- What: Discussion on the need for unified identity fabrics in agentic AI
- Impact: Organizations need to rethink identity management for AI systems
Identity , AI/ML Inheriting trust: Why unified identity fabrics are becoming essential for agentic AI July 13, 2026 Share By Paul Wagenseil Credit: Adobe Stock Images The rise of agentic AI is forcing organizations to rethink identity from the ground up, said the panelists in a recent SC Media webcast . AI agents should not be treated as simply another type of non-human identity, the panelists agreed, because autonomous agents create dynamic inheritance chains that span humans, applications, service accounts, APIs, and other AI agents. As these inheritance chains grow, traditional identity governance models — designed for humans and later adapted for machine identities — have a hard time providing the visibility, accountability, and real-time authorization needed to secure autonomous workflows. What's needed is a unified identity fabric that continuously correlates identities, permissions, and relationships across disparate systems to expose inherited privileges and enable governance of AI agents. The panelists — Dr. Charles Herder, co-founder of Badge Inc.; Akshay Srinivas Rajanbabu, Distinguished Engineer at Radiant Logic; independent security advisor Andy Weeks; and host Mandy Logan — agreed that identity governance needs more than static permissions and periodic reviews. Organizations must now continuously map relationships among human identities, non-human identities, and AI agents while dynamically evaluating authorization based on context and intent. The panelists also explored how cryptographic trust , ephemeral credentials, delegated authority, and relationship graphs could work together to provide secure identity inheritance across increasingly autonomous enterprise environments, creating a foundation for governing AI agents without slowing innovation. As Akshay Rajanbabu explained, the industry has entered a fundamentally new era of identity: "The big takeaway for me was that agentic identity governance cannot be treated as a future problem," said Rajanbabu. "It exists today. We need to start working on it today. We need to map that inherited access chain." The greatest challenge isn't just authenticating AI agents but also understanding how permissions can build up as agents call on other agents, applications, APIs, and workflows. AI agents often inherit more privileges as they interact with enterprise systems, creating long chains of delegated authority that can quickly become invisible. The panelists said fragmented identity repositories might prevent security teams from seeing these inheritance paths, making unified identity graphs essential for understanding who or what can ultimately access sensitive resources. Another major theme involved accountability. AI agents may create additional agents and delegate tasks long after the employee who created them has changed roles or left the organization. Organizations must pre-determine who in the company inherits these delegated identity chains after an employee moves on. "What keeps me up is that it's not just visibility, it's accountability," said Weeks. Herder argued that AI agents should operate using delegated, time-limited credentials rooted in verified human identities. Combined with a unified identity platform, he said, cryptographic trust lets organizations prove both identity and delegated authority while reducing opportunities for credential abuse. The most forward-looking portion of the discussion focused on moving beyond static authorization toward intent-aware authorization. Rather than making access decisions solely on identity attributes or predefined roles, future identity systems should continuously evaluate the business purpose behind an agent's actions using contextual information derived from relationship graphs and inherited permissions. Authorization must occur in seconds, or even milliseconds, to prevent AI agents from exploiting temporary misconfigurations or excessive privileges. "Dynamic authorization is the only way that this scales as we go forward," Weeks said. AI agents are a fundamental shift in enterprise identity, the panelists agreed, not just another category of machine identity. Successfully governing them requires continuously updated identity data, relationship mapping, cryptographic trust, dynamic authorization, and intent-aware policy enforcement operating together as a unified identity fabric. Paul Wagenseil Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com. Related Identity The Canvas breach exposed higher Ed’s third-party identity blind spot Bassam Al-Khalidi July 13, 2026 Here are five steps defenders can take in the wake of the Canvas breach. Identity Okta warns of vishing scheme that extorts data Steve Zurier July 10, 2026 Attackers pose as IT and tell employees to enroll an MS passkey, but the bad guys register their own key and take over the user. AI/ML Stop trying to ‘lock down’ your AI: Why rigid guardrails are a gift to hackers Paul Wagenseil July 10, 2026 Flexible governance, not restriction, of AI agents preserves productivity while providing oversight and accountability. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digest Authentication Digital Certificate Discretionary Access Control (DAC) You can skip this ad in 5 seconds