"Agents run on borrowed credentials, with no owner and no off switch." — Itamar Apelblat, Co‑Founder and CEO, Token Security
Persistence changes everything
What the author calls wave three of AI-driven work is defined by persistence: AI coworkers that live beyond a single session and operate without constant human approvals. In this mode, the security question shifts from "what did the model say?" or "what did the model do?" to "who — or what — holds long‑lived access?" The article warns persistent agents will require provisioning and lifecycle controls unlike those used for humans or current short‑lived AI sessions, and that standing privileges for agents will generate an access‑governance challenge similar to, but faster than, human access creep.
OAuth, service accounts, and hosted chat platforms
The piece lays out a practical gap: the two most widely deployed agent platforms do not issue agents their own credentials. According to the source, neither Anthropic nor OpenAI run the OAuth client credentials grant in their hosted chat products, while ChatGPT connectors reject service accounts and JWT assertions outright. Developers can hand an agent a static bearer token via APIs, but the article calls that "far from a proper identity." The result, it says, is that agents frequently run on human‑granted privileges and that audit logs record the human starter as the actor.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleGoogle's Chip demo at I/O 2024 and the attribution problem
The article points to a May 2024 Google demo at I/O of a Workspace agent called Chip as an example of an alternative approach. Chip had a Workspace account, a designated role, configured permissions, and stated objectives; Workspace VP Aparna Pappu told attendees Google still had work to do before "agentive" experiences could reach product. Chip remained a demo, and the author notes that what shipped instead were agents that inherit a human's authority — a model that makes downstream attribution and governance difficult when one person's agent spawns work for another's.
Vendor moves and a fragmented solution set
Platform vendors have begun to add agent‑specific identity features, but the article highlights fragmentation. Microsoft shipped Entra Agent ID with first‑class agent identities and a named human sponsor. Okta added agent identities to Universal Directory with short‑lived, scoped tokens and revocation. SailPoint and CyberArk offer comparable functionality. The author frames the downside plainly: each of these solutions secures agents inside its own estate, leaving cross‑platform governance an unresolved problem.
Five practical controls — and what they mean for technologists, procurement leaders, and end users
- Find the shadow coworkers: detect unregistered agents through authentication traffic, not just registration records.
- Give every persistent agent its own identity: if an agent authenticates as a human, downstream controls and investigations cannot distinguish actions.
- Record a human owner: orphaned agents with live credentials are the most common source of standing privileges.
- Scope access to the agent, not the person who launched it: an agent that reads Jira should not inherit a token that also writes to cloud resources.
- Decide when the agent dies: write expiration conditions and idle timeouts into the agent's lifecycle at creation.
For technologists and security teams, the article says, those controls map to identity‑first monitoring and remediation — finding agents by OAuth grants, API keys, and login traffic, assigning each an identity and a human owner, rotating credentials, and retiring agents when appropriate. For platform vendors and procurement leaders the piece signals a choice: continue vendor‑specific agent identities or demand cross‑platform standards. For end users and operators, the consequence is practical: a rising burden if systems keep asking humans to approve frequent sensitive actions, and obscured audit trails when agents act under human credentials.
The article closes with a crisp operational axiom: before you give a digital coworker a job, give it a badge — a distinct identity, a recorded owner, scoped privileges, and a planned end of life. Token Security offers a service that identifies agents running on borrowed credentials across cloud and SaaS systems, assigns identities and human owners, scopes and rotates credentials, and retires agents that are idle or orphaned.




