AI agent access is complicating identity controls as agents log in, carry credentials and act on someone’s behalf. They have characteristics of both human and machine users.
That overlap can make actions harder to attribute: An agent may appear in an audit log as the person it works for, even though software took the action. Security teams need to account for that distinction, according to Nancy Wang (pictured), chief technology officer of AgileBits Inc., doing business as 1Password.
“Is it a machine? Is it a human? The right answer is [that] it’s probably both,” Wang said. “Which is why it makes it actually even more important to understand what is the identity this agent is acting as.”
Wang spoke with theCUBE Research’s Krista Case and co-host Rebecca Knight at Okta’s Oktane event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how 1Password is treating AI agents as a hybrid identity that needs just-in-time, task-based access and credentials that never sit in the model. (* Disclosure below.)
AI agent access raises the stakes for Okta and 1Password
1Password rejects standing privilege for humans, machines and agents alike. Access is granted just in time and checked against why it is needed, an idea the company recently turned into a privileged access product scoped to a single task.
“Just like you would verify whatever an intern does before you allow them to move on to the next project, [it’s the] same thing with agents,” Wang said. “You just want that agent to prove that it actually finished its last task with the right level of permissions, doing the right thing before you allow it to move on to the next task.”
1Password and Okta are backing shared identity standards so an agent’s verified identity and authorization context can carry across their systems, Wang noted. The company’s Credential Broker releases secrets only when needed, without exposing them to the agent or underlying model.
“I think that all of our apps are going to become thin clients and that most of the code will be written in remote sandboxes,” Wang said. “Secure access needs to happen in the cloud.”
Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Okta’s Oktane event:
(* Disclosure: TheCUBE is a paid media partner for Okta’s Oktane event. Neither Okta, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
