AI Agents Are Becoming Digital Colleagues. Their Identity and Access Models Must Change.
An AI agent borrows your credentials. AI colleagues never return them.
Itamar Appelblat, Co-founder and CEO of Token Security
Organizations no longer have years to adapt to changes in AI-driven work. In just three years, workplace AI has already moved through one major phase, while the next is approaching quickly.
Session-scoped chats came first, bringing risks associated with model output. Task-scoped agents followed, introducing risks related to autonomous behavior and actions. Now, truly persistent AI colleagues are on the horizon—and they could dismantle the access model organizations currently rely on.
AI companies have already begun signaling this direction through their terminology. Microsoft refers to agents as “digital colleagues,” while OpenAI CEO Sam Altman outlined plans for virtual colleagues in February 2025.
That vision is becoming a reality. Security teams will need new identity governance and access-control models to address the fundamental differences between temporary AI tools and persistent AI colleagues.
Why persistent AI agents change everything
Organizations will need to plan for persistent AI agents sooner or later. For several years, businesses could fit AI into existing access models. However, autonomous digital colleagues require a different approach.
Approving actions one at a time only works when a human can verify each request. Persistent agents instead require access to be provisioned in advance through a machine-friendly—but secure—process. They should not rely on continuous human approval for every action, but they must be able to request additional access when a task requires it.
The identity model for AI agents is still far from standard. Current approaches rely on OAuth permissions, in-session handoffs, and service accounts. The first two typically treat humans as the primary identity, while service accounts are rarely created specifically for AI agents.
Persistence also creates a new risk profile for AI agent credentials. A persistent agent has a standing privilege much like a human employee, which means organizations must manage its entire identity lifecycle. Deprovisioning is an essential security step.
Access creep is another concern. Persistent digital collaborators can accumulate permissions across multiple projects. Access creep is already one of the oldest unresolved problems in identity governance for humans. For machines, the problem could be worse because permissions can accumulate faster—and agents tend to use the access they receive.
Several individually reasonable permissions can also combine to give an agent an overall level of access that no one intended to grant.
The SOC 2 report states that controls worked, but does not explain what did not. The agent runs under borrowed credentials and has no owner or off switch.
Token Security finds all agents, assigns them identities, and restores access to the jobs they are intended to perform.
AI platforms and enterprises must adapt
Enterprises are not the only organizations that need to adapt to the next phase of AI agent workflows. The two most widely deployed agent platforms currently do not issue their own credentials to agents.
Neither Anthropic nor OpenAI performs OAuth client-credential granting in its hosted chat products, although the ChatGPT connector does. Service accounts and JWT assertions are completely denied.
Both platforms allow developers to pass a static bearer token to an agent through the API, but a bearer token is not a proper agent identity.
As a result, AI systems can receive persistent privileges designed for humans, while audit logs become contaminated. When an AI system acts using permissions granted to a user, the human is often recorded as the actor.
The desire to keep humans informed creates additional problems. OAuth assumes that a person will read a consent screen and approve a fixed list of scopes. Agents, however, are rarely satisfied with their first interaction. They discover tools at runtime and attempt to use them as needed.
Reviewing sensitive actions every few minutes is frustrating, but it can also create a security risk because human attention is limited.
Effective AI colleagues need access to the right systems
Tara Seshan, product lead for ChatGPT Work and Codex at OpenAI, described what agents can actually help with on Lenny’s Podcast in August 2026.
Model intelligence is only part of the equation. The rest depends on what she calls “meat-and-potatoes tactics,” including access to data, cloud infrastructure, and reliable systems.
Her analogy is straightforward: Hire a coworker and lock that person in a room without access to Google Docs, Slack, or company databases, and the coworker will not be effective. Isolated cloud agents face the same limitation.
She is right about the requirement. Useful AI colleagues need access to many of the same systems used by human employees.
Seshan also discussed an agent spawning subagents to parallelize work and a near future in which agents collaborate on shared tasks. Both scenarios are logical extensions of AI workflows, but they assume an identity model that does not yet exist.
When one person’s agent hands work to another person’s agent, the credentials used to perform the task belong to the person who started the chain—not necessarily to the agent performing the action.
Google demonstrated an AI teammate identity model in 2024
At Google I/O in May 2024, Google demonstrated a Workspace agent named Chip. Chip had its own Workspace account, a designated role, defined permissions, and a specific set of goals. Users could join a chat room and receive responses based on the history available to the agent.
Workspace VP Aparna Pappu said at the time that Google still had significant work to complete before virtual teammate experiences reached production. Chip remained a demonstration.
What Google and its competitors have shipped instead is an agent that inherits human authority.
How to secure persistent AI agents
Platform vendors are beginning to respond. Microsoft has shipped Entra Agent IDs with first-class agent identities and designated human sponsors. Okta has added agent identities with short-lived, scoped tokens and revocation paths to Universal Directory. SailPoint and CyberArk offer comparable services.
The limitation is that each approach is tied to a specific platform. For organizations seeking platform independence, identity control becomes the de facto checkpoint for enforcing policies because identity governs access to actions across systems.
Organizations should begin with these core priorities:
- Give every persistent agent a unique identity. If an agent authenticates as a human, downstream controls cannot reliably distinguish between the two, and investigations cannot accurately attribute actions.
- Scope access to the agent, not the person who started it. An agent that reads Jira should not hold a token that also writes to a cloud provider simply because the engineer who launched it has both permissions.
- Define when the agent should expire. Digital coworkers may not be project-based, but they should not be treated as immortal. A team may disband, an employee responsible for the agent may leave, or the agent may become inactive. When creating an agent, define these conditions and specify how long it can remain idle before automatic expiration.
The third wave of AI security requires agent identities
The first wave of AI involved risks driven by model outputs, requiring filtering, guardrails, and output classification. The second wave introduced action-based risks and human-involved processes, increasing the focus on authorization and access control. The third wave removes humans from more workflows while leaving access intact.
The pressure is about to increase. Seshan’s example includes agents that generate subagents and collaborate across teams. One person’s digital coworker may quickly hand work to another person’s coworker. These handoffs can only be managed effectively if agents maintain their own identities.
In other words, agents need their own credentials and identities before they are given work.
At Token, we have identified AI agents and MCP servers running in environments, including those without a registered owner, by analyzing OAuth grants, API keys, and login traffic. Organizations can give each agent its own identity and human owner, scope and rotate its credentials, and retire the agent when its owner leaves or it becomes idle.
Token Security covers entire cloud and SaaS environments, not just one vendor.
Book a Token demo to check how many agents are operating with borrowed human credentials.
Sponsored and written by Token Security.
Source: www.bleepingcomputer.com


