Agents Are Already in Your Enterprise
AI agents are already running in your enterprise, both sanctioned and unsanctioned. Employees build them in Copilot Studio, Agentforce, and ServiceNow; developers ship custom agents on LangGraph, CrewAI, and AutoGen; SaaS vendors quietly embed agentic features by default. Fortune 50 organizations have found attack surfaces with 150,000+ resources tied to agents and automations. This is the new shadow IT, and it operates at machine speed, not human speed.
This is a board-level business risk, not just an IT issue. Hallucinating or compromised agents can trigger real operational, legal, and regulatory fallout, not just technical incidents. Most organizations can't yet answer basic questions about what agents exist in their environment, what they can touch, or how they behave. Visibility is just the starting point: you can't govern what you can't see.
Why Identity Is Necessary but Not Sufficient
RSA 2026 got identity right. Non-human identities are proliferating faster than human ones, and they're under-governed. But identity answers only one question: was this agent permitted to access this resource? It can't answer whether what the agent did with that access was appropriate.
Two runs of the same authorized agent, using the same clean credential chain, can look identical in the access log, while one is routine and the other is a live data breach. That's the authorization trap: not a failure of identity governance, but its structural boundary.
The Full Identity Surface: From Credentials to Delegation Chains
Agent identity isn't one artifact. It's a surface spanning service accounts, API keys, OAuth tokens, and authority delegated hop to hop across orchestrators and sub-agents. Each additional hop in that chain compounds decision scope and risk in ways conventional identity governance was never built to track.
An agent's real identity is the stable relationship between its original goal, its granted autonomy, and its authorized operations, not the credentials assigned to serve that identity.
Building the Business Case for Agentic AI Security Investment
Security investment decisions are risk-quantification conversations: how much exposure does the organization carry, what does reducing it cost, and what's the return. Framing agent risk in business terms, such as liability, disruption, and regulatory consequence, earns more board attention than framing it in technical terms.
This chapter also introduces the analytical lens used for the rest of the guide: the five-signal framework, covered starting in Part Three.