IGA Was Built for Employees. Agents Break the Model.
Identity governance assumes a hire date, a manager, and an exit interview. Autonomous AI agents have none of those, and legacy IGA tools can't see the gap.

Key points
- Traditional identity governance and administration (IGA) platforms were designed around human employment records and departure dates, neither of which apply to autonomous AI agents.
- AI agents act as first-class principals inside enterprise environments, holding credentials with no HR system of record behind them.
- Existing joiner-mover-leaver workflows have no equivalent trigger for an agent being spun up or quietly retired.
- Provisioning at machine speed means agent identities can multiply faster than any quarterly access review cycle can catch.
- Defenders inherit orphaned, over-privileged non-human identities that look, to legacy IGA, like nothing at all.
Identity lifecycle management has a comforting shape. Someone gets hired. HR creates a record. A manager approves access. Eventually the person leaves and, in theory, their accounts die with the offboarding ticket.
AI agents refuse to fit inside that shape.
An analysis published this week by The Hacker News argues that the entire joiner-mover-leaver model, the load-bearing beam of every IGA deployment shipped in the last two decades, was built for principals with an employment record. Agents don't have one. They have a config file, maybe a service account, and an appetite for tokens.
That mismatch is the whole story. When we reported SailPoint's $200 million move to acquire Entro Security on 18 June, the subtext was the same: non-human identity and secrets management had become a gap too large for a governance platform to ignore.
What actually breaks when the principal isn't a person?
Start with provisioning. A human joins, a manager clicks approve, birthright entitlements flow. An agent gets instantiated by a developer or another agent entirely, and inherits whatever credentials the calling context happened to have lying around. No manager is in the loop. Often there's no ticket either.
Movement is worse. When a human changes roles, HRIS fires an event and access recertification kicks in. When an agent gets repurposed, pointed at a new data source or wired into a new workflow, nothing fires. The identity stays the same while the blast radius quietly grows.
Then there's the leaver problem. Humans quit. Agents get abandoned. A prototype from a hackathon six months ago still holds a Snowflake key. A retired workflow still has an OAuth grant against Google Workspace. Nobody offboards a script.
This is not a novel category of risk. It's service-account sprawl with a language model attached. Anyone who has cleaned up a decade of legacy svc_ accounts in Active Directory already knows this movie. What's new is the velocity: agents can be spawned programmatically, and increasingly they spawn each other. The provisioning curve stops looking like hiring and starts looking like fork().
Legacy IGA platforms, SailPoint, Saviynt, Okta Identity Governance among them, are catching up, but their data models still assume a human system of record upstream. Feed them a population of non-human identities with no HRIS to reconcile against, and the certification campaigns get creative in unhelpful ways.
Should you worry?
Yes, and here's where to start this quarter. Inventory non-human identities separately from human ones, and require every agent identity to name a human owner and an expiration date. Treat agent credentials as short-lived by default: if a token can outlive the workflow that needed it, that's the bug. Wire agent creation events into the same review pipeline as privileged human access, not into a separate DevOps backwater nobody audits. Kill birthright entitlements for agent identities, because every permission should be justified against a specific tool call, not a job family.
None of this requires believing in AGI. It requires believing that a service account with a reasoning loop attached deserves at least as much governance scrutiny as a summer intern.
That bar is lower than the industry is currently clearing.



