Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before an AI agent can act on enterprise data or systems, a CISO needs to know whose authority it is using, what it may do, where that permission is enforced, and how to stop it. Give each agent an attributable identity, bind its authority to a named user or accountable owner, constrain actions to approved tasks and resources, and make its activity observable and revocable. A unique identity is necessary, but it does not by itself make an action safe.

What does identity need to establish for an agent?

An agent should be treated as a distinct actor in the enterprise identity and authorization model—not as an invisible extension of a person’s login. Its identity should let security teams distinguish one agent from another and connect activity to the user or system that operates it. The associated entitlements should state what the agent is permitted to access or do.

Bill Fisher, a security engineer at NIST’s National Cybersecurity Center of Excellence, wrote: “For organizations to have confidence in transactions, agents need to be treated like first-class entities with their own unique identifiers, credentials, and associated entitlements that are bound to and by the identity of the user or system operating the agent.” The statement appears in his August 27, 2026, NIST Cybersecurity Insights post, “Back to the Future: Why Agentic AI Needs a Strong Identity Foundation.”

That relationship creates an authority chain that can be investigated: agent identity, sponsor or delegated user, credential, entitlement, action, and target resource. If an agent’s records only show a shared service account or a human’s broadly privileged login, investigators may be unable to tell which agent acted or under whose authority.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Should an agent use delegated user authority or its own identity?

Choose and document an authority model for each workflow. A user-initiated agent may act using permissions delegated by that user; an unattended, autonomous agent should have its own identity and defined operating authority. Avoid letting an implementation silently borrow a person’s credentials as a shortcut.

Pattern How authority is assigned Operational consideration
Delegated user access The agent acts within permissions delegated by the initiating user. Activity can be related to a user, but teams must understand the effective permissions and what happens when that user’s access changes.
Autonomous agent identity The agent acts under its own identity and assigned entitlements. It can support unattended operation, but requires a named accountable owner, a defined purpose, and its own lifecycle controls.

Microsoft Learn describes both patterns in its guidance for securing AI with Microsoft Entra. These are design choices, not a reason to assume every agent should have the same identity configuration. The right choice depends on whether a task is genuinely performed on a user’s behalf or needs to run independently.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How should authorization limit what an agent can do?

Authorization should evaluate the proposed action, the tool or integration being called, and the resource being targeted. Do not assume that a trusted orchestrator or a recognizable agent identity makes every downstream call appropriate. Enforce permissions at the relevant tool and resource as well as in the layer that coordinates the agent.

  • Allow only reviewed tools and integrations; deny unreviewed ones by default.
  • Scope permissions to a task and its required resources rather than granting broad inherited access.
  • Separate read and write authority where the workflow allows it.
  • Require human confirmation or time-bound elevation for destructive or otherwise high-impact operations.
  • Review the effective permissions across the entire call chain, including downstream systems—not only the orchestrator’s nominal role.

These are implementation recommendations drawn from Microsoft Learn’s least-privilege guidance, not universal product features or a settled agent-identity standard. Human approval is a control for consequential actions, not a substitute for defining delegated authority. NIST has cautioned that too many human-in-the-loop prompts can lead to consent fatigue.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What operating controls should cover the agent lifecycle?

Microsoft describes uncontrolled growth of agents without visibility or lifecycle control as “agent sprawl.” A practical operating model covers discovery through retirement, with an accountable owner and an explicit boundary for every sanctioned agent.

  1. Discover: Inventory sanctioned and unsanctioned agents, including owners, runtime environments, connected tools, data stores, and downstream systems. Record enough detail to identify agents that have appeared outside the approved process.
  2. Assign identity and ownership: Give each agent a distinct identity, a named sponsor or accountable owner, a recorded business purpose, and an operating boundary. Do not use shared human credentials as the agent’s identity.
  3. Define authority: Record whether the workflow uses delegated user permissions or an autonomous identity. Map approved tasks to the tools and resources each task needs.
  4. Constrain execution: Apply the task, tool, and resource controls described above, including approval or time-bound elevation where consequence warrants it.
  5. Observe activity: Log the agent identity, effective scope, action, resource, and correlation context. For delegated activity, preserve the user relationship. Monitor for unusual scope expansion and unexpected downstream access.
  6. Revoke and reassess: Test that teams can disable an agent identity, rotate its credentials, invalidate its tokens, and remove stale grants. Re-review the agent when its workflow, tools, data, or environment materially changes.

Which architecture choices should security leaders compare?

The deployment may use more than one control point. Compare the options against the workflow’s consequences and confirm that authorization remains effective from the agent through to the resource.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Decision Options to compare Questions for the CISO
Permission granularity Broad role or inherited access; task- and resource-scoped access How much access is usable without review, what is the potential blast radius, and do downstream systems enforce the narrow scope?
Approval model Standing authority; just-in-time elevation; human confirmation How serious is the consequence of an incorrect action? Can an approval be audited, and would frequent prompts create consent fatigue?
Identity mechanism Existing OAuth 2.0 delegation and workload-identity patterns; emerging agent-specific mechanisms Can credentials be managed and revoked across the lifecycle? Is the mechanism interoperable and mature enough for the use case?
Governance placement Identity platform; application or tool gateway; downstream resource authorization Does each call stay authorized end to end, or does one layer implicitly trust the orchestrator?

NIST’s August 2026 discussion notes that modern authorization patterns, including SPIFFE and OAuth 2.0, can address some enterprise agent challenges. NIST also says work on consumer-facing agent authenticators bound to user identities is in early phases. Treat an emerging mechanism’s maturity and lifecycle support as part of the decision, not as an assumed benefit.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do current NIST identity materials establish—and what do they not?

NIST’s work on software and AI agent identity is active exploration, not a completed standard or a final agent IAM requirement. The National Cybersecurity Center of Excellence project page describes an effort to demonstrate standards-based approaches to identifying, managing, and authorizing software and AI agents. As of October 4, 2026, the page said the project was soliciting comments, with community input informing further planning.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

NIST Special Publication 800-63-4, Digital Identity Guidelines, is risk-based guidance for digital identities of natural persons. It expressly excludes machine-to-machine authentication and API access on behalf of subjects, so it should not be presented as an agent identity standard. Fisher’s NIST post states the practical starting point: “The established IAM standards and best practices of today are the foundation upon which we will build the secure and scalable agentic protocols of the future.” For CISOs, that means applying sound identity and authorization practices now while tracking the standards work without treating exploratory guidance as settled policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.