Who Approved Credentials Your Agent
Who approved the AI agent credentials your agents are running on? In many organizations, the honest answer is nobody. Techstrong TV asked security and engineering practitioners that question. Furthermore, their answers reveal a growing blind spot in how teams grant access to AI agents.
A one time decision that never gets revisited
When an agent is built, someone makes a single decision about which credentials it will use. In addition, people running their own agents, such as Claude Cowork, set those credentials themselves. One practitioner says they have yet to meet a customer with a formal approval process for agent permissions.
Usually, the approver is a developer working under deadline pressure. Meanwhile, an engineer may build a quick prototype and wire in a token to make it work. Consequently, that same token is often still in place six months later.
More power than the humans they serve
At larger companies, IT or a manager usually grants the agent its credentials. However, the agent often ends up with more access and power than the person it works for. As a result, a single over permissioned agent can become a serious security risk.
Moving enforcement to the moment of use
The practitioners agree that approval at creation time is not enough. Therefore, enforcement has to move to the moment an agent tries to use a token. That shift lets teams check whether each action still makes sense in context.
Furthermore, it gives security teams a chance to catch stale tokens and excessive permissions before they cause harm. Teams should also review AI agent credentials on a regular schedule, just as they do for human users.
Why AI agent credentials need an owner
Every agent needs a clear owner and a documented approval path. In addition, credentials should be scoped to the task and rotated over time. Consequently, organizations can adopt AI agents without handing them the keys to everything.
Explore more cybersecurity coverage and the latest Techstrong TV interviews.
For more information please visit techstrong.tv
Transcript
On a lot of customer cases which I've seen, it's nobody. When the agent is being built, there is a one-time decision of which credentials the agent will be using. If you're self-running these agents like Cloud CoWork, you are setting the credentials of the agent.
I talk to a lot of customers, and I have yet to talk to a single customer with a formal approval process for agent permissions. Usually, a developer under deadline pressure. An engineer needed to do a quick prototype of a product, and he kind of developed the whole application, and it's primarily the same token that is still there six months later.
You need to move the enforcement from when the token was originally created to the moment that the agent is actually trying to use it. But if you're working for a larger company or a Fortune 1000, it's generally going to be either IT or your manager who's going to credentialize your agent. And more times than not, that agent will have more access and power than you do as the human.