I have spent most of my career in identity and access management. Long enough to have seen the industry solve some incredibly hard problems, and long enough to know how slowly it can move beyond the architectures it knows.
Agentic AI is forcing that change.
NIST’s latest work on AI agent identity and authorization makes the direction clear: agents need to become first-class identities, delegated authority needs to be preserved, access needs to become more granular, and authorization context needs to move across agent chains.
NIST is right about the foundations. The challenge is that identity now operates in a very different environment.
IAM was designed around a simpler chain
For most of the history of IAM, the model looked something like this:
Human → identity → permissions → application → data
The new model looks very different:
Human → agent → agent → tool → API → data → action
An agent may retrieve information, call another agent, invoke a tool, combine data from several systems and then take an action. The person who initiated the task may be several steps removed from the final transaction.
Identity still matters, as does authentication, delegation and least privilege. However, knowing who an agent is and what permissions it has is simply not enough anymore.
We have to understand the world in which that agent is operating if we want to effectively control it.
Agents needs context and trust
This is where the human model starts to struggle.
Whether an action should proceed depends on relationships, purpose, data sensitivity, consent, provenance and trust. In many enterprises, that information already exists, but it is scattered across systems like data management platforms, data security, IAM and governance platforms.
Agents need that context at the point of decision.
An agent may have permission to access a dataset, but whether it should use that data for a particular task depends on much more than the permission itself. Where did the data come from? Is consent in place? How is the user related to it? Is it sufficiently trustworthy for the action the agent is about to take?
These are context and trust decisions, and agents will make them continuously at machine speed.
Agents need to be connected to the world around them
This is why we built the IndyKite Identity Knowledge Graph.
It is a data model designed to make humans, machines and AI agents first-class identities, then connect them to the data, systems and other entities around them.
The graph captures relationships such as ownership, delegation and consent alongside signals including purpose, provenance and trust.
Instead of knowing only who an agent is and what permissions it holds, the system can understand who it represents, how it is connected to the resources involved, what context surrounds the request and whether the information it is acting on can be trusted.
Authorization has to follow the workflow
Agents do not authenticate once and remain inside a predictable application boundary. They move across tools, APIs, data and other agents, and the conditions around the request change as they go.
Authorization therefore has to follow the workflow.
With AgentControl, IndyKite combines the Identity Knowledge Graph with fine-grained authorization to govern what agents can access and do at runtime. Each decision can incorporate identity, delegation, relationships, intent, policy and trust at the moment an action is attempted.
The same context creates traceability. Enterprises can understand what happened, who or what initiated it, what authority was involved and why the action was allowed.
Security architecture has to keep pace with agent adoption
NIST is now working to establish standards for secure, interoperable AI agents, including identity, authorization and accountability. This will be increasingly important going forward, but it also shows how early this market still is.
Enterprises are deploying agents while the standards and best practices around agentic identity are still taking shape. We have seen what happens when temporary identity architectures become permanent infrastructure. There is an opportunity to avoid repeating that pattern.
The decisions being made now will determine how far agentic systems can scale. If security is built around the assumptions of traditional IAM, autonomy will eventually hit a ceiling. If control is designed for agents from the outset, enterprises can expand what those systems are trusted to do without rebuilding the security model every time the use case becomes more complex.
This is the moment to establish that foundation, before today’s workarounds become tomorrow’s legacy.
If you want to learn more, check out the Whitepaper: Zero Trust Architecture for Agentic AI.









