For an AI agent, that means being able to establish what the agent is, who owns or sponsors it, what authority it has been given, what it is allowed to do and what it actually did.
That is a much richer concept than authentication.
Key Takeaways
- AI agents should be treated as distinct, governed non-human identities rather than extensions of human accounts.
- Authentication establishes identity; authorisation determines what that identity can do.
- Delegation provides the link between an agent and the human or business principal it represents.
- Lifecycle and audit controls are essential if agents are going to operate at enterprise scale.
An agent is a new kind of enterprise actor
Enterprise environments already contain thousands of non-human identities.
Applications have identities. Workloads have identities. Services have identities. Devices have identities.
AI agents belong in this broader identity landscape.
What makes them different is their degree of autonomy.
A traditional service generally performs a predefined operation. An agent can determine its next action based on its objective, the information it receives and the tools available to it.
That makes the identity of the agent relevant to every subsequent decision.
If an agent calls an API, the organisation needs more context than simply knowing that the request came from a trusted system.
It needs to know which agent made the request, what it was trying to accomplish and under whose authority it was acting.
Authentication is the beginning, not the answer
Authentication answers an important question:
Who is making this request?
But enterprise authorisation has always required a second question:
What is this identity allowed to do?
With agentic systems, there is another:
Why is this agent allowed to do it now?
An agent may have legitimate access to an application and still attempt an action that falls outside the purpose for which that access was granted.
This is why runtime authorisation becomes increasingly important as agents become more autonomous. Ping describes runtime identity as moving the decision point from the initial login or credential issuance to the moment an action is requested.
The relationship between the agent and the human matters
Most enterprise agents will operate within a broader chain of responsibility.
An employee asks an agent to complete a task.
The agent invokes a tool.
The tool accesses a business application.
That application performs an operation.
The identity model needs to preserve that chain.
The agent should not have to pretend to be the employee.
Instead, the organisation should be able to establish:
Human or business principal → delegated authority → agent → requested action → resource
This is why delegation is so important.
Delegation provides a mechanism for granting an agent a defined subset of another identity's authority without simply handing over the underlying credentials. Ping's guidance specifically recommends delegation rather than impersonation, with limited scopes and explicit accountability.
Why shared credentials create a governance problem
Shared service accounts have existed for years, often because they were practical.
They become much harder to justify when the actor using them can reason, make decisions and interact with multiple systems autonomously.
If several agents use the same credential, an investigation may reveal that a particular account performed an action but not which agent was responsible or which human initiated the activity.
The identity becomes technically valid but operationally ambiguous.
A distinct identity for each agent provides a better foundation for accountability.
It can be associated with an owner, purpose, environment, permissions and lifecycle state.
That makes it possible to govern the agent rather than simply authenticate its connection.
Identity also creates a lifecycle
An agent should not become a permanent identity simply because it was created successfully.
Its access should reflect its purpose throughout its lifecycle.
That means being able to register the agent, establish ownership, grant appropriate permissions, review those permissions, modify them when its purpose changes and retire the identity when it is no longer required.
This is not a new governance discipline.
It is an extension of identity lifecycle management into an environment where the number and variety of non-human actors can grow rapidly.
Ping's current agent governance model similarly emphasises discovery, distinct identities, ownership, delegation, least privilege, lifecycle controls and auditability as connected parts of agent governance.
Identity should preserve context
The real value of agent identity is therefore not the credential itself.
It is the context surrounding the credential.
Consider two API requests that arrive at the same application.
One is from an agent performing an approved task for an employee.
The other is from an agent that has acquired the same technical access but is attempting an action outside its intended purpose.
If the system only knows that both requests possess valid credentials, it has very little basis for distinguishing them.
If it understands the agent, the delegated authority, the resource, the requested action and the surrounding context, it has a much stronger basis for making a decision.
That is the direction identity needs to take as autonomous systems become more capable.
The identity question will follow every agent
The enterprise AI conversation will continue to evolve.
Models will change. Frameworks will change. Agent architectures will change.
The underlying governance questions are likely to be much more durable.
Who is the agent?
Who owns it?
Who is it acting for?
What is it allowed to do?
What is it doing now?
Can we prove what happened?
Those are identity questions.
And as agents move from assisting people to acting on their behalf, answering those questions will become a prerequisite for enterprise trust.
An AI agent does not need to be human to have an identity. It needs an identity because it is capable of acting.
From Breach to Board-Ready: A Governance Playbook for Agentic AI
Discover how identity-first governance can help organisations secure AI agents, enforce least privilege and strengthen enterprise oversight.



