Skip to content
Open access

From Service Accounts to Agentic Identities: A Zero Trust Governance Framework for Delegated Authority, Runtime Tool Control, and Accountable Non-Human Actors in Enterprise Cybersecurity

Sep 2026 · Informatics · Vol 13, pp. 146 · 0 citations · 11 references

TL;DR

The AIGATE (Agentic Identity Governance, Authority, Tool-Control and Evidence) Framework is an integrated governance architecture connecting identity, delegated authority, autonomy, runtime enforcement, evidence, and revocation across the agent lifecycle.

Abstract

Agentic AI is changing enterprise cybersecurity as AI systems move beyond passive content generation toward autonomous planning, tool use, delegated execution, and operational action. As agents connect to email, code repositories, security operations center (SOC) platforms, finance workflows, cloud services, and enterprise application programming interfaces (APIs), they increasingly function as dynamic non-human identities rather than conventional software tools or service accounts. Existing identity and access management (IAM), Zero Trust, machine identity, and AI-governance approaches remain fragmented in their treatment of delegated authority, task intent, autonomy, runtime tool use, and auditable organizational consequences. This paper addresses these gaps by proposing the AIGATE (Agentic Identity Governance, Authority, Tool-Control and Evidence) Framework. AIGATE integrates eight governance layers: agent identity registration, lifecycle governance, delegated authority mapping, intent-bound access, least agency and least privilege, runtime tool-call control, audit evidence and accountability, and revocation and resilience. The framework treats agents as governed non-human enterprise identities whose actions remain attributable to designated human and organizational roles. AIGATE is developed through a structured critical synthesis of the recent literature on agentic AI security, machine identity, Zero Trust, runtime enforcement, and AI governance, with literature-derived governance requirements mapped explicitly to the eight framework layers. Three SOC, DevOps, and finance scenarios are used as illustrative applications rather than empirical validation. The contribution is an integrated governance architecture connecting identity, delegated authority, autonomy, runtime enforcement, evidence, and revocation across the agent lifecycle.

Read PDF

Similar papers

#artificial intelligence Review Sep 2026

When Agentic Trust Crosses Organizational Boundaries: Structural Externalization and a Reference Model for Trust Evidence

Agentic systems increasingly invoke tools, services, data, and other agents across organizational boundaries, yet a relying party cannot assess a delegated action solely from producing-domain controls and records. This paper develops Trustworthiness as a Service (TaaS) through a synthesis of trustworthy-AI governance,...

Hua-Fu Li, Ji'an Xia · 0 citations
Case report Sep 2026

The five-layer trust stack for agent-to-agent coordination : a compositional architecture for verifiable, auditable, and deception-resistant autonomous agent interactions

As autonomous artificial intelligence (AI) agents are deployed across enterprise and defense environments, ad hoc agent-to-agent coordination introduces machine-speed accountability gaps that existing access control and audit frameworks were not originally designed to address. Without a structured trust framework, agen...

Michael G. R. Lewis · 0 citations
Open access Sep 2026

Security Architecture for Agentic AI in Enterprise Cloud Environments: A Zero-Trust Framework for Secure Autonomous Systems

Agentic artificial intelligence expands the enterprise security boundary because autonomous agents can plan tasks, retain memory, invoke tools, call APIs, and initiate business actions. Authentication at session start is therefore insufficient when later actions may be influenced by untrusted content, poisoned memory,...

S. Suryawanshi · 0 citations
Open access Sep 2026

Runtime Policy Firewall: A Zero-Trust Governance Layer for Enterprise Agentic AI

Enterprise adoption of generative AI is shifting from passive question answering to autonomous agentic execution. Modern agents can decompose goals, retrieve business context, call tools, update records, send messages, initiate transactions, and coordinate workflows across multiple systems. This creates productivity op...

Swapneswar Ray · 0 citations
Review Open access Sep 2026

Governing Agentic AI in the Administrative State: Human Oversight, Cybersecurity Accountability, and Risk in Autonomous Digital Systems

Agentic artificial intelligence (AI) shifts digital government from systems that generate recommendations toward networked systems that perceive, plan, communicate, invoke tools, initiate actions, and adapt with limited direct supervision. This article examines agentic AI as an intelligent cybersecurity governance prob...

Haris Alibašić · 0 citations
Preprint Sep 2026

A Black Box for Agentic Processes: Blockchain-Anchored Evidence for AI Agent Communication, Human Oversight, and GRC Audits

A product- and vendor-neutral black-box architecture for agentic processes that creates blockchain-anchored cryptographic commitments for selected agent communications, human-in-the-loop approvals, tool calls, and process artifacts without placing sensitive content on-chain.

A. Brömme · 3 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.