Connect with us

Tech News

Ensuring the Security of AI Agents on Your Team: Best Practices for Protection

Published

on

AI agents are part of your team now. Here’s how to secure all of them.

Presented by JumpCloud


A comprehensive approach to safeguarding all identities within the contemporary workforce, whether human or artificial.

Your organization likely has a robust system for managing human identities. New employees undergo onboarding, receive roles, entitlements, and have a designated manager overseeing their access. When they leave, their credentials are revoked. This process is well-established in IT: all workforce identities that can access your systems must be identified, scoped, and accountable from the moment they enter your environment to the moment they depart.

AI agents now operate within those same systems. They interact with Salesforce, create Jira tickets, provision infrastructure, conduct financial transactions, and communicate on behalf of your teams. In essence, they function as workforce members, yet in many organizations, they were never formally onboarded, lack a designated owner, and have no offboarding procedure when their role concludes.

Research conducted by JumpCloud in Q3 2026 revealed that non-human identities outnumber human users in 83% of organizations, with only 21% implementing governance controls specifically for them. The framework outlined below aims to bridge this gap.

Stage 1: Identifying all agents operating in your environment

Effective governance begins with a thorough inventory, which many organizations lack. AI agents are deployed by various teams without IT’s full knowledge, leading to shadow AI—agents operating in production environments without formal records, designated owners, or a systematic way to halt them in case of issues. Continuously monitoring your agent population across all environments, including cloud platforms, managed devices, SaaS integrations, and on-premise systems, is crucial. Document each agent’s access permissions, workflow impact, and triggering mechanisms to establish a foundational inventory.

See also  Top Deals on Electric Toothbrushes for Prime Day

Stage 2: Formalizing every agent as a recognized identity with an assigned owner

Every agent operating in your environment should exist as a formal identity in your directory, possessing defined objectives, authorized actions, and a human owner responsible for its conduct. This architectural decision distinguishes organizations capable of governing their agents from those that cannot. Registered agents can be assigned entitlements, subjected to access policies, and included in access reviews, while ungoverned agents, existing as service accounts or API keys, pose a significant risk.

Registration also addresses Zombie Agents—agents that continue to operate beyond their intended purpose—by automatically revoking access when ownership lapses. This proactive approach eliminates the need for reactive cleanups after system failures.

Stage 3: Managing agent access with minimal privileges and zero permanent credentials

Registered agents require access to perform tasks, with the principle of least privilege guiding their entitlements to align precisely with their defined roles. Managing agent access securely involves issuing time-bound credentials for privileged operations, implementing approval workflows for sensitive system access, and maintaining emergency shutdown mechanisms for immediate response to breaches. Credential shielding is essential for agents requiring access to privileged systems, ensuring credentials remain hidden during operations.

Stage 4: Continuous governance of agent behavior beyond deployment

Establishing controls is just the beginning; ongoing governance ensures their effectiveness. Continuously monitoring agent actions, conducting regular access reviews, and promptly addressing deviations from authorized behavior are essential. Maintaining an audit trail for each agent, detailing access, actions, authorizations, and outcomes, is vital for accountability. Organizations unable to reconstruct this information lack meaningful agent governance.

See also  Exploring the Quirky Charm of the Looki L1 AI Pendant: A Hands-On Review

Foundation for all stages

Fragmented IT environments hinder the execution of this framework. Unifying identity, access, device management, and security controls enables consistent governance across humans, devices, and agents. Organizations with cohesive IT environments are five times more likely to integrate agents into critical workflows compared to those with fragmented systems. The Agentic IAM concept emphasizes governing humans, devices, and agents through a unified control layer to facilitate scalable governance alongside AI adoption.

Securing every identity, whether human or artificial, is paramount for safe AI expansion. Organizations that prioritize this foundation not only reduce risks but also accelerate AI integration with confidence in the governance and accountability of every identity in their ecosystem.


For more insights, access JumpCloud’s Q3 2026 IT Trends Research report (based on 800 IT leaders from the US and UK) here. Explore the Agentic IAM lifecycle framework developed by JumpCloud here.

Greg Keller, CTO and Co-founder at JumpCloud.


Sponsored content is produced by companies with a business relationship with VentureBeat. For more information, contact sales@venturebeat.com.

Trending