Tech News
Ensuring the Security of AI Agents on Your Team: Best Practices for Protection
Presented by JumpCloud
A comprehensive approach to safeguarding all identities within the contemporary workforce, whether human or artificial.
Your organization likely has a robust system for managing human identities. New employees undergo onboarding, receive roles, entitlements, and have a designated manager overseeing their access. When they leave, their credentials are revoked. This process is well-established in IT: all workforce identities that can access your systems must be identified, scoped, and accountable from the moment they enter your environment to the moment they depart.
AI agents now operate within those same systems. They interact with Salesforce, create Jira tickets, provision infrastructure, conduct financial transactions, and communicate on behalf of your teams. In essence, they function as workforce members, yet in many organizations, they were never formally onboarded, lack a designated owner, and have no offboarding procedure when their role concludes.
Research conducted by JumpCloud in Q3 2026 revealed that non-human identities outnumber human users in 83% of organizations, with only 21% implementing governance controls specifically for them. The framework outlined below aims to bridge this gap.
Stage 1: Identifying all agents operating in your environment
Effective governance begins with a thorough inventory, which many organizations lack. AI agents are deployed by various teams without IT’s full knowledge, leading to shadow AI—agents operating in production environments without formal records, designated owners, or a systematic way to halt them in case of issues. Continuously monitoring your agent population across all environments, including cloud platforms, managed devices, SaaS integrations, and on-premise systems, is crucial. Document each agent’s access permissions, workflow impact, and triggering mechanisms to establish a foundational inventory.
Stage 2: Formalizing every agent as a recognized identity with an assigned owner
Every agent operating in your environment should exist as a formal identity in your directory, possessing defined objectives, authorized actions, and a human owner responsible for its conduct. This architectural decision distinguishes organizations capable of governing their agents from those that cannot. Registered agents can be assigned entitlements, subjected to access policies, and included in access reviews, while ungoverned agents, existing as service accounts or API keys, pose a significant risk.
Registration also addresses Zombie Agents—agents that continue to operate beyond their intended purpose—by automatically revoking access when ownership lapses. This proactive approach eliminates the need for reactive cleanups after system failures.
Stage 3: Managing agent access with minimal privileges and zero permanent credentials
Registered agents require access to perform tasks, with the principle of least privilege guiding their entitlements to align precisely with their defined roles. Managing agent access securely involves issuing time-bound credentials for privileged operations, implementing approval workflows for sensitive system access, and maintaining emergency shutdown mechanisms for immediate response to breaches. Credential shielding is essential for agents requiring access to privileged systems, ensuring credentials remain hidden during operations.
Stage 4: Continuous governance of agent behavior beyond deployment
Establishing controls is just the beginning; ongoing governance ensures their effectiveness. Continuously monitoring agent actions, conducting regular access reviews, and promptly addressing deviations from authorized behavior are essential. Maintaining an audit trail for each agent, detailing access, actions, authorizations, and outcomes, is vital for accountability. Organizations unable to reconstruct this information lack meaningful agent governance.
Foundation for all stages
Fragmented IT environments hinder the execution of this framework. Unifying identity, access, device management, and security controls enables consistent governance across humans, devices, and agents. Organizations with cohesive IT environments are five times more likely to integrate agents into critical workflows compared to those with fragmented systems. The Agentic IAM concept emphasizes governing humans, devices, and agents through a unified control layer to facilitate scalable governance alongside AI adoption.
Securing every identity, whether human or artificial, is paramount for safe AI expansion. Organizations that prioritize this foundation not only reduce risks but also accelerate AI integration with confidence in the governance and accountability of every identity in their ecosystem.
For more insights, access JumpCloud’s Q3 2026 IT Trends Research report (based on 800 IT leaders from the US and UK) here. Explore the Agentic IAM lifecycle framework developed by JumpCloud here.
Greg Keller, CTO and Co-founder at JumpCloud.
Sponsored content is produced by companies with a business relationship with VentureBeat. For more information, contact sales@venturebeat.com.
-
Facebook10 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook10 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook8 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook10 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook8 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook10 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook8 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple10 months agoMeta discontinues Messenger apps for Windows and macOS

