authentication and policy enforcement. The non-human identity layer must extend those controls with scoped credentials, short-lived tokens, audience restrictions and clear separation between an agent’s identity and the human or service that authorised it.
Agentic Identity needs operational visibility
Visibility is particularly important when agents are assembled from multiple models, tools and SaaS platforms. Each integration can create new credentials and indirect trust relationships. An inventory that records only employees will miss the identities actually driving automated activity.
Organisations should connect identity telemetry with API, workload and application logs. That makes it possible to establish normal behaviour for an agent, identify privilege expansion and investigate whether a customer-facing action was produced by an expected workflow or an altered instruction chain.
Governance across the customer and machine boundary
The partnership also highlights the need for joined-up governance. Customer identity teams, IAM engineers and application owners need shared policies for consent, delegation and accountability. Agent permissions should be purpose-bound, reviewable and easy to revoke when a session, task or business relationship ends.
As agent adoption accelerates, the winners will be organisations that treat Agentic Identity as an extension of identity governance rather than as a feature added after deployment. That approach turns machine identity from an invisible implementation detail into a managed security control.